Khazna

Privacy Policy for Khazna

Khazna (خزنة) is a personal vault: links you want to come back to, notes you jot down, and checklists you tick off. It has no accounts and no backend of ours. This page explains what it keeps on your device, the two requests that leave it, and how to switch both of them off.

Last updated 24 August 2026 · Covers Khazna 0.1.0 and later · com.khazna.vault

The short version

Everything you save lives in the app's own storage on your phone. There is no account to create, no server of ours to sync to, and no way for us to read what is in your vault.

Two requests, both optional

The app fetches the title of a link you already saved, and sends usage measurements that contain no vault content. Each is a switch in Settings.

What you write is never sent

Titles, notes, URLs, checklist items and search text never appear in a measurement — not truncated, not hashed, not "just the domain".

Uninstalling is the erase button

Removing the app removes the vault with it. There is no copy anywhere else to ask us to delete.

1. Who we are and what this covers

Khazna is built and published by Mohamed Gado, an individual developer, reachable at boogado@yahoo.com. In the language of data protection law, that person is the data controller for the small amount of information described in section 5. There is no company, no team and no third party with access.

This policy covers the Khazna mobile application, identified as com.khazna.vault, on Android and iOS. It does not cover the websites you open from inside it — once you tap a saved link you are on someone else's page, under their policy, and section 7 explains exactly what the app does and does not do at that moment.

2. No accounts, no server of ours

There is nothing to sign up for. Khazna has no login, no profile, no cloud, no sync and no API of ours anywhere in the picture. We do not operate a server that your vault touches, which means there is no database of items, no backup of your notes, and nothing for us to hand over, lose, or be compelled to produce.

This is a design decision with a cost, and it is worth stating plainly: because there is no server, there is no automatic recovery. If you lose the phone without having exported a backup (section 10), the vault is gone. We consider that the correct trade for a private notebook.

Two requests do leave the device, and neither is a server of ours: a page title fetch that goes straight to the site you saved, and an anonymous usage measurement sent to PostHog. Both are described below and both can be switched off.

3. What stays on your device

All of it. Khazna stores its data in the app's private storage, which the operating system isolates from other apps. Nothing in this list is uploaded anywhere.

What Contains
Your vault Every item you save: kind, title, URL, note body, checklist entries and their ticked state, tags, pin and archive flags, the time each was created and last changed, and whether a link has been opened
Settings Theme, language, haptics, sort order, app lock and its auto-lock delay, screen privacy, and your two network switches
Lock timing A single timestamp recording when the app last went to the background, so the lock knows whether to re-arm. No credentials of any kind are stored
Scheduled reminders Held by the operating system's own alarm scheduler, on the device, along with the text it will display

There is no analytics copy of any of this, no crash report that captures screen contents, and no diagnostic log that includes what you wrote.

4. The two requests the app makes

Khazna's own code opens exactly two kinds of network connection. Adding a third would require changing this page first, which is a rule the project holds itself to.

Request 1 — the title of a link you saved

When you save a link without typing a title, the app can fetch the page's own title so the item is readable later instead of being a bare URL. What that involves, precisely:

One honest consequence: the site you saved sees a request from your IP address at the moment you save or view the item, the same as if you had opened it in a browser. If that matters for a particular link, turn the setting off before saving it.

Request 2 — usage measurement

The app sends anonymous product measurements to PostHog, hosted in the European Union, so that decisions about what to build are based on how the app is actually used. Section 5 describes exactly what an event may contain — the short version is counts, durations, screen names and yes/no flags, and never a single character of what you wrote.

Switch: Settings → Privacy → Usage measurement. Off means nothing is sent.

5. Usage measurement, in detail

Most apps promise that analytics are "anonymous" and leave you to take it on faith. Here is the actual mechanism, because it is checkable rather than a promise.

Every event the app is allowed to send is declared in one file in the source, together with the exact shape of what it carries. A value in that file may be a number, a true/false flag, or one of a fixed list of words that we chose (a screen name such as feed, an item kind such as link). It may not be free text. A title, a URL, a note, a checklist label and a search query are all free text, so none of them can be placed in an event without changing that rule — and an automated test refuses to build the app if the rule is changed.

