AppzSight ("we," "our," or "us") operates four mobile applications: AppzSight Notes — a comprehensive offline notes suite, Appzsight Reportit (ReportIt) — an enterprise incident reporting app, KPI Collector — a personal KPI tracking journal, and Expense Tracker — a multi-currency personal expense manager. This Privacy Policy applies to all four applications.

Our Core Promise

All AppzSight apps are privacy-first. Your notes, reports, KPI data, images, and all personal information never leave your device and are never transmitted to us. We do not collect, store, or access any of your personal information across any of our apps. Zero personal data leaves your device. Ever.

1. Information We Do NOT Collect

Across all four apps, we do not collect, transmit, or store any of the following:

  • Personal identification information (name, email, phone number)
  • App content — notes, reports, KPI entries, or any data you create
  • Photos, images, or media attachments
  • Contact information
  • Device information or identifiers
  • Location data
  • Usage analytics or statistics
  • Crash reports or diagnostic data
  • Purchase history

2. Data Stored Locally on Your Device

All app data is stored exclusively on your device in encrypted app-private storage. No data is synchronized to the cloud or transmitted to our servers.

AppzSight Notes

  • Text Notes: Content, formatting, text size preferences, RTL settings
  • Checklists: Items, completion status, order
  • Drawings: Base-64 encoded images from the canvas editor
  • Gallery Notes: Up to 7 photos per note with swipe pager data
  • Contact Notes: Names, multiple phone numbers, multiple emails
  • Tags & Folders: Organization metadata you create
  • Reminders: Dates, times, repeat schedules, notification data
  • Media: Photos (camera or gallery), voice recordings, PDF attachments (up to 50MB)
  • Settings: PIN/biometric settings (via Android Keystore / iOS Keychain), theme, language, premium status
  • Storage: Android: /data/data/[package]/ & MediaStore for exports  |  iOS: App sandbox & FileManager

ReportIt

  • Incident Reports: The department, your note (up to 1,000 characters), date/time, a report ID, and the generated PDF
  • Photo & Video Evidence: Up to 5 photos or 1 video you take or choose, plus reduced-size copies kept with each sent report so it can be reviewed and exported later — stored in app-private storage
  • Follow-Up Status: Shared, Pending, Resolved or Discarded, and when the status last changed
  • Departments: Department names, icons, order and (optional) recipient email addresses you enter
  • Reporter Info: Name, designation, email, and mobile number you enter in Settings, used only to populate the "Reported By" line on generated PDFs — stored in the device's secure storage (Android Keystore / iOS Keychain), never transmitted to us
  • App Settings: Theme, language, app lock and follow-up timing preferences

KPI Collector

  • KPI Definitions: Names, units, targets, and categories you define
  • Log Entries: Values, dates, and notes for each KPI entry
  • Goals: Target values, deadlines, and progress data
  • Chart Data: Trend data computed on-device from your entries
  • App Settings: Preferences and notification settings

Expense Tracker

  • Expense Records: Source name, amount, currency, required-by date, notes, color tag, split-payment instalments
  • Completed Records: Paid expense history with payment date and group metadata
  • Settings: Default currency, theme mode (light/dark/system), language (English/Arabic), PIN hash (SHA-256, never plain text), biometric preference
  • Storage: Android Room SQLite database in app-private sandbox (/data/data/[package]/)

We have no servers, no cloud storage, no backend infrastructure, and no ability to access your data from any of our apps.

3. App Permissions & Usage

Each app requests only the permissions necessary for its local functionality.

AppzSight Notes Permissions

  • Camera: Capture photos for gallery notes and image attachments. Photos saved locally only.
  • Storage / Files & Media: Save notes, images, backups, and exports to device storage.
  • Notifications: Send reminder alerts for scheduled notes. No data transmitted.
  • Biometric (Fingerprint/Face ID): Optional app and per-note locking. Biometric data never leaves the secure hardware.
  • Alarm & Reminders: Schedule notification triggers for note reminders.
  • Microphone (Optional): Only requested when you first attempt to record a voice note. Audio files stay on your device and are never transmitted.
  • Read Contacts (Optional): Only used when you explicitly choose "Import from Device." 100% on-device — we never access your contacts otherwise.
  • Internet: Google Play Billing (purchases) and Google Play In-App Review (ratings prompt) — or, on the Huawei AppGallery version, HUAWEI In-App Purchases and AppGallery's in-app rating screen instead — and on-demand link preview metadata when you paste a URL in a Link note. No personal data transmitted to us.

