diff --git a/distribution/play-listing.md b/distribution/play-listing.md index 80ef158..07c9f8b 100644 --- a/distribution/play-listing.md +++ b/distribution/play-listing.md @@ -73,12 +73,12 @@ Then open the app, tap Connect, paste your server URL, and you're in. Your AI co OpenCode Mobile is MIT licensed. Source code, issue tracker, and community at github.com/dzianisv/opencode-mobile. Contributions welcome. PRIVACY -OpenCode Mobile does not collect your code, prompts, or AI responses. All traffic goes directly from the app to YOUR opencode server — never through our infrastructure. Optional Sentry crash reporting collects only device model, OS version, and stack traces (no message content). +OpenCode Mobile does not collect your code, prompts, or AI responses. All traffic goes directly from the app to YOUR opencode server — never through our infrastructure. With your opt-in consent we use Sentry for crash diagnostics and PostHog for anonymous usage analytics (no PII, no message content, off by default). Diagnostic reports you share are also delivered to our support inbox. Support: support@agentlabs.cc Issues: github.com/dzianisv/opencode-mobile/issues ``` -(3366/4000 chars) +(3474/4000 chars) > Supersedes the prior draft, which named a dated model ("GPT-4") and was missing the directory picker and reasoning-effort features shipped since. Model references are now version-free by design ("Claude, GPT, Gemini, or any other model") so this copy doesn't go stale again as model names change. @@ -162,10 +162,10 @@ Issues: github.com/dzianisv/opencode-mobile/issues Suggested path: `https://dzianisv.github.io/opencode-mobile/privacy/` Privacy policy must cover: -- What data is collected (Sentry crash diagnostics: device model, OS version, stack trace; no user content) -- How data is used (debugging crashes only) -- Third-party SDKs (Sentry — link to https://sentry.io/privacy/) -- Data retention (Sentry default 90 days) +- What data is collected (Sentry crash diagnostics: device model, OS version, stack trace; PostHog usage analytics: activation-funnel events with coarse properties; Chatwoot shared support reports: scrubbed diagnostic reports sent only when the user taps "Share Report"; no user content in any of them) +- How data is used (debugging crashes; measuring whether new users successfully connect/activate; responding to user-initiated support reports) +- Third-party SDKs (Sentry — https://sentry.io/privacy/; PostHog — https://posthog.com/privacy) and our own self-hosted Chatwoot support inbox (support.agentlabs.cc — not a third-party vendor) +- Data retention (Sentry default 90 days; PostHog standard retention; Chatwoot support conversations retained until resolved, then periodically purged) - User rights (delete request via email, contact us) - Contact: support@agentlabs.cc @@ -176,20 +176,47 @@ Operator: VIBE TECHNOLOGIES, LLC, 519 S Henderson St, Seattle WA 98108-4522 USA We do not collect your code, prompts, AI responses, server URLs, or chat history. -We collect (via Sentry SDK for crash reporting): +We collect, only with your opt-in consent (single toggle, default OFF): + +Via Sentry SDK (crash reporting): - Device model, OS version, app version - Stack traces of crashes and unhandled errors - App breadcrumbs (function names, screen names — no message bodies) -Data is sent to Sentry (sentry.io) and retained per Sentry defaults (~90 days). +Via PostHog SDK (anonymous usage analytics, EU region): +- Activation-funnel events: app_opened, connection_form_submitted, + connection_attempted, connection_succeeded, connection_failed, + message_sent, response_received +- Only coarse properties (e.g. mode=quick/advanced, error_class=timeout); + never server URLs, prompts, code, or raw error text + +Via our own Chatwoot support inbox (support.agentlabs.cc), only when you tap +"Share Report": +- The same diagnostic report shown in the OS share sheet: connection + classification, probe results, device info, and recent app logs +- Every URL and every hostname/IP probed this session is redacted first — + your server address never reaches this inbox +- A random per-install identifier links follow-up reports into the same + support conversation; not linked to your name, email, or account + +Data is sent to Sentry (sentry.io, ~90 days retention), PostHog +(eu.i.posthog.com, standard retention), and our Chatwoot instance +(support.agentlabs.cc, retained until the conversation is resolved and +periodically purged thereafter). Third-party services: - Sentry — crash reporting. https://sentry.io/privacy/ +- PostHog — usage analytics. https://posthog.com/privacy -Data sharing: none beyond Sentry. +Self-hosted infrastructure: +- Chatwoot support inbox (support.agentlabs.cc) — we operate this + ourselves; it is not a third-party vendor. + +Data sharing: none beyond Sentry, PostHog, and our own Chatwoot support inbox. User rights: -- Email support@agentlabs.cc to request deletion of crash records associated with your device. +- Email support@agentlabs.cc to request deletion of crash records, analytics + records, or shared support-report conversations associated with your device. Contact: support@agentlabs.cc ``` @@ -203,7 +230,7 @@ Google requires this before publishing. Answers for OpenCode Mobile current stat | Question | Answer | |---|---| | Does your app collect or share any of the required user data types? | Yes | -| Is all of the user data collected by your app encrypted in transit? | Yes (HTTPS to Sentry) | +| Is all of the user data collected by your app encrypted in transit? | Yes (HTTPS to Sentry, PostHog, and our Chatwoot support inbox) | | Do you provide a way for users to request that their data is deleted? | Yes — via support@agentlabs.cc | ### Data types collected @@ -211,8 +238,9 @@ Google requires this before publishing. Answers for OpenCode Mobile current stat | Data type | Collected? | Shared? | Optional? | Purpose | Encrypted in transit? | |---|---|---|---|---|---| | App crash logs (Diagnostics) | Yes | Yes (Sentry) | **Yes (opt-in, default OFF)** | App functionality, diagnostics | Yes | -| App performance / interactions | No | – | – | – | – | -| Device or other IDs | No | – | – | – | – | +| App interactions (App activity) | Yes | Yes (PostHog) | **Yes (opt-in, default OFF, same toggle)** | Analytics (activation funnel: app opened, connection attempted/succeeded/failed, message sent, response received) | Yes | +| Device or other IDs | Yes | Yes (Sentry/PostHog anonymous IDs) | **Yes (opt-in, default OFF)** | Diagnostics, analytics — random app-generated IDs, not linked to identity | Yes | +| User-submitted diagnostic reports (Diagnostics) | Yes | Yes (delivered to our own self-hosted Chatwoot support inbox) | **Yes (opt-in, default OFF, same toggle; also requires the user to manually tap "Share Report")** | Customer support — troubleshooting a connection failure or crash the user chose to report; server address always redacted first | Yes | | Personal info (name, email, etc.) | No | – | – | – | – | | Financial info | No | – | – | – | – | | Health / fitness | No | – | – | – | – | diff --git a/distribution/privacy-policy.html b/distribution/privacy-policy.html index 19c370f..bb90a42 100644 --- a/distribution/privacy-policy.html +++ b/distribution/privacy-policy.html @@ -97,8 +97,9 @@
Summary: OpenCode Mobile does not collect your code, prompts, AI responses, server URLs, or any chat content. All AI traffic goes directly from the app to your own - opencode server. We use Sentry only for anonymous crash diagnostics, and only with your - consent. + opencode server. With your consent, we use Sentry for anonymous crash diagnostics, PostHog + for anonymous usage analytics, and — only when you tap "Share Report" — deliver a + scrubbed copy of that diagnostic report to our support inbox.

