PBS Nomad (PBS-NP) — Privacy Policy

Version: v0.2 · Effective date: 6 July 2026 (first published for the Google Play closed-testing phase) · Applies to: the PBS-NP ("PBS Nomad") Android application v1, distributed via Google Play and (where offered) direct APK download from penbag.store. Languages: English is the source-of-truth; a Hebrew translation will be commissioned before the v1.0 public release.


0. One-line summary

PBS-NP v1 collects nothing. It runs entirely on your device. It does not send your questions, your answers, your usage, or any personal information anywhere. There is no telemetry, no analytics, no advertising SDK, and no "phone home."

The rest of this Policy explains that in detail, is honest about the small number of future features that would change this (each of which is opt-in and would require an update to this Policy before it ships), and gives you your rights.


1. Who we are

This Privacy Policy explains how the PBS-NP app ("PBS-NP", "the App", "we", "our", "us") handles information when you use the App on your Android device.

PBS-NP is operated by Uri Zohar, registered as an Esek Patur (Hebrew: עוסק פטור — "Exempt Dealer") in Israel under the Israeli Value Added Tax Law 5736-1975, trading under the commercial brand name "PenBag". "PenBag" is the publicly-used brand name. Esek Patur is a registered self-employed status with the Israeli Tax Authority; it is not a separate legal entity for liability purposes, meaning your contract is with Uri Zohar in his personal capacity, conducting business under registered Esek Patur status. References in this Policy to "PBS-NP", "PenBag", "we", "our", and "us" mean Uri Zohar, Esek Patur, trading as PenBag.

Data controller (per Israeli Privacy Protection Law 5741-1981, as amended by Amendment 13 (effective 2025-08-14), and per GDPR Article 4(7) for EU residents): Uri Zohar, Esek Patur, trading as PenBag. Note: because v1 does not collect or transmit personal data (see §3), the App maintains no server-side database of users; controller obligations attach only if and when a future opt-in online feature is enabled — see §4.

Contact: support@penbag.store (subject: "PBS-NP privacy"). A human reads this inbox; we will reply within a reasonable time and in any event within the statutory deadlines that apply to you under your local privacy law.


2. The App in plain language — how our privacy posture works

PBS-NP v1 is an offline, on-device civilian survival-knowledge app.

  • Everything runs on your device. You ask questions; the App answers them locally, from a knowledge base ("Nomad DB") that is built into the app installer at install time (per PBS-NP Arch-A Migration Plan §3.5). There is no cloud service answering your questions. There is no remote query log because there is no remote server involved.
  • Nothing leaves your device. In v1 there is no telemetry, no analytics SDK, no advertising SDK, no crash-reporting service, and no network egress of any kind (per PBS-NP v1 PRD NFR-20 and the offline-by-default security boundary in the v1 PRD §"Offline-default boundary — NO egress"). The App does not "call home."
  • You do not create an account with us. v1 uses a local, device-bound app state only (per CQ-P1). There is no sign-up, no login to any PenBag server.
  • Your questions, answers, and settings stay on your device, stored locally. You can wipe them in Settings at any time.

This is the strongest privacy posture we can offer, and it matches the reason the App exists: disruption-resilient personal capability that works without the internet.


3. What information we collect

3.1 Information collected by PenBag — none

In v1, PenBag collects no personal data from you. We do not receive your questions, your answers, your query history, your settings, any identifier, your location, your contacts, your IP address, crash reports, diagnostics, or usage analytics. There is no server that receives data from the App.

Consistent with Google Play's definition of "collection" — which means transmitting data off a user's device — data that is only processed locally on your device and never sent off the device is not collected and is therefore reported as "No data collected" on the Play Data safety form (see §12; per Google Play Data safety guidance, https://support.google.com/googleplay/android-developer/answer/10787469).

3.2 Information stored only on your device (never transmitted)

The following exists only on your device and is never sent to us or to anyone else:

  • Your queries — the questions you ask PBS-NP.
  • The App's answers — what PBS-NP returned for each query, plus citations to knowledge-base entries.
  • Query history — a local, chronological log of your queries and answers.
  • Your settings — language preference, voice/text mode, font scale, etc.
  • Local app state — a device-local identifier used by the App on your device only (per CQ-P1); it is not a PenBag account and is not transmitted.
  • Operational logs — a rolling local log of crashes and errors, kept on your device only, for your troubleshooting. In v1 these are not transmitted anywhere.

