TREVIK

TREVIK — Privacy Policy

P-01 — Scope and local model

This Policy describes Artifact #7. Its financial vault is processed on the Android device and is not transmitted to the Operator. For conservative compliance, the Operator treats himself as the database controller where Israeli privacy law applies because he determines the App’s processing purposes, without claiming that possession is irrelevant or that the local-vault question has been judicially settled.

P-02 — Responsible person

Ibrahim Abu Naser, an individual in Nazareth, Israel, operates the App. SORLANE is a brand and not a legal person. Privacy requests: privacy@trevik.app. The address must be provisioned and monitored before publication.

P-03 — Information you enter

You may enter income, optional balance, cards and last four digits, limits, billing dates, fees, waivers, commitments, loans, installments, planned or logged purchases, currency, category and preferences. Do not enter full payment credentials, banking credentials or government identifiers. Financial information is treated as specially sensitive.

P-04 — Information generated locally

The App generates affordability states, card rankings, installment indications, calculations, history and local reminders. Operational and vault-related errors are reported to the device's standard debug console; the App does not maintain a separate, retained local error log. Reported messages redact runs of four or more consecutive digits; shorter digit sequences and other message content are not redacted or length-limited.

P-05 — Purposes and voluntary provision

Providing data is voluntary and not required by law. The App uses it locally to provide the functions described in the Terms, protect the vault, display history and schedule reminders. Refusal causes only the relevant feature to be unavailable, less accurate or marked Unknown. No unrelated purpose is authorized.

P-06 — Device permissions

The Android package declares platform and library permissions, including network and notification capabilities. Artifact #7 has no app code path that uses network permissions to transmit vault or operational data. Notification permission is used for local reminders. Unconfigured messaging components do not register a device or enable remote push.

P-07 — Storage and security

The vault is encrypted locally. PIN protection and device biometrics may guard access; the App does not receive raw biometric templates. Screen capture is blocked while locked or backgrounded but allowed while unlocked in the foreground. If the App remains backgrounded for five minutes, it relocks the next time it returns to the foreground; it does not actively lock while running in the background, and it does not relock merely due to inactivity while in the foreground. No measure is absolute.

P-08 — Retention and deletion

Vault data remains until you delete records, use Full Reset, clear App data or uninstall, subject to platform behavior. Full Reset deletes the vault and user-related data but not language preference, bundled reference data, external exports, platform records or support communications. The App does not retain a separate local error log to preserve or clear (see P-04).

P-09 — Export and import

Export creates an encrypted envelope protected by a passphrase of at least 12 code points. The App does not store or recover the passphrase. You control copying and storage. Import performs integrity and version checks and rolls back if it cannot complete. External copies are outside Full Reset and the Operator’s control.

P-10 — Network and links

The App makes no app-initiated network request to operate. Reference data is bundled; an update is needed to correct it. If you choose an external link or telephone action, the destination receives the ordinary information generated by your browser or telephone service under its own policy. The App adds no vault value to the link.

P-11 — Analytics and support

No analytics or crash data is transmitted. If you contact support and choose to mention an on-screen error code, the Operator receives only what you intentionally send. Do not send vault data. Any future telemetry requires prior legal and product review, a precise event list, vendor and transfer facts, updated notice, and consent where required.

P-12 — Notifications

Local reminders may be visible on the lock screen. Three of four types are in Hebrew regardless of selected language, and three types include the last four card digits. No remote push or marketing message is sent.

P-13 — Recipients and transfers

The App sends the vault to no recipient, processor, advertiser, bank, issuer or affiliate and makes no international transfer. Google and the operating system process store and platform data under their own terms. The Operator may answer a valid legal demand only for information he actually possesses; he cannot produce a vault he never receives.

P-14 — Access, correction and control

You can view, edit and delete vault information directly and use Full Reset. For personal information the Operator actually holds, such as a support message, request access or correction under applicable law at privacy@trevik.app. Proportionate identity checks and lawful retention or refusal grounds may apply.

P-15 — Children

The App is intended for adults and has no age gate. Do not use it if under 18. If a minor sends information to the Operator outside the vault, contact privacy@trevik.app.

P-16 — Changes and future features

Material changes receive appropriate notice and consent where required. No external telemetry, remote push, account, sync, cloud vault, location, paid feature, commercial partnership or AI/document import may be activated merely by changing this Policy.

P-17 — Languages and contact

The Hebrew, Arabic and English versions are intended to be equivalent and none is subordinate. Operator: Ibrahim Abu Naser, Nazareth, Israel. Privacy: privacy@trevik.app; support: support@trevik.app; general: contact@trevik.app. These routes require operational verification before publication.

privacy@trevik.app