docs+consent: disclose activation analytics honestly across consent modal, privacy policy, and store docs (#81)

The app ships PostHog activation-funnel analytics gated behind the same
consent flag as Sentry, but the consent modal, Settings toggle, privacy
policy, and Play Data safety draft only mentioned crash reporting. Fix
the disclosure everywhere:

- TelemetryConsentModal: body + bullets + a11y labels now cover anonymous
  usage analytics (PostHog EU) alongside crash reports
- Settings: toggle renamed 'Crash Reports & Usage Analytics', description
  names both Sentry and PostHog
- Privacy policy (md + html + live gh-pages mirror): new section 3a with
  the full event/property table, PostHog EU destination, anonymous-ID
  statement, decline/revoke (drop-on-revoke) semantics; sections 4-7, 9
  and the Apple nutrition-label addendum updated for analytics
- play-listing.md: Data safety draft declares App interactions + Device
  or other IDs (opt-in, default OFF, shared with PostHog/Sentry)
- docs/playstore.md: Data safety row flipped to re-verify with pointer
  to the new design record
- docs/analytics.md: new design record — event schema, consent gating
  incl. buffered-event drop on revoke, disclosure surfaces to keep in
  sync, verification checklist (all TODO)
- website privacy page metadata mentions analytics opt-in

Closes #63


Claude-Session: https://claude.ai/code/session_01NJKAQ6HAikWGQK7PGZ5Y4E

Co-authored-by: engineer <engineer@gray-knight-m1.local>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Den
2026-07-17 03:28:00 -07:00
committed by GitHub
parent b52fa52a4c
commit 63f3ec3c7e
10 changed files with 569 additions and 75 deletions