Sent Never sent
Which screen was opened, by our name for it The title of any item
That an item was created, and of which kind Any URL, or any part of one, including the domain
How many characters it had — the number, not the text The body of a note
How many results a search returned What you searched for
How many entries a checklist has and how many are ticked What any checklist entry says
Whether a title fetch succeeded, and how long it took Which page was fetched
Whether an unlock succeeded, failed or was cancelled Anything about your fingerprint, face or passcode
How many items the vault holds, rounded into a band Anything that identifies you personally

Counts that could grow without limit are rounded into bands before sending, because "this vault holds 1,247 items" is close to a fingerprint while "1000+" answers the same product question and is not.

PostHog assigns a random identifier to the installation so that a sequence of events can be recognised as one session. It is not derived from your device id, your phone number or any account, it is not shared with anyone, and reinstalling the app produces a new one. Session replay and autocapture — the PostHog features that record the screen and the text of whatever is tapped — are permanently disabled in the code and are not offered as a setting.

The legal basis, where the GDPR applies, is legitimate interest in understanding how the app is used, and the measurement is on by default. If you would rather not take part, one switch in Settings ends it.

6. Saving things into Khazna

There are four ways in, and none of them watches you.

The app has no access to your browsing history, your other apps' data, your contacts, your photos, your location, your microphone or your camera — several of those are explicitly blocked in the app's manifest (section 12).

7. Opening a saved link

Tapping a link opens it in an in-app browser tab, or in your default browser when that is not available. From that point you are visiting the site normally: it sees your IP address and whatever your browser sends it, exactly as it would if you had typed the address. Khazna does not inject anything into the page, does not read its contents, and does not track where you go next. It records one thing locally, on your device: that the link has been opened, so it can stop showing as unread.

8. Reminders

You can ask an item to resurface at a chosen time. The reminder is scheduled with the operating system's own alarm scheduler and fires on the device. No push service is involved, no push token is requested, and the reminder's text — which may include your item's title — never leaves the phone. Denying notification permission simply means reminders are unavailable; nothing else in the app changes.

9. App lock and screen privacy

Two optional protections, both off by default and both entirely local.

App lock puts your device's own authentication — fingerprint, face, or PIN and pattern — in front of the vault. The check is performed by the operating system; the app is told only whether it passed. No biometric data is ever available to the app, and no PIN or password of ours exists to be stored, guessed or reset. The app remembers a single timestamp of when it was last backgrounded, so it can re-lock after the delay you chose. A cold start always locks.

If the lock becomes impossible to satisfy — you removed your device screen lock after enabling it, for instance — the app turns the setting off and lets you in rather than leaving you shut out of your own notes. A vault its owner cannot open is a loss, not security.

Screen privacy asks the operating system to block screenshots and screen recording, and to hide the app's preview in the task switcher. On Android this is the standard secure-window flag. The settings screen reports whether the block is actually in force rather than merely what you asked for, because a privacy control that claims to be on while it is not is worse than not having one.

10. Backup and restore

A backup is a plain JSON file containing your items, produced on demand and handed to your device's share sheet. Where it goes is entirely your choice — a cloud drive, a chat with yourself, a cable. It is not uploaded anywhere by the app, and no copy is kept by us. The file is not encrypted, because it is yours to place somewhere you trust; treat it as you would a document containing the same notes.

Restoring reads a file you pick and merges it into the vault. It never wipes what is already there, and restoring the same file twice changes nothing. You can also copy a backup to the clipboard and paste it back, which is useful for moving between two devices with nothing in between.

11. App updates

Two update mechanisms exist, and neither is a request the app's own features make.

12. Permissions

Khazna asks for very little, and explicitly blocks several permissions that its libraries would otherwise be free to declare.

