Fileen

FILEEN PRIVACY POLICY

Effective Date: 27 August 2026

Legal Document Version: 4.0

This Privacy Policy governs the manner in which the Fileen application for iOS, together with any developer-controlled functionality expressly identified as part of Fileen, handles information in connection with the installation, access, configuration, and use of the application. Fileen is designed as a private, local-first file manager, document and media viewer, and media-processing utility. The principal architectural objective of Fileen is to permit files and related activity to remain under the control of the person using the device and to perform ordinary file management, playback, conversion, trimming, compression, archive, preview, and metadata operations on the device rather than by transmitting the contents of those files to a remote processing environment operated by Fileen.

This Policy is intentionally comprehensive. It should be read together with the Fileen Terms of Use, the Fileen Copyright and Acceptable Use Policy, any permission notice displayed by iOS at the time a system permission is requested, and the terms and privacy practices of Apple and of any website, file host, cloud location, application, or other third party that a user elects to access through or in connection with Fileen. By installing or using Fileen, a user acknowledges that the handling of information necessarily depends not only on the design of Fileen but also on the actions selected by the user, the settings of the device, the operation of iOS, the behavior of destination websites and network providers, and the characteristics of the files and links chosen by the user.

1. APPLICATION PROVIDER, SCOPE, AND INTERPRETATION

Fileen is provided by the person or legal entity identified as the seller or application provider on Fileen's product page in the App Store, referred to in this Policy as the "Application Provider," "Developer," "Fileen," "we," "us," or "our." Questions relating to this Policy or to the privacy practices described in it may be directed to dev@fileen.net. The identity and contact information displayed by Apple for the seller or application provider form part of the identification of the party responsible for Fileen and should be consulted together with the contact address stated in this Policy.

This Policy applies to the Fileen iOS application and to any developer-controlled endpoint, configuration service, or support channel that is expressly used for the operation or support of Fileen. It does not apply to Apple, iOS, the App Store, iCloud, Photos, Files, a website opened by the user, a file host contacted by the user, a cloud provider selected by the user, an application to which the user exports a file, an internet service provider, a domain name provider, or any other independent third party. Each such party may receive, process, retain, or disclose information under its own terms, technical architecture, and privacy policy, and Fileen does not control those independent practices merely because the user reaches the third party through a link, browser, document picker, share sheet, or other system interface available in Fileen.

For purposes of this Policy, "User Content" means files, folders, images, video, audio, documents, archives, file names, file paths, bookmarks, notes, metadata, download records, browsing records, playback positions, and other content or organizational information created, imported, opened, downloaded, converted, stored, or managed by the user through Fileen. "On-Device Information" means information kept within the application container, a location selected through Apple system interfaces, or another local storage area available to the user on the device. "Online Action" means an action that requires communication with a destination outside the device, including opening a website, resolving or requesting a direct link, downloading a remote file, sending an email, exporting to an online destination, or retrieving app configuration.

2. LOCAL-FIRST DESIGN AND THE ABSENCE OF A FILEEN CLOUD ACCOUNT

Fileen does not require a Fileen account, does not create a server-side profile for ordinary use, does not assign a user-facing account identifier, and does not operate a Fileen cloud library into which a user's files are automatically uploaded. The ordinary operation of the application is designed so that User Content remains in locations controlled through the device and is not copied to a remote Fileen storage account. The absence of a Fileen account also means that Fileen ordinarily has no centralized account record by which it can identify a particular installation, reconstruct the contents of a user's library, synchronize the user's folders across devices, or restore local files after the application or the device has been erased.

The fact that Fileen does not operate a cloud account should not be understood to mean that every action performed on a connected device occurs without any network communication. A user may deliberately request information from a website, download a file from a host, save an item to an Apple or third-party cloud-backed location, send an item through the share sheet, or contact support. In each such case the user is directing information to a destination outside the Fileen application. This distinction is material: Fileen does not maintain a server-side repository of the user's files or ordinary in-app activity, but the third-party destination selected by the user may receive and handle information as necessary to perform the action requested by the user.