View File

@@ -73,12 +73,12 @@ Then open the app, tap Connect, paste your server URL, and you're in. Your AI co
OpenCode Mobile is MIT licensed. Source code, issue tracker, and community at github.com/dzianisv/opencode-mobile. Contributions welcome. OpenCode Mobile is MIT licensed. Source code, issue tracker, and community at github.com/dzianisv/opencode-mobile. Contributions welcome.
<b>PRIVACY</b> <b>PRIVACY</b>
OpenCode Mobile does not collect your code, prompts, or AI responses. All traffic goes directly from the app to YOUR opencode server — never through our infrastructure. Optional Sentry crash reporting collects only device model, OS version, and stack traces (no message content). OpenCode Mobile does not collect your code, prompts, or AI responses. All traffic goes directly from the app to YOUR opencode server — never through our infrastructure. With your opt-in consent we use Sentry for crash diagnostics and PostHog for anonymous usage analytics (no PII, no message content, off by default). Diagnostic reports you share are also delivered to our support inbox.
Support: support@agentlabs.cc Support: support@agentlabs.cc
Issues: github.com/dzianisv/opencode-mobile/issues Issues: github.com/dzianisv/opencode-mobile/issues
``` ```
(3366/4000 chars) (3474/4000 chars)
> Supersedes the prior draft, which named a dated model ("GPT-4") and was missing the directory picker and reasoning-effort features shipped since. Model references are now version-free by design ("Claude, GPT, Gemini, or any other model") so this copy doesn't go stale again as model names change. > Supersedes the prior draft, which named a dated model ("GPT-4") and was missing the directory picker and reasoning-effort features shipped since. Model references are now version-free by design ("Claude, GPT, Gemini, or any other model") so this copy doesn't go stale again as model names change.
@@ -162,10 +162,10 @@ Issues: github.com/dzianisv/opencode-mobile/issues
Suggested path: `https://dzianisv.github.io/opencode-mobile/privacy/` Suggested path: `https://dzianisv.github.io/opencode-mobile/privacy/`
Privacy policy must cover: Privacy policy must cover:
- What data is collected (Sentry crash diagnostics: device model, OS version, stack trace; no user content) - What data is collected (Sentry crash diagnostics: device model, OS version, stack trace; PostHog usage analytics: activation-funnel events with coarse properties; Chatwoot shared support reports: scrubbed diagnostic reports sent only when the user taps "Share Report"; no user content in any of them)
- How data is used (debugging crashes only) - How data is used (debugging crashes; measuring whether new users successfully connect/activate; responding to user-initiated support reports)
- Third-party SDKs (Sentry — link to https://sentry.io/privacy/) - Third-party SDKs (Sentry — https://sentry.io/privacy/; PostHog — https://posthog.com/privacy) and our own self-hosted Chatwoot support inbox (support.agentlabs.cc — not a third-party vendor)
- Data retention (Sentry default 90 days) - Data retention (Sentry default 90 days; PostHog standard retention; Chatwoot support conversations retained until resolved, then periodically purged)
- User rights (delete request via email, contact us) - User rights (delete request via email, contact us)
- Contact: support@agentlabs.cc - Contact: support@agentlabs.cc
@@ -176,20 +176,47 @@ Operator: VIBE TECHNOLOGIES, LLC, 519 S Henderson St, Seattle WA 98108-4522 USA
We do not collect your code, prompts, AI responses, server URLs, or chat history. We do not collect your code, prompts, AI responses, server URLs, or chat history.
We collect (via Sentry SDK for crash reporting): We collect, only with your opt-in consent (single toggle, default OFF):
Via Sentry SDK (crash reporting):
- Device model, OS version, app version - Device model, OS version, app version
- Stack traces of crashes and unhandled errors - Stack traces of crashes and unhandled errors
- App breadcrumbs (function names, screen names — no message bodies) - App breadcrumbs (function names, screen names — no message bodies)
Data is sent to Sentry (sentry.io) and retained per Sentry defaults (~90 days). Via PostHog SDK (anonymous usage analytics, EU region):
- Activation-funnel events: app_opened, connection_form_submitted,