1. Who We Are

@@ -178,20 +179,153 @@ No server hostname or port number ever leaves your device via Sentry.

+

3a. Data We Do Collect (Usage Analytics)

+

+ With the same explicit consent (a single opt-in covers both crash reporting and analytics), + we collect a small set of anonymous usage events via PostHog to understand + whether new users successfully connect to their server and start using the app + (an "activation funnel"). +

+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
EventWhen it firesProperties
app_openedOnce per app session, after consentis_first_open (true/false)
connection_form_submittedYou tap Connect/Save with a server URL enteredmode ("quick" or "advanced")
connection_attemptedA connection test startssource ("onboarding" or "edit_test")
connection_succeededThe connection test succeedssource
connection_failedThe connection test failssource, error_class (a coarse category such as "timeout" or + "unauthorized" — never the raw error text)
message_sentYou send a message to an agent session—
response_receivedAn agent response finishes—
+ +

+ What analytics events never contain: your server URL, hostname, IP address, + or port; prompts, messages, or AI responses; code or file contents; tokens or credentials; + raw error messages. Connection failures are reduced to a fixed list of coarse categories + before being sent. +

+

+ Analytics data is sent to PostHog's EU region (eu.i.posthog.com) + and is identified only by a random, app-generated anonymous ID — not linked to your name, + email, or any account. +

+

+ If you decline consent, no analytics is initialised and nothing is sent. If you revoke + consent later, analytics stops immediately and any events still buffered on the device are + discarded, not uploaded. +

+ +

3b. Data We Do Collect (Shared Support Reports)