3. INFORMATION CREATED, STORED, OR PROCESSED ON THE DEVICE

Depending on the features used, Fileen may create, read, modify, organize, index, display, or remove On-Device Information. That information may include the contents of files; the names and extensions of files and folders; file size, creation date, modification date, duration, dimensions, codec, format, and other technical attributes; local thumbnails and preview images; folder organization; favorites; recently opened items; download status; playback position; queue state; repeat and speed settings; bookmarks; app preferences; interface language; security settings; and other information necessary to provide the local functions selected by the user.

When the user requests conversion, trimming, compression, extraction, PDF creation, archive creation, archive extraction, metadata removal, thumbnail generation, media playback, or another local tool, Fileen may create working files, cache files, render files, temporary exports, or replacement copies on the device. Such material may remain until the operation finishes, until Fileen or iOS removes temporary data, until the user deletes the relevant output, or until the application is removed. The specific amount of local storage used depends on the size and nature of the files selected, the operation performed, the available storage, the file format, and the behavior of iOS.

Fileen may use local databases, preference files, indexes, or other structures solely to provide organization and functionality within the application. These local structures may contain references to User Content and may remain on the device even after an individual item is moved, renamed, or deleted until routine maintenance or deletion processes are completed. Fileen does not transmit those local indexes to Fileen-controlled servers for the purpose of constructing a remote profile, measuring behavior, or maintaining a copy of the user's library.

4. NO STORAGE OF USER CONTENT OR APP-ACTIVITY PROFILES ON FILEEN SERVERS

In the current release, Fileen does not upload or store the contents of User Content on developer-controlled servers. Fileen does not maintain on its servers a copy of a user's files, file library, file names, folder structure, local search history, local download history, playback history, media queue, favorites, browser history, browsing cookies, biometric data, or the contents of locally generated conversions. Fileen also does not maintain a server-side user account, advertising profile, cross-device behavioral profile, or analytics history associated with ordinary use of the application.

Where Fileen contacts a developer-controlled endpoint for the limited purpose of obtaining static configuration, confirming compatibility, checking a technical status, or performing another narrowly defined operational request, the endpoint is designed not to retain User Content, submitted file contents, browsing history, download history, or a persistent user profile. Any data that must be present in transit to complete such a request is processed only for the time reasonably necessary to return the requested response and is not used by Fileen to identify, track, advertise to, or build a history about the user. This statement concerns what the Application Provider does with information reaching a developer-controlled endpoint; it is not a statement that Fileen displays no advertising. Advertising in the free version is described in Section 14, and the information involved in it is processed by the advertising provider rather than by the Application Provider. The Application Provider's production configuration should be understood as operating without a Fileen database of user files or personal usage records. In the current release this is stronger than a matter of configuration: Fileen contacts no server operated by the Application Provider at all. The application communicates only with destinations the user selects, with the operating system's own services, and with the advertising and consent components described in Section 14. The media-resolution component is a static resource compiled into the application rather than code retrieved from a Fileen server, so it is not downloaded, not updated remotely, and not able to change after review.

Network communication nevertheless requires technical routing. Internet service providers, domain name resolvers, content delivery services, operating-system services, destination servers, and other network intermediaries may momentarily receive technical connection information, such as an internet protocol address, request time, and routing data, because such information is necessary to deliver traffic across the internet. Fileen does not characterize the unavoidable real-time processing of such information as the creation of a Fileen user account or the storage of User Content. Independent infrastructure providers may apply their own lawful operational practices, and a destination selected by the user may retain information under its own policy.

If a future version of Fileen introduces an account, server-side file processing, cloud synchronization, remote backup, persistent analytics, advertising technology, or another feature that materially changes these practices, the applicable disclosures will be revised before or when that feature is made available, and any consent or choice required by applicable law or by Apple will be presented through an appropriate interface. The statements in this Policy describe the current version and should not be interpreted as a promise that the feature set will never change.

5. DIRECT LINKS, DOWNLOADS, AND DESTINATION SERVERS

When a user pastes or opens a direct link and instructs Fileen to request the resource identified by that link, Fileen must communicate with the server or network identified by the link. The destination may receive the complete resource address, the user's internet protocol address, the time and technical characteristics of the request, standard network headers, redirect information, and any authentication material or query parameters already embedded in the link. Depending on the destination and on the user's prior activity, the destination may also receive cookies, session information, credentials, or other data maintained by WebKit or by the operating system.