You can wipe any or all of the above in Settings → Privacy → Wipe data at any time.

Because this data never leaves your device, PenBag has no ability to access, read, retain, or delete it — it is under your control alone.

3.3 Network use in v1 — narrow and non-personal

PBS-NP v1 is designed to function fully offline. The only situations where the App may use the network in v1 are:

A. App updates via Google Play. App updates happen through the Google Play Store under Google's terms; PenBag does not see those requests. Refer to Google's own privacy policy for how the Play Store handles installs and updates. This is standard for every Android app and involves no PenBag server.

B. A user-initiated, user-approved knowledge-base update, if and where offered. The App may offer you the ability to manually fetch an updated Nomad DB knowledge bundle. If such an update is offered and you choose to start it:

  • The request downloads a signed, non-personal knowledge file (survival/preparedness reference content). It is verified for cryptographic integrity before install (per CQ-V25).
  • It transmits no personal data about you. Your queries, answers, history, and settings are not part of this request and are never sent. The request is a plain content download, comparable to downloading a document.
  • It is never automatic and never silent — it happens only when you tap to update (per PBS-NP v1 PRD §"Update available" popup → user-triggered manual sync; FR-23).
  • Because it transfers no user data off your device, it does not constitute "data collection" under the Play Data safety definitions (§12).

Aside from (A) and (B), v1 makes no network connections. If you keep the device offline, PBS-NP's core functionality is unaffected.

3.4 Information we do NOT collect or use (v1)

  • We do NOT operate a cloud service that answers your questions. Answers are generated on-device.
  • We do NOT use any telemetry, analytics, or usage-measurement service (no Google Analytics, no Firebase Analytics, no Mixpanel, no Crashlytics, no Sentry, no self-hosted analytics).
  • We do NOT use third-party advertising SDKs or any ad tracking.
  • We do NOT collect contacts, address book, photos, calendar, precise or approximate location, or any device data beyond what is described in §3.2 (which stays on your device).
  • We do NOT sell your data. We do NOT share your data. We do NOT perform cross-context behavioral advertising. There is no data to sell or share, because none is collected.

4. Future features (honesty about what is NOT here yet)

To be transparent, PBS-NP's longer-term roadmap contemplates a small set of optional, opt-in, online features. None of these exist in v1. None of them is active. This Policy describes v1 only.

If any of the following is ever built and enabled, it will be opt-in (default OFF), will show you a clear disclosure at the point you turn it on, and — critically — this Privacy Policy will be updated to describe it truthfully before that feature ships to you (see §13). Until that update is published, you can rely on this Policy's statement that PBS-NP collects nothing.

Contemplated future features (not present in v1):

  • Opt-in online knowledge-bundle download (a future "Flow-A" online update path). A future gated, opt-in way to fetch knowledge updates over the network. (The v1 App ships its knowledge base built into the installer; see §3.3.)
  • Opt-in multi-device sync. A future feature to sync your settings and conversation history across your own devices, end-to-end encrypted, using your own storage bucket and your own key — the key would never leave your device, and PenBag would never hold your data or your key (per PBS-NP v1 PRD FR-36 / OQ-04). Not in v1.
  • Opt-in cloud "assist" for higher-quality answers when online (e.g., improved Hebrew or complex-query handling). If built, it would transmit only the specific query you chose to send, would be clearly labeled, and would be disclosed before first use (per PBS-NP v1 PRD FR-39). Not in v1.
  • Opt-in web search. A future opt-in ability to run a web search you initiate. Not in v1.

We list these so you are not surprised later and so this document is honest about direction. Their appearance here is not a statement that they are present — they are explicitly not in the v1 build, and enabling any of them is a future event gated by a Policy update and your explicit opt-in.


5. Legal bases for processing (GDPR Article 6)

For users in the European Union, United Kingdom, or other jurisdictions applying GDPR-equivalent law:

Activity (v1) Legal basis (GDPR Article 6) Notes
Local, on-device operation of the App (queries, answers, settings, history stay on device) Article 6(1)(b) — performance of a contract Necessary to operate the App for you under the ToS. No personal data is transmitted to us, so no cross-border processing by us occurs.
User-initiated, non-personal knowledge-bundle download (if offered, §3.3B) Article 6(1)(b) — performance of a contract You initiate it; it carries no personal data.
App updates via Google Play Handled by Google under Google's terms PenBag is not the controller for Play Store install/update data.