connection_attempted, connection_succeeded, connection_failed,
message_sent, response_received
- Only coarse properties (e.g. mode=quick/advanced, error_class=timeout);
never server URLs, prompts, code, or raw error text
Via our own Chatwoot support inbox (support.agentlabs.cc), only when you tap
"Share Report":
- The same diagnostic report shown in the OS share sheet: connection
classification, probe results, device info, and recent app logs
- Every URL and every hostname/IP probed this session is redacted first —
your server address never reaches this inbox
- A random per-install identifier links follow-up reports into the same
support conversation; not linked to your name, email, or account
Data is sent to Sentry (sentry.io, ~90 days retention), PostHog
(eu.i.posthog.com, standard retention), and our Chatwoot instance
(support.agentlabs.cc, retained until the conversation is resolved and
periodically purged thereafter).
Third-party services: Third-party services:
- Sentry — crash reporting. https://sentry.io/privacy/ - Sentry — crash reporting. https://sentry.io/privacy/
- PostHog — usage analytics. https://posthog.com/privacy
Data sharing: none beyond Sentry. Self-hosted infrastructure:
- Chatwoot support inbox (support.agentlabs.cc) — we operate this
ourselves; it is not a third-party vendor.
Data sharing: none beyond Sentry, PostHog, and our own Chatwoot support inbox.
User rights: User rights:
- Email support@agentlabs.cc to request deletion of crash records associated with your device. - Email support@agentlabs.cc to request deletion of crash records, analytics
records, or shared support-report conversations associated with your device.
Contact: support@agentlabs.cc Contact: support@agentlabs.cc
``` ```
@@ -203,7 +230,7 @@ Google requires this before publishing. Answers for OpenCode Mobile current stat
| Question | Answer | | Question | Answer |
|---|---| |---|---|
| Does your app collect or share any of the required user data types? | Yes | | Does your app collect or share any of the required user data types? | Yes |
| Is all of the user data collected by your app encrypted in transit? | Yes (HTTPS to Sentry) | | Is all of the user data collected by your app encrypted in transit? | Yes (HTTPS to Sentry, PostHog, and our Chatwoot support inbox) |
| Do you provide a way for users to request that their data is deleted? | Yes — via support@agentlabs.cc | | Do you provide a way for users to request that their data is deleted? | Yes — via support@agentlabs.cc |
### Data types collected ### Data types collected
@@ -211,8 +238,9 @@ Google requires this before publishing. Answers for OpenCode Mobile current stat
| Data type | Collected? | Shared? | Optional? | Purpose | Encrypted in transit? | | Data type | Collected? | Shared? | Optional? | Purpose | Encrypted in transit? |
|---|---|---|---|---|---| |---|---|---|---|---|---|
| App crash logs (Diagnostics) | Yes | Yes (Sentry) | **Yes (opt-in, default OFF)** | App functionality, diagnostics | Yes | | App crash logs (Diagnostics) | Yes | Yes (Sentry) | **Yes (opt-in, default OFF)** | App functionality, diagnostics | Yes |
| App performance / interactions | No | – | – | – | – | | App interactions (App activity) | Yes | Yes (PostHog) | **Yes (opt-in, default OFF, same toggle)** | Analytics (activation funnel: app opened, connection attempted/succeeded/failed, message sent, response received) | Yes |
| Device or other IDs | No | – | – | – | – | | Device or other IDs | Yes | Yes (Sentry/PostHog anonymous IDs) | **Yes (opt-in, default OFF)** | Diagnostics, analytics — random app-generated IDs, not linked to identity | Yes |
| User-submitted diagnostic reports (Diagnostics) | Yes | Yes (delivered to our own self-hosted Chatwoot support inbox) | **Yes (opt-in, default OFF, same toggle; also requires the user to manually tap "Share Report")** | Customer support — troubleshooting a connection failure or crash the user chose to report; server address always redacted first | Yes |
| Personal info (name, email, etc.) | No | – | – | – | – | | Personal info (name, email, etc.) | No | – | – | – | – |
| Financial info | No | – | – | – | – | | Financial info | No | – | – | – | – |
| Health / fitness | No | – | – | – | – | | Health / fitness | No | – | – | – | – |