A direct link can contain sensitive information. For example, a link may contain a temporary token, a file name, an account reference, a signed authorization value, a document identifier, or another parameter that permits access to content. Fileen does not determine whether a link contains such information or whether the recipient is entitled to receive it. The user is responsible for reviewing the source and for deciding whether to submit or request the link. Fileen does not store the submitted link on a developer-controlled server as part of a permanent user history; however, the destination and intermediate network providers may process or retain the request under their own rules.

Downloads initiated through Fileen are intended to save the requested resource to the user's device or to another location expressly selected by the user. Fileen does not use developer-controlled servers as an undisclosed proxy for storing the downloaded file. A destination server may impose access controls, geographic restrictions, rate limits, authentication requirements, usage terms, retention rules, or technical protections, and the use of Fileen does not alter or override those requirements.

6. EMBEDDED WEB BROWSING AND WEBSITE DATA

Fileen may provide an embedded browser or web view so that the user can navigate to a website, inspect a page, or reach a resource. Web browsing is an Online Action. A website opened in Fileen may collect or receive the same kinds of technical and account-related information that it would receive when opened in another browser, including an internet protocol address, device or browser characteristics, cookies, local storage, session identifiers, account information entered by the user, page interactions, and information contained in requests. Fileen does not control the content, scripts, tracking technologies, security, retention practices, or legal compliance of a website merely because it is displayed in an embedded view.

WebKit may store website data locally on the device. Depending on the configuration of the relevant view and the behavior of the website, such data may include cookies, cache files, local storage, session storage, service-worker data, browsing history, form state, permissions, and other website records. These records are not uploaded by Fileen to a Fileen account. They may persist on the device until they expire, are cleared through an available Fileen control, are removed through iOS, or are deleted when the application is removed. If Fileen offers a command to clear website data, the effectiveness of that command may depend on what WebKit permits the application to remove and on whether other applications or system services maintain separate copies.

The user should not assume that private or nonpersistent browsing within Fileen prevents a website, network provider, employer, school, device-management administrator, or other party from observing a connection. A nonpersistent data store may reduce the amount of website data written to the local application container, but it cannot make an internet request invisible to the server that receives it or to every network intermediary involved in delivering it.

7. APPLE SYSTEM PERMISSIONS AND USER-DIRECTED ACCESS

Fileen may request access to a system capability only when the user selects a feature that requires that capability or when iOS requires a permission prompt. Permission is controlled by iOS, and the user may grant, limit, or revoke access through system settings, subject to the behavior of the operating system. Refusing a permission may prevent the relevant feature from functioning but does not, by itself, prevent use of unrelated parts of Fileen.

When the user saves an image, video, or other compatible item to the Photos library, Fileen uses the access made available by Apple for that action. Where the application is configured for add-only access, Fileen may add the selected item without receiving general permission to browse the entire Photos library. The Photos application and iCloud Photos may copy or synchronize the saved item according to the user's Apple settings. That synchronization is performed by Apple and is not a Fileen cloud upload.

When the user selects a document, folder, or location through Apple's Files interface, a document picker, a share extension, or a security-scoped bookmark, Fileen receives access to the specific item or location made available by the user and by iOS. The user may choose an on-device location, iCloud Drive, or another provider integrated with Files. If the selected location is backed by a cloud service, that provider may upload, download, synchronize, retain, or analyze the item under its own terms. Fileen cannot determine from every file path whether a third-party provider will perform cloud processing.

The current release is not designed to request precise geographic location, contacts, microphone, or camera access for the ordinary file-management, downloading, conversion, compression, and playback functions described in this Policy. A website opened by the user may separately request a browser permission, and a future optional feature may require an additional system permission. Any such request should be evaluated according to the explanation displayed by iOS and the purpose of the feature selected by the user.

8. FACE ID, TOUCH ID, DEVICE PASSCODE, AND APPLICATION LOCK

Current release: Fileen does not include an application lock. The current version performs no biometric or device-passcode authentication and does not link Apple's LocalAuthentication framework. This section applies only if an optional lock is offered in a future release.