ReportIt Permissions

  • Camera: Capture photo evidence for incident reports. Photos stored in app-private storage only.
  • Photos (picker): Photos and videos you select through the system photo picker — the app gets only the items you pick, not your whole library. No storage permission is requested on Android.
  • Biometric / Passcode (Optional): Used only when you turn on App Lock. Authentication is handled by the operating system; no biometric data is stored by the app.
  • No Notifications, Location, Contacts or Microphone: None of these are requested.
  • No network use by ReportIt itself: ReportIt never sends your reports, photos or personal details anywhere. Tapping "Share" or "WhatsApp" generates a PDF on-device and hands it to the OS share sheet / WhatsApp — any transmission after that point is between you and the app you chose, not us.
  • In-app purchase (ReportIt Pro): The Google Play version includes Google's Play Billing library, which declares the Internet permission so Google can process the one-time "ReportIt Pro" purchase and receive the library's own purchase diagnostics. The App Store version uses Apple's StoreKit. Purchases are handled entirely by Google or Apple: we never see your payment details, and the only thing the app keeps is whether Pro is unlocked. The Huawei AppGallery version has no billing and no Internet permission.

KPI Collector Permissions

  • Storage / Files & Media: Save KPI data exports and backups to device storage.
  • Notifications: Reminder alerts for KPI logging. No data transmitted.
  • Internet (if applicable): Google Play Billing for premium features only. No KPI data is ever transmitted.

Expense Tracker Permissions

  • Biometric (Fingerprint/Face ID): Optional app lock. Authentication handled by device secure hardware via Android BiometricPrompt. No biometric data is stored by the app.
  • No Camera: Expense Tracker does not request or use the camera.
  • No Internet: Expense Tracker is fully offline — no network permission is declared. No data ever leaves your device.
  • No Contacts, No Microphone, No Location: None of these permissions are requested.

What None of Our Apps Have

  • ❌ Location services — We never track your location
  • ❌ Device identifiers (IMEI, Android ID, MAC address)
  • ❌ Advertising ID — explicitly removed from all apps
  • ❌ Background data upload of any kind
  • ❌ Analytics or telemetry SDKs
  • ❌ Crash reporting services

4. App Features Overview

AppzSight Notes — Notes Suite

11 note types including text, checklists, drawings, photo gallery, contacts, encrypted notes, audio, markdown, links, tables, and My Time (a life/career timeline note). All work 100% offline with zero cloud sync. Supports 27 languages with full RTL support.

ReportIt — Incident Reporting

Incident reporting by department with photo/video evidence and a follow-up status for every report. Reports are composed and stored entirely on-device, turned into a PDF, and shared via WhatsApp, email or the native OS share sheet — always an explicit action by you. Summary exports (PDF or CSV) are created on-device and shared the same way. The app never transmits your reports itself. Free to use with one department and the last 30 days of history; an optional one-time ReportIt Pro purchase (through Google Play or the App Store) unlocks unlimited departments, full history, custom date ranges and export.

KPI Collector — Personal KPI Tracking

Define and track personal performance metrics with daily logging, goal setting, and trend visualization. All calculations and chart rendering happen on-device. Available on Android and iOS.

Expense Tracker — Multi-Currency Expense Manager

Track personal and business expenses with multi-currency support (20 currencies), color tagging, split-payment instalments with exact decimal arithmetic, and mark-as-paid workflow. Fully offline — no internet permission. Supports English and Arabic with full RTL layout. PIN and biometric lock available.

5. Backup, Export & Import

AppzSight Notes

  • ZIP Backup: Export all notes + images into a single ZIP file to Downloads/NotesK/
  • Auto-Backup: Daily scheduled backups + on-change backups to device storage only
  • JSON / CSV / PDF / PNG Export: Multiple formats for full data portability
  • Print: Via Android print framework
  • Import: AppzSight Notes ZIP/JSON/CSV backups, Google Keep ZIP (via Takeout)
  • Restore: Full restore from any backup with merge or replace options

ReportIt

  • Sharing: Generate a PDF and share it via WhatsApp, email or any app you choose — triggered only by you
  • Summary Export: Export a filtered summary of your reports as PDF (optionally with photos) or CSV, shared through the app you choose
  • Local Archive: Each sent report's PDF and media copies stay in app-private storage until you delete the report (or use Settings › Delete all reports)
  • Cloud Backup: Report history, PDFs and photos are excluded from Google/iCloud cloud backups; only non-sensitive preferences are backed up. A direct phone-to-phone transfer can still move your data to a new device.