Because v1 collects no personal data, there is no consent-based processing by PenBag in v1. Consent-based processing (Article 6(1)(a)) would apply only to the future opt-in features in §4 — and only after this Policy is updated to describe them.


6. Your rights

6.1 Israeli Privacy Protection Law 5741-1981 (as amended by Amendment 13)

Per Amendment 13 (effective 14 August 2025):

  • Right of access (Section 13) — a right to a copy of personal information held about you in a database.
  • Right of correction (Section 14) — a right to correct inaccurate personal information.
  • Right of deletion — a right to deletion of personal information no longer needed / lawfully held.
  • Right to object — to use of your personal information for direct marketing.

In v1, PenBag holds no personal-information database about you. All of your data lives on your device and you control it directly in Settings → Privacy → Wipe data. If you have a rights question, contact support@penbag.store and we will confirm that no server-side data about you exists.

6.2 GDPR (EU + UK residents)

You have all GDPR Chapter 3 rights (access — Art. 15; rectification — Art. 16; erasure — Art. 17; restriction — Art. 18; portability — Art. 20; objection — Art. 21; automated-decision rights — Art. 22). In v1, because PenBag holds no personal data, these rights over any PenBag-held data are satisfied trivially (there is none); rights over the on-device data are exercised by you directly in Settings. PBS-NP does not make automated decisions producing legal effects about you. To ask a question: support@penbag.store; we respond within 30 days (Article 12(3)).

6.3 California (CCPA / CPRA), if applicable

If California residents use the App, CCPA/CPRA rights apply regardless of targeting. Because v1 collects, sells, and shares no personal information, there is nothing to disclose, delete, or opt out of at the PenBag level; on-device data is under your control. A "Do Not Sell or Share" mechanism is not required where no sale/share occurs; this will be revisited if any §4 feature is ever enabled.

6.4 Other jurisdictions

If mandatory operator-disclosure or data-subject-rights regimes not listed above apply to you (e.g., Brazil LGPD, Quebec Law 25, India DPDP), contact support@penbag.store. Because v1 collects no data, the substantive obligations are minimal; any required disclosure block will be added if a future feature changes the data posture.


7. Data retention

  • On-device data (queries, answers, history, settings, local logs) — kept on your device until you wipe it. Retention is entirely your choice; PenBag cannot access or retain it.
  • PenBag-held datanone in v1. PenBag operates no server that receives your data, so there is nothing for PenBag to retain.
  • Google Play install/update data — governed by Google's policy, not PenBag.

If a future §4 opt-in online feature is enabled, its retention terms will be added here in the Policy update that must precede it.


8. Security

  • On device, at rest: the App stores your local data using Android platform storage; sensitive local tables are protected using Android Keystore-backed encryption (per CQ-P2). Android auto-backup is disabled for sensitive tables (android:allowBackup="false" + backup-rules exclusions, per CQ-I19), so this data is not copied off-device by the OS backup system.
  • Bundle integrity: any knowledge bundle the App installs (whether baked into the installer or, in future, downloaded) is cryptographically verified (Ed25519 signature + SHA-256) before install (per CQ-V25). A failed verification is rejected locally; nothing is transmitted.
  • In transit: because v1 does not transmit your data, there is no data-in-transit exposure for personal data. The only network traffic in v1 is the Play Store update path (Google) and, if you initiate it, the non-personal knowledge-bundle download over HTTPS.
  • No production secrets in the APK beyond low-sensitivity public values (the knowledge-signing root public key; and, if a future download path is enabled, its endpoint URL) (per CQ-S9).

9. Children and age rating

PBS-NP is rated 12+ (per CQ-L6) and is intended for general civilian-survival knowledge use. Because v1 collects no personal data from anyone, it collects none from children. We do not knowingly collect personal information from children under 13 (there is nothing to collect). Any future Household/dependent feature (contemplated v1.2, per CQ-I5) that would process data will be disclosed in a Policy update before it processes anything.


10. International transfers

In v1 there is no transfer of your personal data internationally, because none is collected or transmitted.

  • App updates flow through Google Play (Google's infrastructure and policy).
  • A user-initiated knowledge-bundle download, if offered, transmits only the signed, non-personal knowledge file over HTTPS; no personal data is transferred.

