/privacy describes the server and the CLI and says nothing about the iOS app — while being the privacy policy URL that app's App Store listing points at. A policy that does not mention the app it covers is both a review risk and simply incomplete.
Adds a section stating only what is verifiable in the client's source:
one API token in the device Keychain, the active account in app
preferences, nothing else retained; no analytics, no crash reporting, no
third-party SDK; HTTPS to the named instance and nowhere else; and
gitbay auth token revoke ending access immediately.
Nothing here is a new promise — it is what the app already does, written where Apple and users can read it.