KPI Collector

  • Data Export: Export KPI logs to CSV or JSON to your device storage
  • Backup: Backup all KPI data locally to device storage

Expense Tracker

  • JSON Export: Export all active and completed expense data as a JSON file via the Android share sheet — save locally or send to an app of your choice
  • No cloud backup: Cloud backup and device-transfer backup are explicitly disabled. Data is never backed up to Google Drive or any cloud service.

Important: All exports and backups are saved to your device's local storage only. We do not receive, process, or have access to these files. You choose where to share or store exported data.

6. Security Features

Where applicable, our apps offer on-device security:

  • AppzSight Notes: App-level PIN lock (4-digit, via device Keystore), biometric lock (Fingerprint/Face ID), per-note lock, configurable auto-lock timer. No biometric data stored by the app.
  • ReportIt: Optional App Lock (OS biometric/PIN) that re-locks after 5 minutes in the background and hides report content in the app switcher. Report data stored in the app-private sandbox; reporter details in Android Keystore / iOS Keychain.
  • KPI Collector: Data stored in app-private sandbox inaccessible to other apps. Sensitive settings stored via Android Keystore / iOS Keychain.
  • Expense Tracker: Optional PIN lock (SHA-256 hashed, never stored in plain text) and biometric lock via Android BiometricPrompt. Cloud backup explicitly disabled via android:allowBackup="false" and data extraction rules. All data in app-private sandbox.

7. Data Retention

  • AppzSight Notes: Deleted notes move to Recycle Bin with 30-day auto-purge via background worker. Archived notes remain indefinitely. Manual permanent deletion available.
  • ReportIt: Reports remain on device until you delete them (individually, all resolved reports, or everything via Settings › Delete all reports). Uninstalling the app removes all of its data. No automatic deletion.
  • KPI Collector: All KPI data and logs remain until you delete them. No automatic deletion.
  • Expense Tracker: Expenses remain until you manually delete individual records or use "Clear All Data" / "Clear Completed Records" from Settings. No automatic deletion.
  • All apps: Uninstalling the app removes all app data permanently from your device.

8. Third-Party Services

We use minimal third-party services across our apps. We use no analytics, no advertising networks, no crash reporters, and no tracking SDKs in any of our apps.

AppServicePurposeData Involved
AppzSight NotesGoogle Play BillingOne-time Premium purchasePurchase token sent to Google only — not to us
AppzSight NotesGoogle Play In-App ReviewPrompt you to rate the appNo personal data; handled entirely by Google
AppzSight Notes (Huawei AppGallery version)HUAWEI In-App Purchases (IAP Kit)One-time Premium purchasePurchase data sent to Huawei only — not to us
AppzSight Notes (Huawei AppGallery version)AppGallery in-app ratingPrompt you to rate the appNo personal data; handled entirely by Huawei
AppzSight NotesLink Preview (HTTPS)Fetch Open Graph metadata when you paste a URL in a Link noteOnly the URL you pasted is fetched; no data sent to us
ReportItGoogle Play Billing / Apple StoreKitOne-time "ReportIt Pro" purchasePurchase handled by Google or Apple — not sent to us. Reports, photos and personal details are never transmitted by the app; sharing is handed off to WhatsApp or the OS share sheet, which you control.
KPI CollectorGoogle Play Billing (if applicable)Premium features purchasePurchase token sent to Google only — not to us
Expense TrackerNoneFully offline — no internet permissionNo network requests of any kind. No third-party services used.

What we do not use: ❌ Firebase  |  ❌ Analytics  |  ❌ AdMob / Ads  |  ❌ Cloud storage  |  ❌ Crash reporting  |  ❌ Authentication services

For Google's data practices, see Google's Privacy Policy.

9. Data Security Measures

All four apps protect your data with multiple layers:

  • Device-Level Encryption: Your data benefits from your device's full-disk encryption (when device lock is enabled)
  • App Sandbox: All data stored in app-private directories inaccessible to other apps
  • Secure Storage: Sensitive settings stored via Android Keystore / iOS Keychain
  • Minimal Network Surface: Internet is used only for explicitly triggered actions (Google Play or Huawei store services, email sending, link previews) — no background sync, no telemetry, no persistent connections
  • No Account Required: No login, no email, no passwords to compromise

10. Children's Privacy

None of our apps knowingly collect any information from anyone, including children under 13. Since we collect absolutely no data and have no external data communications, all four apps are safe for all ages. Parents can confidently allow children to use our apps knowing no information leaves the device.