Permission Why
Internet and network state The two requests in section 4, and app updates
Notifications Requested only when you set your first reminder. Optional
Biometric authentication Only when you turn app lock on. Optional
Vibrate Haptic feedback on save and on ticking a checklist. Optional in Settings
Boot completed and wake lock So a reminder scheduled before a restart still fires afterwards

Explicitly blocked in the app's own configuration, so they cannot be present in a released build: microphone, camera, precise location, approximate location, physical activity recognition, reading images and reading video from your library.

Also absent, because nothing in the app has any use for them: contacts, SMS, call logs, the list of installed apps, and background location.

13. How your data is secured

Your vault sits in the app's private storage area, which Android and iOS keep isolated from other applications. On a device with a screen lock, that storage is covered by the operating system's own encryption at rest. App lock and screen privacy (section 9) add a second layer if you want one.

The two outbound requests use HTTPS. Beyond that, the strongest security property here is structural rather than technical: there is no server holding your items, so there is no breach of ours that could expose them.

A caveat worth stating: a device with no screen lock, or one that has been rooted or jailbroken, does not provide the isolation described above, and no app can restore it.

14. Retention and deletion

Your items are kept until you delete them. Deleting an item removes it; there is no hidden trash, and no copy is retained anywhere else. Archiving keeps an item out of the feed while leaving it searchable, and is not deletion.

To erase everything: uninstall the app, or clear its storage from your device settings. Both remove the vault and every setting with it, immediately and permanently. Export a backup first if you want to keep anything.

Usage measurements are held by PostHog for up to twelve months and then expire. They are not tied to your identity, so there is nothing personal to delete — but if you want the installation's measurement history removed anyway, email us from the address in section 19 and it will be deleted. Turning the switch off stops any further measurement immediately.

15. Your rights

Where the GDPR, the UK GDPR or a similar law applies, you have rights of access, rectification, erasure, restriction, portability and objection. Their shape here is unusual, because of how little exists:

We cannot identify you from anything we receive, so we cannot search for "your" data on request — that is a consequence of collecting so little, not an evasion. You also have the right to complain to your local data protection authority.

16. Children's privacy

Khazna is a general-purpose notebook and is not directed at children. It contains no ads, no advertising identifiers, no in-app purchases and no social features, and it does not knowingly collect information from anyone. If you believe a child's information has somehow reached us, write to the address in section 19 and it will be removed.

17. Third-party services

Who What they receive When
The website of a link you saved A page request from your IP address, like any browser visit Only if title fetching is on, once per saved link
PostHog (EU region, eu.i.posthog.com) Anonymous events as described in section 5: counts, durations, screen names, flags. No content, ever Only if usage measurement is on
Expo (u.expo.dev) App version and platform, in order to serve the right update bundle On launch, to check for an update
Google Play / Apple App Store Whatever the store platform itself collects, under its own policy Installation and updates

There are no advertising networks, no attribution or install-tracking SDKs, no social logins, no crash reporter that captures screen contents, and no data broker relationship of any kind. Nothing is sold or shared for advertising, and nothing about you is used to train a model.

18. Changes to this policy

If the app starts doing something this page does not describe, this page is updated first, in the same working session as the change — not afterwards. The date at the top changes with it, and the full history of every edit is public in this repository's git log. Material changes will also be noted in the app's release notes.

19. Contact

Any question about privacy, or to have this installation's measurement history deleted: boogado@yahoo.com

Developer: Mohamed Gado · App: Khazna (com.khazna.vault)

This page is static and hosted on GitHub Pages. It sets no cookies, runs no analytics, and loads no fonts or scripts from other servers.

سياسة الخصوصية لتطبيق خزنة

خزنة دفتر شخصي: روابط تريد العودة إليها، وملاحظات تدوّنها، وقوائم مهام تشطبها. لا حسابات فيه ولا خادم لنا خلفه. تشرح هذه الصفحة ما يبقى على جهازك، والطلبَين الوحيدَين اللذَين يخرجان منه، وكيف تُوقف كلًّا منهما.

