C CARI

Legal · Privacy Policy

Privacy Policy

CARI — CISO AI Readiness Index (iOS application)

Effective date: 20 July 2026 · Last updated: 20 July 2026

Summary. CARI does not collect, transmit, sell or share any personal data. It has no user accounts, no analytics, no advertising and no third-party SDKs, and it makes no network requests. The assessments you save are stored only in the app's private storage on your own device.

Who this policy covers

This policy applies to the CARI (CISO AI Readiness Index) application for iPhone and iPad, published by Prof. Dr. Šarūnas Grigaliūnas (CISO.lt). It describes how the app handles information. It does not apply to any other website or service.

Data collected by the developer

None. The developer receives no data from this app whatsoever. The table below reflects the app's App Store privacy disclosure.

CategoryCollectedDetail
Contact informationNoneNo account, sign-up, email address or name is requested at any point.
IdentifiersNoneNo device ID, advertising ID or user ID is read or generated.
Usage & analyticsNoneNo analytics or telemetry SDK is present in the app.
Diagnostics & crash dataNoneNo crash-reporting service is integrated.
LocationNoneThe app requests no location permission.
Contacts, photos, filesNoneThe app requests no access to any system data source.

Information stored on your device

CARI is an assessment tool, so it stores what you enter — locally, and only locally:

These records are written to the app's own sandboxed storage on your device using Apple's on-device database framework. They are not synced to iCloud, not backed by any server, not transmitted anywhere, and not accessible to the developer or to any third party. They may be included in your own encrypted device backups if you have those enabled, which remain entirely under your control.

Anything you type into a notes field is stored verbatim on your device. Because these records may end up in your device backups, avoid entering information you would not want kept there — the app cannot inspect or filter what you write.

Your control over this data

Because no data ever reaches the developer, there is nothing held about you to access, correct, port or erase on request. Your rights under the GDPR and comparable laws are satisfied directly through the controls above, which you exercise on your own device.

Network activity and third parties

CARI makes no network requests in the course of normal use. It contains no analytics, crash-reporting, advertising, attribution or tracking services, and shares data with no third party — it holds none to share.

The only exception is explicit and user-initiated: the governance reference screens include links to official published sources such as EUR-Lex, ISO, NIST and ENISA. Tapping one opens that address in your browser, at which point that organization's own privacy policy applies. No information about you is passed along with the link.

Children's privacy

CARI is rated 4+ and contains no objectionable material. It is designed for security and governance professionals. It does not knowingly collect information from anyone, including children, because it does not collect information at all.

Data retention

The developer retains nothing, because the developer receives nothing. Records you save remain on your device until you delete them or remove the app.

Changes to this policy

If this policy changes, the revised version will be published on this page with an updated effective date. Material changes to how the app handles information will also be described in the App Store release notes for the version that introduces them.

Contact

Questions about this policy or about privacy in the app can be sent to info@ciso.lt.

Prof. Dr. Šarūnas Grigaliūnas · CISO.lt · Lithuania