Fileen may offer an optional application lock that invokes Apple's LocalAuthentication framework. The biometric comparison is performed by iOS and, where applicable, by secure device hardware. Fileen receives only the result needed to determine whether access should be granted, denied, canceled, or retried. Fileen does not receive, store, transmit, reconstruct, or have access to a face map, fingerprint image, biometric template, or the underlying biometric enrollment data maintained by Apple.

Enabling a Fileen lock does not encrypt every copy of every file in every location and does not replace the device passcode, iOS data protection, a secure backup practice, or the security controls of a cloud provider selected by the user. A person who has access to an unlocked device, to an exported copy, to a backup, to a shared file, or to another application that can open the same location may be able to access content notwithstanding the Fileen lock. The Fileen lock is an additional access control for the application interface and should not be treated as a guarantee against every form of access, recovery, or disclosure.

9. LOCAL METADATA, THUMBNAILS, AND MEDIA INFORMATION

To display and manage content, Fileen may read or derive technical metadata from a file, including format, duration, dimensions, codec, page count, creation or modification date, embedded title, artist, album, artwork, camera information, location metadata, archive structure, and similar attributes. Unless the user directs Fileen to export, share, or send the file to an external destination, this examination and the related preview generation occur on the device.

If the user selects a metadata-removal or clean-sharing function, Fileen may create a new copy that omits certain metadata fields supported by the relevant file format. Fileen does not guarantee that every form of identifying or sensitive information can be detected or removed, because information may appear in file contents, visible pixels, audio, document text, proprietary fields, sidecar files, filenames, folder names, or unsupported metadata structures. The user should inspect the output before sharing it.

10. EXPORT, SHARING, CLOUD-BACKED LOCATIONS, AND DEVICE BACKUPS

Fileen may permit the user to export or share a file through Apple's share sheet, save an item to Photos or Files, copy it to another application, send it through a messaging or email service, or place it in a location synchronized by Apple or another provider. These actions occur at the user's direction. Once the item is delivered to another person, application, or service, the receiving party controls its subsequent processing, and deletion within Fileen does not necessarily delete copies held elsewhere.

Data in the Fileen application container may be included in an encrypted or cloud-based device backup depending on iOS behavior, device configuration, Apple settings, file attributes, and the storage location selected by the user. Fileen does not operate those backups and may not be able to remove a file from a backup already controlled by Apple or another provider. Deleting Fileen generally removes the application's local container from the device, but it does not necessarily delete previously exported copies, files stored in shared or cloud locations, support correspondence, or backups maintained outside the application.

11. SUPPORT, RIGHTS, SECURITY, AND OTHER USER-INITIATED COMMUNICATIONS

Fileen does not require the user to submit a name or email address inside the application for ordinary use. If the user voluntarily sends an email or another support communication, the Application Provider and the relevant email or support provider receive the information included by the user. That information may include the sender's email address, message, screenshots, device or app details, file names, diagnostic descriptions, attachments, or other information chosen by the user. Such correspondence is separate from the local operation of Fileen and may be retained for the time reasonably necessary to respond, maintain a support history, protect legal rights, address security or abuse, and comply with law.

Users should avoid sending the contents of a private file, a sensitive link, an access token, a password, a government identifier, financial information, health information, or another confidential item unless the disclosure is necessary, lawful, and expressly intended. Fileen cannot prevent an email provider, network provider, or other communication service selected by the user from handling the message under that provider's terms.

12. PURPOSES AND LEGAL BASES FOR PROCESSING

To the extent that Fileen processes information, it does so for purposes directly connected with providing the feature selected by the user, maintaining the security and integrity of the application, responding to a communication initiated by the user, complying with legal obligations, protecting the rights of the Application Provider or others, preventing misuse, and maintaining compatibility with iOS and supported file formats. Fileen does not process local User Content for advertising, data brokerage, cross-context behavioral profiling, or the creation of a commercial audience profile.

Where an applicable data-protection law requires a legal basis, the applicable basis may include performance of the service requested by the user, steps taken at the user's request, consent for an optional permission or action, the legitimate interests of operating and protecting Fileen in a manner that does not override the rights of the user, compliance with a legal obligation, or the establishment, exercise, or defense of legal claims. The precise basis depends on the nature of the action and the law that applies. Withdrawal of a system permission or optional consent does not affect processing that was lawful before withdrawal and may prevent the corresponding feature from functioning.