If a future §4 feature introduces any personal-data transfer, the applicable GDPR Chapter V mechanism (SCCs / adequacy) and the Israeli Privacy Protection Authority cross-border rules will be documented in the Policy update that precedes it.


11. Third parties

Recipient Role in v1 Data shared by PenBag
Google (Google Play) App distribution and updates PenBag shares no user data with Google via the App. Google independently receives standard Play Store install/update information under Google's own policy; PenBag does not see it.
Content delivery for knowledge-bundle download (only if you initiate it, §3.3B) Serves the signed, non-personal knowledge file over HTTPS Request metadata for an HTTPS file download only; no queries, no user content, no personal identifiers.

We do not share data with advertisers, data brokers, behavioral-advertising networks, or any third party for marketing purposes. There is no user data to share.


12. Google Play "Data safety" disclosure (summary)

Consistent with this Policy and with Google's Data safety guidance (https://support.google.com/googleplay/android-developer/answer/10787469, which defines "collect" as transmitting data off a user's device and excludes data processed only locally on the device), PBS-NP v1's Data safety declaration is:

  • Data collected: None.
  • Data shared: None.
  • Data processed only on-device (not disclosed as collection): your queries, answers, history, and settings — all local, never transmitted.

The full Data safety answer table for the Play Console is maintained alongside this Policy (see §16 and the Play Launch Plan gate B7). This declaration is conditioned on the CTO's build confirmation that the production AAB contains zero telemetry / analytics / ads SDK / network egress (Play Launch Plan gate B8). If any such code path is ever added, the Data safety form and this Policy must be updated before submission.


13. App permissions

PBS-NP v1 requests the minimum permissions needed:

Permission Why Refusable?
INTERNET Only for App updates (Google Play) and, if you initiate it, the optional non-personal knowledge-bundle download. Not used for telemetry, analytics, or transmitting your data. You can run the App fully offline; core functionality does not require the internet.
RECORD_AUDIO (microphone) Voice query input (push-to-talk, per CQ-SP2), processed on-device (Whisper.cpp). Voice recordings are not transmitted. YES. If denied, the App falls back to text-only (per CQ-SP3).
READ_EXTERNAL_STORAGE (scoped storage on Android 10+) Only if you choose to sideload a knowledge bundle from local storage/USB/transfer (per CQ-OF2). YES. Used only when you initiate a sideload.

We do NOT request: contacts, calendar, location, camera, SMS, phone, body sensors, or any background permission.


14. Updates to this Policy

We may revise this Policy. Material changes — in particular, enabling any future online feature from §4 that would change the "we collect nothing" posture — will be published in this Policy before the feature ships, will be surfaced to you via an in-app banner on launch, and will require fresh acknowledgment before further use (per CQ-L1 override 2026-05-20). The current version and effective date are always shown at the top of this Policy and in Settings → About → Privacy Policy.


15. How to contact us

Subject Address
Privacy questions, rights requests support@penbag.store (subject: "PBS-NP privacy")
Security issues / vulnerability disclosure security@penbag.store (PGP key TBD per CQ-V43)
General support support@penbag.store

16. Outside-counsel review markers (⚠️ — to be resolved before public ship)

This document is LMO compliance research, not professional legal advice. The following require attorney review before v1.0 ship:

  • ⚠️ Esek Patur business-registration-ID disclosure under Israeli Consumer Protection Law 5741-1981 §14C(a)(1). Whether a business registration ID / Teudat Zehut must appear on the in-app notice depends on "consumer service" classification; recommended to defer until first Israeli signup + attorney confirmation.
  • ⚠️ Hebrew translation accuracy. The Hebrew version must be reviewed by a native Hebrew-speaking attorney; the English version is LMO's source-of-truth.
  • ⚠️ Confirmation of the no-egress build (Play Launch Plan gate B8). This entire "No data collected" posture is truthful only if the shipped AAB has zero telemetry / analytics / ads SDK / network egress. CTO must confirm (network-isolated runtime test, PRD SC-12) before Uri submits the Data safety form. If confirmation fails, route back to LMO before submission.
  • ⚠️ Whether an optional knowledge-bundle download endpoint exists in the actual v1 AAB. §3.3B is written to be truthful whether or not v1 ships a live download path. CTO to confirm which is the case so §3.3B / §11 can be tightened to "no network at all except Play updates" if the download path is not in v1.