11. Your Rights (GDPR/CCPA/Local Laws)

Because we collect zero personal data and store everything locally, most data privacy regulations have limited application. However, you retain absolute control across all our apps:

  • Right to Access: All your data is visible and accessible within each app at all times
  • Right to Delete: Delete any item instantly within each app. Uninstall to erase all data permanently.
  • Right to Port: Export your complete dataset anytime via the export features in each app
  • Right to Rectify: Edit any data directly within each app
  • Right to be Forgotten: Uninstall the app to remove all data permanently from your device
  • Right to Restrict Processing / Right to Object: Not applicable — we perform no data processing or tracking

12. Premium Features & Billing

Where premium features exist (e.g., AppzSight Notes Premium), all billing is handled by the store you installed from — Google Play, the Apple App Store, or Huawei AppGallery. We do not see, store, or process any payment information. Premium status is stored locally on your device, not tied to user accounts.

13. Open Source & Transparency

Our apps are built with open-source technologies including Kotlin, Jetpack Compose, SwiftUI, Room Database, and CoreData. None of our apps contain proprietary tracking or analytics code. You can verify our privacy claims by inspecting each app's network permissions.

14. Changes to This Policy

We may update this Privacy Policy as features evolve. We will notify you of changes by posting the new policy in each app's Settings → About screen and updating the "Last Updated" date on this page. Since we collect no contact information, we cannot notify you directly — please check this page periodically.

15. Contact Us

For privacy-related questions, data export assistance, or to exercise your rights:


The Final Path — الطريق الأخير

This section applies exclusively to our separate The Final Path: Quran & Sunnah (الطريق الأخير: القرآن والسنة) app for iOS and Android. Its data practices differ from AppzSight Notes and the other apps above, mainly because it uses your device's location to calculate accurate prayer times.

What The Final Path Collects

The Final Path is free, has no accounts, and no ads. The Quran text, tafsir, hadith, and Seerah are bundled with the app. Audio recitations are streamed or downloaded directly from two independent public recitation archives, everyayah.com and verses.quran.com; like any website, they receive your IP address and the file requested. We don't operate them and never see or handle that traffic. We do not collect, transmit, or store any personal identification information, and we do not run analytics or crash reporting.

Location (Prayer Times)

If you tap "Use my current location" on the prayer times screen, the app asks the OS for a one-time location fix and uses the operating system's built-in geocoder to turn it into a city name (Android's Geocoder / Apple's CLGeocoder). These system services send the coordinates to Google or Apple respectively to look up the place name, under Google's and Apple's own privacy policies; no third-party location SDK is included in the app. Your coordinates are also sent to a public, independent prayer-times calculation API (Al Adhan) solely to retrieve accurate prayer times for that spot — apart from the system geocoder above, this is the only network use of your location, it is not linked to your name or any identifier, we do not operate that API and never receive or store your coordinates ourselves, and the app does not request location in the background. If the request fails or you decline, the app falls back to an on-device calculation using your selected city and device time zone — no location data leaves your device at all in that case. You can pick a city manually instead of sharing your location at any time.

Data Stored Locally on Your Device

Bookmarks (verses, Mushaf pages, hadith, Seerah paragraphs, and the Names of Allah), memorization and review progress, downloaded recitations, your selected city, reciter, font, and display preferences are stored locally via standard OS storage (SharedPreferences on Android, UserDefaults on iOS) and never leave your device.

Permissions

  • Location (optional): only for the current-location prayer-times feature described above; you can decline and pick a city manually instead
  • Notifications: local, on-device prayer-time reminders you can enable per-prayer; nothing is sent to any server to schedule them
  • Internet: used only to fetch prayer times for your chosen coordinates/city and to stream/download reciter audio — never for Quran text, tafsir, hadith, or Seerah, which are fully bundled offline

Contact

For privacy questions about The Final Path: info@appzsight.com or WhatsApp.


dERP — derp.appzsight.com

The following sections (16–20) apply exclusively to the dERP web application at derp.appzsight.com. This is a cloud-based SaaS product with an entirely different data model from our mobile apps.

16. What dERP Collects

Unlike our mobile applications, dERP is a cloud-based platform: it needs an account and stores your company's data on our servers in order to work. By using dERP, you agree to the practices described below.