13. DISCLOSURE AND THIRD-PARTY RECIPIENTS

Fileen does not sell personal information and does not share information for cross-context behavioral advertising. The free version of Fileen integrates a third-party advertising software development kit, and Section 14 describes that integration, the categories of information the advertising provider states that it processes, and the consent mechanism applied to it. Fileen itself operates no analytics service and receives no advertising profile, and the Application Provider does not receive the information processed by the advertising provider in a form that identifies an individual user. Separately from Fileen advertising, a website opened by the user may display its own advertising or use its own measurement technologies, which the Application Provider does not control.

Information may leave the application when the user directs Fileen to contact or deliver information to another party; when iOS, Apple, a selected cloud provider, a file host, a website, an email provider, or another application performs the service selected by the user; when limited infrastructure is required to route a real-time request; when a valid legal obligation requires disclosure of information actually held by the Application Provider; or when disclosure is reasonably necessary to protect rights, safety, security, and the integrity of Fileen. Because Fileen does not maintain a server-side copy of ordinary User Content, the Application Provider generally cannot disclose content that it does not possess.

If the Application Provider undergoes a merger, acquisition, restructuring, financing, sale of assets, or similar business event, rights and obligations relating to Fileen and support correspondence may be transferred subject to applicable law. Such a transaction does not convert local User Content that was never held by the Application Provider into data available for transfer.

14. ADVERTISING IN THE FREE VERSION OF FILEEN

The version of Fileen that is available without a paid subscription may display advertising supplied by a third-party advertising provider. The advertising provider used for this purpose is Google, through the Google Mobile Ads software development kit, commonly identified as AdMob, together with the Google User Messaging Platform, which is the consent component supplied with it. Advertising is a property of the free version only; a user with an active Fileen+ subscription is not shown advertising of any kind, and the advertising components are not asked to load, request, or present anything for that user.

Advertising in the free version appears in two, and only two, circumstances. The first is a banner placed within the ordinary tabbed screens of the application. The second is a single full-screen advertisement that may follow a download that the user has expressly started and that has successfully begun. No advertising is presented because a user has completed a conversion, a compression, an image conversion, a document creation, a metadata removal, or any other on-device tool; because a user has changed the playback tempo, saved or recalled a cue, or altered a setting; or because the application has been opened. The advertising provider controls the content of the advertisement itself, and the Application Provider does not select, approve, or endorse the individual advertisement shown.

Fileen configures the advertising component to operate in a limited, privacy-restricted serving mode. In that mode the advertising provider states that personalization is disabled together with every feature that requires a local identifier, which includes audience targeting, remarketing, interest-based categories, conversion tracking, frequency capping, and unique-reach measurement. Advertisements are therefore selected from the context of the request rather than from a behavioral profile of the user. This limited mode is the principal control Fileen applies to advertising, and it is selected before the advertising component is initialized so that it governs every request. Fileen does not request permission under Apple's App Tracking Transparency framework and does not contain the interface required to request it. Where an application has not received that permission, iOS does not make the device advertising identifier available to the application or to a software development kit within it. In that configuration the advertising provider is not able to combine information from Fileen with information from other companies' applications or websites for the purpose of targeted advertising or advertising measurement, and Fileen is not designed or configured to permit that combination. The absence of that permission concerns cross-application tracking specifically, and it should not be read as a statement that every advertisement is chosen at random. An advertisement may still be selected using information available within Fileen itself and within the advertising request, and, where the applicable consent state permits it, the advertising provider may personalize an advertisement on that first-party basis. Fileen does not instruct the advertising provider to restrict advertising to a non-personalized form, and a user who wishes to limit personalization should use the consent and privacy-options interfaces described below and the advertising controls offered by the advertising provider and by iOS. A future version that sought to serve advertising based on tracking across other companies' applications and websites would require the permission interface described above and a corresponding revision of this Policy and of the App Store privacy information before it could do so.