آخر تحديث ٢٤ أغسطس ٢٠٢٦ · تغطي خزنة 0.1.0 وما بعدها · com.khazna.vault

باختصار

كل ما تحفظه يعيش في مساحة التطبيق الخاصة على هاتفك. لا حساب تُنشئه، ولا خادم لنا يتزامن معه، ولا سبيل لنا لقراءة ما في خزنتك.

طلبان، وكلاهما اختياري

يجلب التطبيق عنوان صفحة لرابط حفظته بالفعل، ويرسل قياسات استخدام لا تحمل أي شيء من محتوى خزنتك. لكلٍّ منهما مفتاح في الإعدادات.

ما تكتبه لا يُرسَل أبدًا

العناوين والملاحظات والروابط وبنود القوائم ونص البحث لا يظهر أيٌّ منها في قياس — لا مقتطعًا، ولا مشفّرًا، ولا «النطاق فقط».

حذف التطبيق هو زر المحو

إزالة التطبيق تزيل الخزنة معه. لا توجد نسخة في مكان آخر تطلب منّا حذفها.

١. من نحن ونطاق السياسة

خزنة من تطوير ونشر محمد جادو، مطوّر فرد، ويمكن مراسلته على boogado@yahoo.com. وبلغة قوانين حماية البيانات، هذا الشخص هو المتحكّم في القدر اليسير من المعلومات الموصوف في القسم ٥. لا شركة، ولا فريق، ولا طرف ثالث له صلاحية وصول.

تغطي هذه السياسة تطبيق خزنة للهواتف، المعرّف بـ com.khazna.vault، على أندرويد و iOS. ولا تغطي المواقع التي تفتحها من داخله — فبمجرد أن تضغط رابطًا محفوظًا تكون في صفحة شخص آخر وتحت سياسته، والقسم ٧ يوضّح بالضبط ما يفعله التطبيق وما لا يفعله في تلك اللحظة.

٢. لا حسابات ولا خادم لنا

لا شيء تسجّل فيه. لا يوجد في خزنة تسجيل دخول، ولا ملف تعريف، ولا سحابة، ولا مزامنة، ولا واجهة برمجية لنا في الصورة من الأساس. نحن لا نشغّل خادمًا تلمسه خزنتك، ومعنى ذلك أنه لا توجد قاعدة بيانات بعناصرك، ولا نسخة من ملاحظاتك، ولا شيء نسلّمه أو نفقده أو نُلزَم بإخراجه.

هذا قرار تصميمي له ثمن، ومن الأمانة قوله صراحة: لأنه لا يوجد خادم، لا توجد استعادة تلقائية. إن فقدت الهاتف دون أن تكون قد صدّرت نسخة احتياطية (القسم ١٠) فقد ضاعت الخزنة. ونرى أن هذه هي المقايضة الصحيحة لدفتر خاص.

هناك طلبان يخرجان من الجهاز فعلًا، وليس أيٌّ منهما خادمًا لنا: جلب عنوان صفحة يذهب مباشرة إلى الموقع الذي حفظته، وقياس استخدام مجهول يُرسل إلى PostHog. وكلاهما موصوف أدناه وكلاهما يمكن إيقافه.

٣. ما يبقى على جهازك

كل شيء. تحفظ خزنة بياناتها في مساحة التطبيق الخاصة، وهي مساحة يعزلها نظام التشغيل عن بقية التطبيقات. ولا شيء في هذه القائمة يُرفَع إلى أي مكان.

ماذا يحتوي على
خزنتك كل عنصر تحفظه: نوعه وعنوانه ورابطه ونص ملاحظته وبنود قائمته وحالة شطبها، ووسومه، وحالتَي التثبيت والأرشفة، ووقت الإنشاء وآخر تعديل، وما إذا كان الرابط قد فُتح
الإعدادات السمة واللغة والاهتزاز وترتيب العرض، وقفل التطبيق ومهلته، وخصوصية الشاشة، ومفتاحا الشبكة
توقيت القفل ختم زمني واحد يسجّل آخر مرة انتقل فيها التطبيق إلى الخلفية، ليعرف القفل هل يعيد التسلّح. ولا تُخزَّن أي بيانات اعتماد من أي نوع
التذكيرات المجدولة يحتفظ بها مجدول المنبّهات في نظام التشغيل، على الجهاز، مع النص الذي سيعرضه

لا توجد نسخة تحليلية من أيٍّ من ذلك، ولا تقرير أعطال يلتقط محتوى الشاشة، ولا سجل تشخيصي يتضمن ما كتبته.