Account & User Data

  • User profile: Full name, username, email address, assigned roles, and account status
  • Password: Stored only as a salted PBKDF2-SHA256 hash (100,000 iterations) — we never store or see your plain-text password
  • Two-factor authentication (optional): If you turn it on, we store the authenticator secret needed to verify your codes, plus hashed one-time recovery codes
  • Sign-in security: Failed sign-in counts and temporary lockouts, to protect your account from password guessing
  • Session tokens: A short-lived access token, and a rotating refresh token kept in a secure, HttpOnly cookie (we store only a hash of it)
  • Invitations: The email address and roles of people your administrators invite
  • Notification preferences: Which alerts you want in-app or by email

Company Data

  • Company profile: Company name, code, base currency, timezone, industry, and optionally address, phone, contact email, country, and VAT number
  • Plan details: Plan, trial and subscription dates, and usage limits

Business Data You Enter

  • Items, units, categories, suppliers and supplier quotes
  • Bills of materials, routings, work centers, labor rates, overhead types, and cost calculations
  • Inventory: warehouses, stock levels, and stock movements
  • Manufacturing: production orders and food batches (for companies using those modules)
  • Accounting: chart of accounts, journal entries, tax codes, cost centers, and budgets
  • Planning: scenarios, simulations, and approval workflows

This data belongs to your company. We process it only to provide dERP to you.

Operational Data

  • Audit trail: Every create, update, and delete is recorded with the user, time, and before/after values. Passwords, two-factor secrets, and other credentials are removed from these records.
  • IP addresses: Used in memory for rate-limiting sign-in and API requests. They are not stored in the database.
  • API keys: Stored as a SHA-256 hash; the full key is shown only once, when it is created

Billing Data

  • dERP does not take online payments today. If online billing is introduced, payments will be processed by Stripe: we will never see or store card details, and will keep only your plan, billing status, and Stripe customer/subscription references.

17. How We Use dERP Data

  • Providing the service: Costing, inventory, accounting, reports, approvals, and the other features your company uses
  • Emails: Account emails (invitations, password resets), notifications you have enabled, and the optional weekly cost summary your company can switch on
  • Security: Sign-in protection, rate limiting, and the audit trail
  • Support: Helping you when you contact us
  • We do not use your data for advertising, profiling, or AI training, we do not sell it, and dERP contains no analytics or tracking scripts.

Service Providers

  • Contabo — hosts our server and database (Dubai, UAE)
  • SendGrid (Twilio) — delivers dERP's emails; receives only the recipient address and the email content
  • open.er-api.com — supplies currency exchange rates when an administrator refreshes them; receives only a currency code, never your data
  • Stripe — payment processing, only if online billing is introduced

18. Data Storage & Security (dERP)

  • Location: dERP runs on a private server in Dubai, UAE
  • Encryption in transit: All connections use HTTPS (TLS 1.2 or later)
  • Isolation: Each company's data is kept separate, and the application only ever shows a user their own company's data
  • Access control: Role-based permissions, optional two-factor sign-in, and account lockout after repeated failed sign-ins
  • Backups: The database is backed up automatically every night on the same server. Backups are kept for 14 days and then deleted.

19. Your Rights (dERP)

  • Access: Your company's data is available to your authorized users in dERP at all times
  • Download your data: Settings → Privacy → Download my data gives you a copy of your profile, preferences, and your recent audit-trail entries
  • Correction: You can update your profile, and your administrators can update company and business records
  • Deletion: Request deletion of your account in Settings → Privacy. Your company's administrator completes the request by anonymizing your personal details (name, username, email). Business records you created stay with your company, because they belong to it.
  • Closing a company account: Email info@appzsight.com. We will delete the company's data within 90 days.
  • Full data export: Contact us for a complete export of your company's data

20. Retention (dERP)

  • Company data is kept while the account is active, and deleted within 90 days after the account is closed
  • Nightly backups are kept for 14 days, so deleted data disappears from backups within 14 days of deletion
  • The audit trail is kept for as long as the company account exists, to protect the integrity of your records
  • If online billing is introduced, billing records will be kept for as long as tax law requires

Questions About Our Privacy Policy?

Contact us directly for any inquiries regarding our data practices.

Summary (Mobile Apps): All four AppzSight mobile apps — AppzSight Notes, ReportIt, KPI Collector, and Expense Tracker — are privacy-first. Your data stays on your device. We collect nothing personal. We track nothing. We have no servers for mobile apps. Internet is used only for Google Play / App Store purchases and link previews you explicitly trigger in AppzSight Notes. ReportIt works completely offline (the network is used only by Google Play or the App Store to process the optional ReportIt Pro purchase), and Expense Tracker has zero internet permission. Your privacy is our priority.

Summary (dERP): dERP (derp.appzsight.com) is a cloud SaaS. It requires an account and stores your business data (BOMs, costs, users) on servers located in the UAE in order to function. We use this data only to deliver the service. We do not advertise, profile, or sell your data. All data stays in the UAE region. See Sections 16–20 for full details.