View File

@@ -97,8 +97,9 @@
<div class="highlight-box"> <div class="highlight-box">
<strong>Summary:</strong> OpenCode Mobile does not collect your code, prompts, AI responses, <strong>Summary:</strong> OpenCode Mobile does not collect your code, prompts, AI responses,
server URLs, or any chat content. All AI traffic goes directly from the app to your own server URLs, or any chat content. All AI traffic goes directly from the app to your own
opencode server. We use Sentry only for anonymous crash diagnostics, and only with your opencode server. With your consent, we use Sentry for anonymous crash diagnostics, PostHog
consent. for anonymous usage analytics, and — only when you tap &quot;Share Report&quot; — deliver a
scrubbed copy of that diagnostic report to our support inbox.
</div> </div>
<h2>1. Who We Are</h2> <h2>1. Who We Are</h2>
@@ -178,20 +179,153 @@
No server hostname or port number ever leaves your device via Sentry. No server hostname or port number ever leaves your device via Sentry.
</p> </p>
<h2>3a. Data We Do Collect (Usage Analytics)</h2>
<p>
With the same explicit consent (a single opt-in covers both crash reporting and analytics),
we collect a small set of anonymous usage events via <strong>PostHog</strong> to understand
whether new users successfully connect to their server and start using the app
(an "activation funnel").
</p>
<table>
<thead>
<tr>
<th>Event</th>
<th>When it fires</th>
<th>Properties</th>
</tr>
</thead>
<tbody>
<tr>
<td><code>app_opened</code></td>
<td>Once per app session, after consent</td>
<td><code>is_first_open</code> (true/false)</td>
</tr>
<tr>
<td><code>connection_form_submitted</code></td>
<td>You tap Connect/Save with a server URL entered</td>
<td><code>mode</code> ("quick" or "advanced")</td>
</tr>
<tr>
<td><code>connection_attempted</code></td>
<td>A connection test starts</td>
<td><code>source</code> ("onboarding" or "edit_test")</td>
</tr>
<tr>
<td><code>connection_succeeded</code></td>
<td>The connection test succeeds</td>
<td><code>source</code></td>
</tr>
<tr>
<td><code>connection_failed</code></td>
<td>The connection test fails</td>
<td><code>source</code>, <code>error_class</code> (a coarse category such as "timeout" or
"unauthorized" — never the raw error text)</td>
</tr>
<tr>
<td><code>message_sent</code></td>
<td>You send a message to an agent session</td>
<td>—</td>
</tr>
<tr>
<td><code>response_received</code></td>
<td>An agent response finishes</td>
<td>—</td>
</tr>
</tbody>
</table>
<p>
What analytics events <strong>never</strong> contain: your server URL, hostname, IP address,
or port; prompts, messages, or AI responses; code or file contents; tokens or credentials;
raw error messages. Connection failures are reduced to a fixed list of coarse categories
before being sent.
</p>
<p>
Analytics data is sent to PostHog's <strong>EU region</strong> (<code>eu.i.posthog.com</code>)
and is identified only by a random, app-generated anonymous ID — not linked to your name,
email, or any account.
</p>
<p>
If you decline consent, no analytics is initialised and nothing is sent. If you revoke
consent later, analytics stops immediately and any events still buffered on the device are
discarded, not uploaded.
</p>
<h2>3b. Data We Do Collect (Shared Support Reports)</h2>
<p>
When a connection fails or the app crashes, you can tap <strong>Share Report</strong> to open
your device's normal share sheet with a diagnostic report. If you have granted the same
consent that covers crash reporting and analytics, a copy of that report is <em>also</em>
delivered directly to our support inbox, hosted on our own <strong>Chatwoot</strong> instance
(<code>support.agentlabs.cc</code>) — this is infrastructure we operate ourselves, not a
third-party SaaS vendor.
</p>
<table>
<thead>
<tr>
<th>Data type</th>
<th>What is included</th>
<th>What is NOT included</th>
</tr>
</thead>
<tbody>
<tr>
<td>Diagnostic summary</td>
<td>Connection classification (e.g. "server unreachable"), probe results, timing</td>
<td>—</td>
</tr>
<tr>
<td>Device info</td>
<td>Device model, OS version, app version</td>
<td>Serial number, IMEI, advertising ID</td>
</tr>
<tr>
<td>Recent app logs</td>
<td>Recent internal log lines (screen names, function-level breadcrumbs)</td>
<td>Message bodies, prompts, AI responses</td>
</tr>
<tr>
<td>Your server address</td>
<td>—</td>
<td>Never included — every URL and every hostname/IP the app probed this session is redacted before the report leaves your device</td>
</tr>
</tbody>
</table>
<p>
A random, per-install identifier (stored locally via secure device storage) links follow-up
reports from the same install into the same support conversation so we can reply to an
ongoing issue. This identifier is not linked to your name, email, or account — we only learn
contact details if you volunteer them in your own reply.
</p>
<p>
Sharing a report is always a manual, explicit action — it is never sent automatically or in
the background. It is only delivered to the support inbox if you have granted consent; if you
decline or revoke consent, tapping <strong>Share Report</strong> still opens your device's
normal share sheet, but nothing reaches our support inbox.
</p>
<h2>4. Consent and Control</h2> <h2>4. Consent and Control</h2>
<p> <p>
Crash reporting is <strong>opt-in and off by default</strong>. The first time you launch Crash reporting, usage analytics, and support-inbox delivery of shared reports are all