٤. الطلبان اللذان يجريهما التطبيق

يفتح كود خزنة نوعين اثنين فقط من اتصالات الشبكة. وإضافة ثالث تستلزم تعديل هذه الصفحة أولًا، وهي قاعدة يلزم بها المشروع نفسه.

الطلب الأول — عنوان رابط حفظته

حين تحفظ رابطًا دون أن تكتب له عنوانًا، يستطيع التطبيق جلب عنوان الصفحة نفسها ليصبح العنصر مقروءًا لاحقًا بدل أن يكون رابطًا عاريًا. وهذا ما يعنيه ذلك بدقة:

ونتيجة واحدة من الأمانة ذكرها: الموقع الذي حفظته يرى طلبًا من عنوان IP الخاص بك لحظة الحفظ أو العرض، تمامًا كما لو فتحته في المتصفح. فإن كان ذلك مهمًّا لرابط بعينه، أوقف الإعداد قبل حفظه.

الطلب الثاني — قياس الاستخدام

يرسل التطبيق قياسات مجهولة عن الاستخدام إلى PostHog، المستضاف في الاتحاد الأوروبي، لتكون قرارات ما يُبنى مستندة إلى كيفية استعمال التطبيق فعليًا. ويصف القسم ٥ بالضبط ما يجوز أن يحمله الحدث — وخلاصته: أعداد ومدد وأسماء شاشات وإشارات نعم/لا، ولا حرف واحد مما كتبته.

المفتاح: الإعدادات ← الخصوصية ← قياس الاستخدام. وإيقافه يعني ألّا يُرسَل شيء.

٥. قياس الاستخدام بالتفصيل

معظم التطبيقات تَعِد بأن تحليلاتها «مجهولة» وتترك لك أن تصدّق. وهذه هي الآلية الفعلية، لأنها قابلة للفحص لا مجرد وعد.

كل حدث يُسمح للتطبيق بإرساله معلَن في ملف واحد في الكود، ومعه الشكل الدقيق لما يحمله. والقيمة في ذلك الملف يجوز أن تكون رقمًا، أو إشارة صح/خطأ، أو واحدة من قائمة ثابتة من الكلمات اخترناها نحن (اسم شاشة مثل feed، أو نوع عنصر مثل link). ولا يجوز أن تكون نصًّا حرًّا. والعنوان والرابط والملاحظة وبند القائمة وكلمة البحث كلها نص حر، فلا يمكن وضع أيٍّ منها في حدث دون تغيير تلك القاعدة — واختبار آلي يرفض بناء التطبيق إن تغيّرت.

يُرسَل لا يُرسَل أبدًا
أي شاشة فُتحت، باسمنا نحن لها عنوان أي عنصر
أن عنصرًا أُنشئ، ومن أي نوع أي رابط أو أي جزء منه، بما في ذلك النطاق
كم حرفًا كان فيه — العدد لا النص نص أي ملاحظة
كم نتيجة أعاد البحث عمّا بحثت
كم بندًا في القائمة وكم منها مشطوب ما يقوله أي بند
هل نجح جلب العنوان وكم استغرق أي صفحة جُلبت
هل نجح فتح القفل أم فشل أم أُلغي أي شيء عن بصمتك أو وجهك أو رمزك
كم عنصرًا في الخزنة، مقرَّبًا إلى شريحة أي شيء يعرّف بك شخصيًّا

الأعداد التي قد تنمو بلا حد تُقرَّب إلى شرائح قبل الإرسال، لأن «هذه الخزنة فيها ١٢٤٧ عنصرًا» أقرب إلى بصمة، بينما «أكثر من ١٠٠٠» يجيب عن السؤال نفسه ولا يكون بصمة.