The advertising provider states, in the privacy manifest it distributes inside its own software, that its advertising component may process a device identifier, advertising data, coarse location derived from network address rather than from device location services, interaction with the advertisement, performance data, crash data, and other diagnostic data, for the purposes of third-party advertising, the provider's own advertising, and analytics. The consent component states that it may process coarse location, performance data, and interaction data for the purpose of operating the consent flow itself. This information is processed by the advertising provider under the advertising provider's own privacy policy and technical architecture. The Application Provider does not receive that information, does not store it, does not have access to an advertising profile derived from it, and cannot retrieve, correct, or delete it on a user's behalf; a request concerning that information is properly directed to the advertising provider.

The limited mode does not mean that no information is processed. Delivering any advertisement requires the device to contact the advertising provider, so the provider necessarily receives network connection information including an internet protocol address, from which an approximate, city-level location may be derived, together with the technical context of the request. The advertising provider also states that it may use limited storage on the device for the detection of invalid or fraudulent traffic. Fileen does not represent that its advertising involves no device storage, that no device information is processed, or that the advertising provider receives nothing. Where the applicable law of the user's region requires consent or a choice before advertising information is processed, Fileen presents the consent interface supplied by the Google User Messaging Platform before the advertising component is started. If the required consent is not obtained, the advertising component is not initialized and no advertising request is made. Where a privacy-options interface is applicable to the user's region, Fileen makes it reachable from within the application so that a user may review or change that choice after the first launch. Neither the presence nor the absence of advertising affects the ability to use the file management, playback, downloading, or on-device tool functions of Fileen.

Fileen does not sell personal information, does not share personal information for cross-context behavioral advertising as that expression is used in certain regional privacy statutes, and does not operate an advertising identifier of its own. Fileen contains no analytics software development kit, no crash-reporting software development kit, and no attribution software development kit, and does not transmit a record of which Fileen features a user has used to the Application Provider or to any other party.

15. FILEEN+ SUBSCRIPTION AND PAYMENT INFORMATION

Fileen+ is an optional, automatically renewing subscription offered through Apple's in-application purchase system. It removes advertising from the application, makes the fifth through eighth cue positions available, and permits the tempo control to move beyond the range available without a subscription. No other function of Fileen is conditioned on it: the file manager, the media player, the downloading functions, and every on-device tool remain available without a subscription. The commercial terms of the subscription are stated in the Fileen Terms of Use and in the purchase interface presented by Apple.

Every Fileen+ purchase, renewal, price change, refund, and cancellation is transacted by Apple. The Application Provider does not operate a payment page, does not present a payment form, and does not receive, process, transmit, or store a payment card number, a bank account number, a billing address, a payment token, or any other payment credential. Information provided in the course of a purchase is provided to Apple and is handled under Apple's terms and privacy policy. Where the Application Provider receives commercial information from Apple, it is aggregated or reported sales and payment information of the kind Apple makes available to developers, and it is not a record of an identified individual's use of Fileen.

Within the application, entitlement to Fileen+ is determined by asking the operating system's purchase framework whether a verified, currently active, unrevoked entitlement exists for the Fileen+ identifiers. Fileen does not create a Fileen account, does not assign a subscriber identifier of its own, does not transmit the entitlement state to a server operated by the Application Provider, and does not retain a locally written flag that would grant access independently of that verification. The Restore Purchases function asks Apple to reassociate an existing subscription with the current installation; it does not send information about the user to the Application Provider.

When a Fileen+ entitlement ends, whether by cancellation, expiry, refund, or revocation, no user content is deleted. Files are unaffected. Cue positions that were recorded while the subscription was active remain stored on the device and become inaccessible rather than erased, and they become available again if the entitlement is restored. A tempo range selected in Settings is likewise retained, while the tempo control returns to the limit applicable without a subscription. Nothing about the end of a subscription causes Fileen to transmit information about the user.

16. RETENTION, DELETION, AND THE CONSEQUENCES OF LOCAL STORAGE

User Content and local app records remain on the device or in the location chosen by the user until removed by the user, overwritten, moved, deleted by Fileen or iOS, removed through application deletion, affected by a storage failure, or handled by a cloud or backup provider selected by the user. Fileen cannot recover a local file after it has been permanently deleted unless a separate copy or backup exists outside Fileen. The user is responsible for maintaining copies of important material and for confirming the contents of a destination before deleting an original.