the app you will see a consent prompt. You can change this at any time: <strong>opt-in and off by default</strong>, controlled by a single consent decision. The
first time you launch the app you will see a consent prompt. You can change this at any time:
</p> </p>
<ul> <ul>
<li>Open the app → <strong>Settings</strong> → <strong>Privacy</strong> → <li>Open the app → <strong>Settings</strong> → <strong>Privacy</strong> →
<strong>Crash reporting</strong> toggle.</li> <strong>Crash Reports &amp; Usage Analytics</strong> toggle.</li>
<li>If you decline, Sentry is never initialised. If you turn reporting off later, the active SDK is closed and no new events are captured.</li> <li>If you decline, neither Sentry nor PostHog is ever initialised, and shared reports are
never delivered to our support inbox (only your device's normal share sheet is used).
If you turn the toggle off later, both SDKs are shut down, no new events are captured,
analytics events still buffered on the device are dropped without being sent, and future
shared reports stop reaching the support inbox.</li>
</ul> </ul>
<h2>5. Third-Party Services</h2> <h2>5. Third-Party Services</h2>
<p> <p>
We use one third-party service for diagnostics: We use two third-party services, both consent-gated:
</p> </p>
<ul> <ul>
<li> <li>
@@ -200,20 +334,37 @@
Data is sent to Sentry's US-based servers and retained for approximately 90 days Data is sent to Sentry's US-based servers and retained for approximately 90 days
per Sentry's default data-retention policy. per Sentry's default data-retention policy.
</li> </li>
<li>
<strong>PostHog</strong> — anonymous usage analytics (the activation-funnel events listed
in section 3a).<br>
Privacy policy: <a href="https://posthog.com/privacy" target="_blank" rel="noopener">posthog.com/privacy</a><br>
Data is sent to PostHog's EU-region servers (<code>eu.i.posthog.com</code>).
</li>
</ul> </ul>
<p> <p>
We use no advertising networks, analytics platforms, social SDKs, or any other We use no advertising networks, social SDKs, or any other
third-party data collection services. The app contains no ads and no ad SDKs. third-party data collection services. The app contains no ads and no ad SDKs.
</p> </p>
<p>
We also operate our own <strong>Chatwoot</strong> support-inbox instance
(<code>support.agentlabs.cc</code>, described in section 3b) to receive diagnostic reports
you explicitly choose to share. Unlike Sentry and PostHog, this is infrastructure we run
ourselves rather than a third-party vendor, but data sent to it still leaves your device and
is retained by us as described below.
</p>
<h2>6. Data Retention</h2> <h2>6. Data Retention</h2>
<p> <p>
Crash reports sent to Sentry are retained for approximately 90 days, after which they are Crash reports sent to Sentry are retained for approximately 90 days, after which they are
automatically deleted per Sentry's retention defaults. automatically deleted per Sentry's retention defaults. Usage analytics events sent to
PostHog are retained per PostHog's standard retention policy. Shared support reports
delivered to our Chatwoot inbox are retained until the associated support conversation is
resolved and periodically purged thereafter; email support@agentlabs.cc to request earlier
deletion of a specific report.
</p> </p>
<p> <p>
We do not operate our own servers that store your data; there is no VIBE TECHNOLOGIES Beyond that support inbox, we do not operate our own servers that store your data; there is
back end involved in normal app usage. no other VIBE TECHNOLOGIES back end involved in normal app usage.
</p> </p>
<h2>7. Your Rights</h2> <h2>7. Your Rights</h2>
@@ -221,11 +372,13 @@
You have the right to: You have the right to:
</p> </p>
<ul> <ul>
<li><strong>Opt out</strong> — disable crash reporting at any time in Settings → Privacy.</li> <li><strong>Opt out</strong> — disable crash reporting, usage analytics, and support-inbox
delivery of shared reports at any time in Settings → Privacy.</li>
<li><strong>Request deletion</strong> — email <a href="mailto:support@agentlabs.cc">support@agentlabs.cc</a> <li><strong>Request deletion</strong> — email <a href="mailto:support@agentlabs.cc">support@agentlabs.cc</a>
with subject "Data deletion request" and we will request deletion of any crash events with subject "Data deletion request" and we will request deletion of any crash events
associated with your device from Sentry. Include your device model and approximate date (Sentry), analytics events (PostHog), and shared support-report conversations (Chatwoot)
range to help us identify your records.</li> associated with your device. Include your device model and approximate date range to
help us identify your records.</li>
<li><strong>Access</strong> — request a summary of what diagnostic data (if any) we hold <li><strong>Access</strong> — request a summary of what diagnostic data (if any) we hold
about your device by emailing the same address.</li> about your device by emailing the same address.</li>
</ul> </ul>
@@ -243,7 +396,8 @@
<h2>9. Security</h2> <h2>9. Security</h2>
<p> <p>
All diagnostic data is transmitted over HTTPS (TLS 1.2+) to Sentry. We do not transmit All diagnostic and analytics data — including shared support reports — is transmitted over
HTTPS (TLS 1.2+) to Sentry, PostHog, and our Chatwoot support inbox. We do not transmit
