Mobile app privacy policy
This page explains what the TruvaLI mobile app for Android and iOS records, what it never collects, and how to reach us. It supplements our general privacy policy.
Last updated: 6 September 2026
App: TruvaLI (com.truvali.truvali_mobile_client)
1. What this app is
The TruvaLI mobile app is a business tool for corporate customers of the TruvaLI AML / fraud monitoring platform. It connects only to your own organisation's TruvaLI workspace. It does not create standalone accounts and does not collect data for its own purposes.
2. Data processed
2.1 Data the app itself records
| Data | Purpose | Where it is kept |
|---|---|---|
| Device name (e.g. "iPhone", "Android device") | So your administrator can see and revoke paired devices | Your organisation's TruvaLI server |
Platform (ios / android) | Same | Your organisation's TruvaLI server |
| App version | Support and compatibility | Your organisation's TruvaLI server |
| Session tokens (access / refresh) | Keeping the device signed in | On the device only, encrypted in iOS Keychain / Android KeyStore |
| User name and e-mail | Showing who is signed in | On the device; sourced from your organisation's own user record |
None of this is transmitted to TruvaLI or to any third party — it stays within your organisation's own TruvaLI installation.
2.2 Business data shown in the app
The app displays AML / fraud data from your organisation's workspace: customer records, transaction amounts, alerts and case files. Your organisation is the data controller for this content. The app is a viewer and does not store this data persistently on the device.
2.3 Camera
The camera is used only to scan the sign-in QR code. Frames are processed on the device, are never stored and never transmitted. Without camera permission, sign-in is not possible; no other feature uses the camera.
3. Data we do not collect
- Location
- Contacts, photos, calendar or file access
- Advertising identifiers or ad network integrations
- Third-party analytics or tracking SDKs (there are none in the app)
- Cross-app or cross-site tracking
The app shows no advertising and uses no data for advertising purposes.
4. Who receives data
The only network connection the app makes is to your organisation's own TruvaLI server. That address comes from the QR code; no server address is hard-coded in the app.
No data is sent to third-party servers. The barcode scanning library (Google ML Kit) runs offline and does not upload camera frames.
5. Retention and deletion
- Session tokens live in the operating system's secure storage on the device. - Signing out deletes the tokens from the device and revokes the device on the server. - Deleting the app removes all local data. - Your administrator can revoke a device's access at any time from the web console.
User accounts are not created in the app. Account creation, modification and deletion happen in your organisation's TruvaLI admin console. To request deletion of your account, contact your system administrator or [email protected].
6. Security
- All server traffic uses HTTPS. - Tokens are stored in iOS Keychain / Android KeyStore, never in plain files. - Access tokens last 1 hour, refresh tokens 30 days; refresh tokens rotate on every use, so a stolen older token is useless.
Our general security posture: truvali.ai/en/company/legal-security
7. Your rights
Under GDPR and Turkish KVKK (Law 6698) you may access, correct, delete or object to the processing of your data. For the business data shown in the app, your organisation is the controller — direct requests there first.
For data the app itself records (the device registration): [email protected] — Bitrelic Technology, Manisa (Türkiye) · Podgorica (Montenegro)
8. Children
This is a corporate business tool, not directed at anyone under 18, and no data is knowingly collected from children.
9. Changes
When this policy changes, the "Last updated" date above changes. Material changes are announced in the app.
10. Contact
[email protected] Bitrelic Technology Manisa, Türkiye · Podgorica, Montenegro