+

+ When a connection fails or the app crashes, you can tap Share Report to open + your device's normal share sheet with a diagnostic report. If you have granted the same + consent that covers crash reporting and analytics, a copy of that report is also + delivered directly to our support inbox, hosted on our own Chatwoot instance + (support.agentlabs.cc) — this is infrastructure we operate ourselves, not a + third-party SaaS vendor. +

+ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
Data typeWhat is includedWhat is NOT included
Diagnostic summaryConnection classification (e.g. "server unreachable"), probe results, timing—
Device infoDevice model, OS version, app versionSerial number, IMEI, advertising ID
Recent app logsRecent internal log lines (screen names, function-level breadcrumbs)Message bodies, prompts, AI responses
Your server address—Never included — every URL and every hostname/IP the app probed this session is redacted before the report leaves your device
+ +

+ A random, per-install identifier (stored locally via secure device storage) links follow-up + reports from the same install into the same support conversation so we can reply to an + ongoing issue. This identifier is not linked to your name, email, or account — we only learn + contact details if you volunteer them in your own reply. +

+

+ Sharing a report is always a manual, explicit action — it is never sent automatically or in + the background. It is only delivered to the support inbox if you have granted consent; if you + decline or revoke consent, tapping Share Report still opens your device's + normal share sheet, but nothing reaches our support inbox. +

+

4. Consent and Control

- Crash reporting is opt-in and off by default. The first time you launch - the app you will see a consent prompt. You can change this at any time: + Crash reporting, usage analytics, and support-inbox delivery of shared reports are all + opt-in and off by default, controlled by a single consent decision. The + first time you launch the app you will see a consent prompt. You can change this at any time:

5. Third-Party Services

- We use one third-party service for diagnostics: + We use two third-party services, both consent-gated:

- We use no advertising networks, analytics platforms, social SDKs, or any other + We use no advertising networks, social SDKs, or any other third-party data collection services. The app contains no ads and no ad SDKs.

+

+ We also operate our own Chatwoot support-inbox instance + (support.agentlabs.cc, described in section 3b) to receive diagnostic reports + you explicitly choose to share. Unlike Sentry and PostHog, this is infrastructure we run + ourselves rather than a third-party vendor, but data sent to it still leaves your device and + is retained by us as described below. +

6. Data Retention

Crash reports sent to Sentry are retained for approximately 90 days, after which they are - automatically deleted per Sentry's retention defaults. + automatically deleted per Sentry's retention defaults. Usage analytics events sent to + PostHog are retained per PostHog's standard retention policy. Shared support reports + delivered to our Chatwoot inbox are retained until the associated support conversation is + resolved and periodically purged thereafter; email support@agentlabs.cc to request earlier + deletion of a specific report.

- We do not operate our own servers that store your data; there is no VIBE TECHNOLOGIES - back end involved in normal app usage. + Beyond that support inbox, we do not operate our own servers that store your data; there is + no other VIBE TECHNOLOGIES back end involved in normal app usage.

7. Your Rights

@@ -221,11 +372,13 @@ You have the right to:

@@ -243,7 +396,8 @@

9. Security

- All diagnostic data is transmitted over HTTPS (TLS 1.2+) to Sentry. We do not transmit + All diagnostic and analytics data — including shared support reports — is transmitted over + HTTPS (TLS 1.2+) to Sentry, PostHog, and our Chatwoot support inbox. We do not transmit any data over unencrypted connections. Your opencode server traffic uses whatever transport security your server provides — we recommend HTTPS for all self-hosted deployments.

@@ -296,13 +450,15 @@ Contact InfoNoN/ANo LocationNoN/ANo - Identifiers (Device ID)Yes (Sentry anonymous ID, with consent)NoNo + Identifiers (Device ID)Yes (Sentry / PostHog anonymous IDs, with consent)NoNo + Usage Data — Product InteractionYes (PostHog activation events, with consent)NoNo Diagnostics — Crash DataYes (Sentry, with consent)NoNo Diagnostics — Performance DataYes (Sentry, with consent)NoNo + Diagnostics — Other Diagnostic DataYes (shared support reports delivered to our Chatwoot inbox, only when the user taps "Share Report" with consent)NoNo All other categoriesNoN/ANo -

App Store Connect summary: Data Linked to You: None. Data Not Linked to You: Crash Data, Performance Data (when user consents). Tracking: No.

+

App Store Connect summary: Data Linked to You: None. Data Not Linked to You: Crash Data, Performance Data, Product Interaction, Other Diagnostic Data (when user consents). Tracking: No.