Because the current version does not maintain a Fileen account or a server-side library, there is ordinarily no Fileen account to delete and no central remote file collection for the Application Provider to erase. Deleting the application generally removes its local container from the device, subject to iOS behavior, shared locations, exported copies, and backups. Website data may be cleared through available controls or by removing the application. Support correspondence may be retained separately as described in this Policy and may be deleted or restricted where applicable law grants such a right and no legal reason requires continued retention.

17. SECURITY AND LIMITATIONS OF TECHNICAL PROTECTION

Fileen uses security capabilities made available by iOS, which may include application sandboxing, file-protection classes, permission controls, secure transport where supported by the destination, and optional LocalAuthentication. Fileen is designed to reduce unnecessary transmission of User Content to the Application Provider. Those measures are intended to reduce risk, but no device, file format, application, network, website, backup, or storage medium is immune from failure, unauthorized access, malicious software, social engineering, loss, theft, corruption, or user error.

The security of a download depends in part on the source, the transport used by the source, the integrity of the file, and the applications used to open it. Fileen may not be able to determine whether a file is malicious, deceptive, corrupted, infringing, or unsafe. The user should obtain files from trusted sources, maintain an updated operating system, review unusual file extensions, and avoid entering credentials into untrusted websites.

18. USER CHOICES AND DATA-PROTECTION RIGHTS

A user may manage local information by moving, renaming, exporting, or deleting items through Fileen and Apple system interfaces; may clear supported website data; may revoke optional system permissions in iOS Settings; may disable the optional Fileen lock; may delete Fileen; and may choose not to initiate an Online Action. The availability and effect of each choice depend on the version of iOS, the location of the file, whether an item has been exported, and whether another provider maintains a copy.

Where applicable law grants a right of access, correction, deletion, restriction, objection, portability, withdrawal, or complaint with respect to information actually controlled by the Application Provider, a request may be sent to dev@fileen.net with sufficient information to identify the request. The Application Provider may need to verify the requester and may be unable to locate records that do not exist, were never received, were processed only in real time, were deleted, or cannot reasonably be associated with a particular person. A user may also have the right to complain to a competent supervisory or data-protection authority.

19. INTERNATIONAL COMMUNICATIONS AND REGIONAL REQUIREMENTS

Fileen may be made available in more than one country or region. When a user contacts a website, file host, email provider, cloud location, or another service, the user's information may be processed in the country where that service or its infrastructure operates. The Application Provider cannot control the international routing or location decisions made by independent third parties selected by the user.

Mandatory rights under the law of the user's place of residence remain applicable to the extent that they cannot lawfully be excluded. If a regional law requires a different notice, consent mechanism, representative, response procedure, or restriction, Fileen may provide an additional regional statement or may limit a feature or distribution in that region. Nothing in this Policy is intended to waive a right that cannot be waived by contract.

20. APP STORE PRIVACY INFORMATION AND CHANGES TO PRACTICES

The privacy information displayed on Fileen's App Store product page is intended to describe the production build submitted to Apple and must be read according to Apple's definitions. Under Apple's framework, data processed only on the device is not treated as collected by the developer, and data transmitted solely to service a real-time request without being retained may be treated differently from information stored for a longer period. The Application Provider is responsible for keeping the App Store disclosure consistent with the actual build, included software development kits, and operational practices.

This Policy may be revised when the application's functionality, legal requirements, technical architecture, distribution, or business model changes. The revised document will identify a new effective date or version. Where a change is material and applicable law requires additional notice or consent, Fileen will use a reasonable method to provide it. Continued use after the effective date of a revised Policy constitutes acknowledgment of the revised terms to the extent permitted by law, but does not replace a separate consent where one is legally required.

21. CONTACT

Privacy inquiries, requests, and complaints concerning Fileen may be sent to dev@fileen.net. The responsible Application Provider is the seller identified by Apple on Fileen's App Store product page. A communication should describe the matter with sufficient detail to permit a meaningful response, but should not include private files, passwords, access tokens, or other sensitive material unless the user has intentionally determined that the disclosure is necessary and lawful.