يمنح PostHog التثبيت معرّفًا عشوائيًّا حتى يمكن التعرّف على سلسلة أحداث كجلسة واحدة. وهو غير مشتق من معرّف جهازك ولا رقم هاتفك ولا أي حساب، ولا يُشارَك مع أحد، وإعادة تثبيت التطبيق تُنتج معرّفًا جديدًا. أما إعادة تشغيل الجلسة والالتقاط التلقائي — وهما ميزتا PostHog اللتان تسجّلان الشاشة ونص ما يُضغط — فمعطّلتان في الكود بشكل دائم ولا تُعرضان كإعداد.

والأساس القانوني، حيث تنطبق اللائحة الأوروبية، هو المصلحة المشروعة في فهم كيفية استعمال التطبيق، والقياس مفعّل افتراضيًّا. وإن كنت تفضّل ألّا تشارك فمفتاح واحد في الإعدادات ينهي الأمر.

٦. كيف تدخل الأشياء إلى خزنة

أربع طرق للدخول، ولا واحدة منها تراقبك.

لا يملك التطبيق وصولًا إلى سجل تصفّحك، ولا بيانات تطبيقاتك الأخرى، ولا جهات اتصالك، ولا صورك، ولا موقعك، ولا ميكروفونك، ولا كاميرتك — وعدد منها محظور صراحةً في إعداد التطبيق (القسم ١٢).

٧. فتح رابط محفوظ

الضغط على رابط يفتحه في تبويب متصفح داخل التطبيق، أو في متصفحك الافتراضي عند تعذّر ذلك. ومن تلك اللحظة أنت تزور الموقع زيارة عادية: يرى عنوان IP الخاص بك وما يرسله متصفحك، تمامًا كما لو كتبت العنوان بنفسك. لا تحقن خزنة شيئًا في الصفحة، ولا تقرأ محتواها، ولا تتعقّب إلى أين تذهب بعدها. وتسجّل شيئًا واحدًا محليًّا على جهازك: أن الرابط فُتح، لتتوقف عن عرضه كغير مقروء.

٨. التذكيرات

يمكنك أن تطلب عودة عنصر إلى السطح في وقت تختاره. يُجدوَل التذكير عبر مجدول المنبّهات في نظام التشغيل ويُطلَق على الجهاز. لا خدمة إشعارات دفع في الأمر، ولا رمز دفع يُطلب، ونص التذكير — وقد يتضمن عنوان عنصرك — لا يغادر الهاتف أبدًا. ورفض إذن الإشعارات يعني ببساطة أن التذكيرات غير متاحة؛ ولا يتغير شيء آخر في التطبيق.

٩. قفل التطبيق وخصوصية الشاشة

حمايتان اختياريتان، كلتاهما متوقفة افتراضيًّا وكلتاهما محلية بالكامل.

قفل التطبيق يضع مصادقة جهازك نفسها — بصمة أو وجه أو رمز أو نقش — أمام الخزنة. يجري الفحص في نظام التشغيل؛ ولا يُبلَّغ التطبيق إلا بنجاحه أو فشله. لا تتاح بيانات حيوية للتطبيق مطلقًا، ولا يوجد رمز أو كلمة مرور خاصة بنا تُخزَّن أو تُخمَّن أو تُستعاد. ويتذكّر التطبيق ختمًا زمنيًّا واحدًا لآخر انتقال إلى الخلفية، ليعيد القفل بعد المهلة التي اخترتها. والبدء البارد يقفل دائمًا.

وإن صار القفل مستحيل الاستيفاء — كأن تكون قد أزلت قفل شاشة جهازك بعد تفعيله — يُطفئ التطبيق الإعداد ويسمح لك بالدخول بدل أن يتركك محبوسًا خارج ملاحظاتك. فخزنة لا يستطيع صاحبها فتحها خسارة لا أمان.