17. Change log — what changed from v0.1 and why

v0.1 (2026-05-21) described a data-collecting app. The v1 build does not collect data. v0.2 corrects the mismatch so the published Policy and the Play Data safety form are truthful. Specifically removed:

Removed from v0.1 Why removed
§3.2 A. Live CDN bundle downloads described as a routine network flow receiving bundle name + timestamp + IP v1 ships the knowledge base baked into the installer (Arch-A §3.5, "no network"); the live CDN download flow is future/out-of-scope. Reframed in v0.2 §3.3B as an optional, user-initiated, non-personal download that carries no user data (and flagged for CTO to confirm whether it exists in the v1 AAB at all).
§3.2 C. Crash + abnormality diagnostics (opt-in) sending snapshots to hub.penbag.store v1 has no crash-diagnostics transmission (PRD NFR-20: no telemetry/phone-home). Removed entirely; local error logs (§3.2) stay on device.
§3.2 D. Q/A learning pipeline (opt-in) sending queries + answers + ratings + device_pseudoid to PenBag v1 has no learning pipeline transmission. Removed entirely.
§3.2 E. Multi-device sync (v1.1+) described inline as a data flow through PowerSync on hub.penbag.store Not in v1. Moved to §4 (future features, honest, not-present framing) and corrected to the PRD's E2EE / user's-own-bucket / key-never-leaves-device model (FR-36 / OQ-04).
§4 legal-basis rows citing consent for diagnostics + Q/A learning No such consent-based processing exists in v1; removed.
§6 retention rows for 12-month diagnostics, indefinite anonymized Q/A archive, 90-day CDN IP logs No PenBag-held data in v1; removed. Retention now states "none held by PenBag."
§10 third-party table row implying PenBag shares HTTPS request metadata to a PenBag hub v1 shares nothing; §11 corrected to "no user data shared."
Data safety implication that some data is collected under consent Corrected to No data collected / No data shared (§12), matching the offline build and Google's on-device-processing exclusion.

Added: §0 plain-language summary; §4 honest "future features, not present" section; §12 Play Data safety summary tied to Google's primary-source definition; this §17 change log; a build-confirmation dependency (gate B8) as a review marker.


18. Primary-source citations used in drafting this Policy

Provision Source URL Retrieved
Actual v1 offline / baked-corpus / no-network build PBS-NP Arch-A Migration Plan §3.5 (internal primary source) MD/PBS-NP-ArchA-Migration-Plan.md 2026-07-02
v1 "no telemetry / no analytics / no phone-home" PBS-NP v1 PRD NFR-20 + offline-default egress boundary (internal primary source) MD/PBS-NP-v1-PRD.md 2026-07-02
v1 all-local / no runtime network posture; Data-safety = No collected/No shared PBS-NP Play Launch Plan (header + gates B6/B7/B8) MD/PBS-NP-Play-Launch-Plan.md 2026-07-02
"Collect" = transmit off device; on-device-only processing not disclosed Google Play Data safety guidance https://support.google.com/googleplay/android-developer/answer/10787469 2026-07-02
Google Play privacy-policy requirement (required even with zero data) Google Play Console help https://support.google.com/googleplay/android-developer/answer/9859455 2026-05-21
Israeli Privacy Protection Law 5741-1981 + Amendment 13 (effective 2025-08-14) Library of Congress Global Legal Monitor https://www.loc.gov/item/global-legal-monitor/2025-11-17/israel-amendment-to-privacy-protection-law-goes-into-effect/ 2026-05-21
GDPR Article 6 (lawfulness) EUR-Lex / gdpr-info https://gdpr-info.eu/art-6-gdpr/ 2026-05-21
GDPR Articles 15–22 (data-subject rights) gdpr-info https://gdpr-info.eu/ 2026-05-21

Note: secondary sources (e.g., IAPP analysis) were used only to locate the primary Israeli Amendment-13 source above; the Library of Congress entry is cited as the primary reference per LMO Hard Rule #1.


19. Document control

Field Value
Drafted by LMO
Reviewed by Approved by Uri Zohar, 6 July 2026 (CQ-L1 / Play Launch Plan B6)
Hebrew translation (pending — see §16 ⚠️)
Outside counsel review (pending — see §16)
Version v0.2
Date 2026-07-02
Supersedes v0.1-draft (2026-05-21)
Next review Before v1.0 ship gate; on any material change; before any §4 feature ships