خصوصية الشاشة تطلب من نظام التشغيل منع لقطات الشاشة وتسجيلها، وإخفاء معاينة التطبيق في مبدّل المهام. وعلى أندرويد هذه هي راية النافذة الآمنة المعتادة. وتذكر شاشة الإعدادات هل المنع سارٍ فعلًا لا ما طلبته أنت فحسب، لأن أداة خصوصية تدّعي أنها مفعّلة وهي ليست كذلك أسوأ من عدم وجودها.

١٠. النسخ الاحتياطي والاستعادة

النسخة الاحتياطية ملف JSON عادي يحوي عناصرك، يُنتَج عند الطلب ويُسلَّم إلى قائمة المشاركة في جهازك. وأين يذهب اختيارك أنت وحدك — سحابة، أو محادثة مع نفسك، أو كابل. لا يرفعه التطبيق إلى أي مكان، ولا نحتفظ نحن بنسخة منه. والملف غير مشفّر، لأنه ملكك تضعه حيث تثق؛ فتعامل معه كما تتعامل مع مستند يحوي الملاحظات نفسها.

والاستعادة تقرأ ملفًا تختاره وتدمجه في الخزنة. لا تمحو ما هو موجود أبدًا، واستعادة الملف نفسه مرتين لا تغيّر شيئًا. ويمكنك أيضًا نسخ نسخة احتياطية إلى الحافظة ولصقها، وهو مفيد للانتقال بين جهازين لا شيء بينهما.

١١. تحديثات التطبيق

آليتا تحديث موجودتان، وليست أيٌّ منهما طلبًا تجريه ميزات التطبيق نفسها.

١٢. الأذونات

تطلب خزنة القليل جدًّا، وتحظر صراحةً عدة أذونات كان بوسع مكتباتها أن تعلنها لولا ذلك.

الإذن لماذا
الإنترنت وحالة الشبكة الطلبان في القسم ٤، وتحديثات التطبيق
الإشعارات يُطلب فقط عند ضبطك أول تذكير. اختياري
المصادقة الحيوية فقط عند تفعيلك قفل التطبيق. اختياري
الاهتزاز استجابة لمسية عند الحفظ وعند شطب بند. اختياري من الإعدادات
اكتمال الإقلاع وإبقاء الجهاز مستيقظًا ليُطلَق تذكير جُدوِل قبل إعادة التشغيل بعدها

ومحظورة صراحةً في إعداد التطبيق نفسه فلا يمكن وجودها في إصدار منشور: الميكروفون، والكاميرا، والموقع الدقيق، والموقع التقريبي، والتعرّف على النشاط البدني، وقراءة الصور، وقراءة الفيديو من مكتبتك.

وغائبة أيضًا لأن لا حاجة لشيء في التطبيق بها: جهات الاتصال، والرسائل، وسجل المكالمات، وقائمة التطبيقات المثبّتة، والموقع في الخلفية.

١٣. كيف تُؤمَّن بياناتك

تجلس خزنتك في مساحة التطبيق الخاصة، وهي مساحة يبقيها أندرويد و iOS معزولة عن التطبيقات الأخرى. وعلى جهاز له قفل شاشة، يغطّي تشفيرُ نظام التشغيل تلك المساحة في حالة السكون. ويضيف قفل التطبيق وخصوصية الشاشة (القسم ٩) طبقة ثانية إن أردتها.

ويستخدم الطلبان الخارجان بروتوكول HTTPS. وما عدا ذلك، فأقوى خاصية أمنية هنا بنيوية لا تقنية: لا يوجد خادم يحمل عناصرك، فلا يوجد اختراق لنا يمكن أن يكشفها.

وتنبيه يستحق الذكر: جهاز بلا قفل شاشة، أو جهاز جرى تجذيره أو كسر حمايته، لا يوفّر العزل الموصوف أعلاه، ولا يستطيع أي تطبيق استعادته.

١٤. الاحتفاظ بالبيانات وحذفها

تبقى عناصرك حتى تحذفها. وحذف عنصر يزيله؛ ولا توجد سلة مخفية، ولا نسخة محفوظة في مكان آخر. والأرشفة تُبقي العنصر خارج القائمة مع بقائه قابلًا للبحث، وهي ليست حذفًا.

لمحو كل شيء: احذف التطبيق، أو امسح تخزينه من إعدادات جهازك. وكلاهما يزيل الخزنة وكل إعداد معها، فورًا ونهائيًّا. صدّر نسخة احتياطية أولًا إن أردت الاحتفاظ بشيء.

قياسات الاستخدام يحتفظ بها PostHog حتى اثني عشر شهرًا ثم تنتهي. وهي غير مرتبطة بهويتك فلا يوجد شخصي يُحذف — لكن إن أردت مع ذلك إزالة سجل قياسات هذا التثبيت، راسلنا من العنوان في القسم ١٩ وسيُحذف. وإيقاف المفتاح يوقف أي قياس لاحق فورًا.

١٥. حقوقك

حيث تنطبق اللائحة الأوروبية أو البريطانية أو قانون مشابه، لك حقوق الوصول والتصحيح والمحو والتقييد والنقل والاعتراض. وشكلها هنا غير معتاد، لقلّة ما هو موجود أصلًا:

ولا نستطيع التعرّف عليك من أي شيء يصلنا، فلا نستطيع البحث عن بياناتك «أنت» عند الطلب — وذلك نتيجة لجمعنا القليل جدًّا لا تهرّبًا. ولك أيضًا حق الشكوى إلى هيئة حماية البيانات في بلدك.

١٦. خصوصية الأطفال

خزنة دفتر عام الاستعمال وليست موجّهة للأطفال. لا إعلانات فيها، ولا معرّفات إعلانية، ولا مشتريات داخلية، ولا ميزات اجتماعية، ولا تجمع معلومات من أحد عن علم. وإن كنت ترى أن معلومات طفل قد وصلتنا بطريقة ما، فاكتب إلى العنوان في القسم ١٩ وستُزال.

١٧. خدمات الغير

من ماذا يتلقّى متى
موقع الرابط الذي حفظته طلب صفحة من عنوان IP الخاص بك، كأي زيارة متصفح فقط إن كان جلب العناوين مفعّلًا، ومرة واحدة لكل رابط محفوظ
PostHog (منطقة الاتحاد الأوروبي، eu.i.posthog.com) أحداث مجهولة كما في القسم ٥: أعداد ومدد وأسماء شاشات وإشارات. ولا محتوى، أبدًا فقط إن كان قياس الاستخدام مفعّلًا
Expo (u.expo.dev) إصدار التطبيق ومنصّته، لتقديم حزمة التحديث الصحيحة عند التشغيل، للتحقق من وجود تحديث
Google Play / Apple App Store ما تجمعه منصّة المتجر نفسها، وفق سياستها هي التثبيت والتحديثات

لا توجد شبكات إعلانية، ولا حزم تتبّع تنصيب أو إسناد، ولا تسجيل دخول عبر الشبكات الاجتماعية، ولا مبلّغ أعطال يلتقط محتوى الشاشة، ولا أي علاقة بوسيط بيانات من أي نوع. ولا يُباع شيء ولا يُشارَك لأغراض الإعلان، ولا يُستخدم شيء عنك في تدريب نموذج.

١٨. تعديلات هذه السياسة

إن بدأ التطبيق يفعل شيئًا لا تصفه هذه الصفحة، فهذه الصفحة تُحدَّث أولًا، في جلسة العمل نفسها التي يقع فيها التغيير لا بعدها. ويتغير التاريخ في الأعلى معها، وتاريخ كل تعديل كامل ومتاح للعموم في سجل git لهذا المستودع. كما ستُذكر التغييرات الجوهرية في ملاحظات إصدار التطبيق.

١٩. التواصل

لأي سؤال عن الخصوصية، أو لحذف سجل قياسات هذا التثبيت: boogado@yahoo.com

المطوّر: محمد جادو · التطبيق: خزنة (com.khazna.vault)