any data over unencrypted connections. Your opencode server traffic uses whatever transport any data over unencrypted connections. Your opencode server traffic uses whatever transport
security your server provides — we recommend HTTPS for all self-hosted deployments. security your server provides — we recommend HTTPS for all self-hosted deployments.
</p> </p>
@@ -296,13 +450,15 @@
<tbody> <tbody>
<tr><td style="border:1px solid #e2e8f0;padding:8px;">Contact Info</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td><td style="border:1px solid #e2e8f0;padding:8px;">N/A</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td></tr> <tr><td style="border:1px solid #e2e8f0;padding:8px;">Contact Info</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td><td style="border:1px solid #e2e8f0;padding:8px;">N/A</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td></tr>
<tr><td style="border:1px solid #e2e8f0;padding:8px;">Location</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td><td style="border:1px solid #e2e8f0;padding:8px;">N/A</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td></tr> <tr><td style="border:1px solid #e2e8f0;padding:8px;">Location</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td><td style="border:1px solid #e2e8f0;padding:8px;">N/A</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td></tr>
<tr><td style="border:1px solid #e2e8f0;padding:8px;">Identifiers (Device ID)</td><td style="border:1px solid #e2e8f0;padding:8px;">Yes (Sentry anonymous ID, with consent)</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td></tr> <tr><td style="border:1px solid #e2e8f0;padding:8px;">Identifiers (Device ID)</td><td style="border:1px solid #e2e8f0;padding:8px;">Yes (Sentry / PostHog anonymous IDs, with consent)</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td></tr>
<tr><td style="border:1px solid #e2e8f0;padding:8px;">Usage Data — Product Interaction</td><td style="border:1px solid #e2e8f0;padding:8px;">Yes (PostHog activation events, with consent)</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td></tr>
<tr><td style="border:1px solid #e2e8f0;padding:8px;">Diagnostics — Crash Data</td><td style="border:1px solid #e2e8f0;padding:8px;">Yes (Sentry, with consent)</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td></tr> <tr><td style="border:1px solid #e2e8f0;padding:8px;">Diagnostics — Crash Data</td><td style="border:1px solid #e2e8f0;padding:8px;">Yes (Sentry, with consent)</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td></tr>
<tr><td style="border:1px solid #e2e8f0;padding:8px;">Diagnostics — Performance Data</td><td style="border:1px solid #e2e8f0;padding:8px;">Yes (Sentry, with consent)</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td></tr> <tr><td style="border:1px solid #e2e8f0;padding:8px;">Diagnostics — Performance Data</td><td style="border:1px solid #e2e8f0;padding:8px;">Yes (Sentry, with consent)</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td></tr>
<tr><td style="border:1px solid #e2e8f0;padding:8px;">Diagnostics — Other Diagnostic Data</td><td style="border:1px solid #e2e8f0;padding:8px;">Yes (shared support reports delivered to our Chatwoot inbox, only when the user taps "Share Report" with consent)</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td></tr>
<tr><td style="border:1px solid #e2e8f0;padding:8px;">All other categories</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td><td style="border:1px solid #e2e8f0;padding:8px;">N/A</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td></tr> <tr><td style="border:1px solid #e2e8f0;padding:8px;">All other categories</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td><td style="border:1px solid #e2e8f0;padding:8px;">N/A</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td></tr>
</tbody> </tbody>
</table> </table>
<p><strong>App Store Connect summary:</strong> Data Linked to You: <em>None</em>. Data Not Linked to You: <em>Crash Data, Performance Data</em> (when user consents). Tracking: <em>No</em>.</p> <p><strong>App Store Connect summary:</strong> Data Linked to You: <em>None</em>. Data Not Linked to You: <em>Crash Data, Performance Data, Product Interaction, Other Diagnostic Data</em> (when user consents). Tracking: <em>No</em>.</p>
<footer> <footer>
&copy; 2026 VIBE TECHNOLOGIES, LLC. OpenCode Mobile is MIT-licensed open-source software. &copy; 2026 VIBE TECHNOLOGIES, LLC. OpenCode Mobile is MIT-licensed open-source software.

View File

@@ -4,7 +4,7 @@
**Operator:** VIBE TECHNOLOGIES, LLC **Operator:** VIBE TECHNOLOGIES, LLC
**App:** OpenCode Mobile (`cc.agentlabs.opencode`) **App:** OpenCode Mobile (`cc.agentlabs.opencode`)
> **Summary:** OpenCode Mobile does not collect your code, prompts, AI responses, server URLs, or any chat content. All AI traffic goes directly from the app to your own opencode server. We use Sentry only for anonymous crash diagnostics, and only with your consent. > **Summary:** OpenCode Mobile does not collect your code, prompts, AI responses, server URLs, or any chat content. All AI traffic goes directly from the app to your own opencode server. With your consent, we use Sentry for anonymous crash diagnostics, PostHog for anonymous usage analytics, and — only when you tap "Share Report" — deliver a scrubbed copy of that diagnostic report to our support inbox.
--- ---
@@ -48,34 +48,78 @@ With your explicit consent (shown at first launch), we collect anonymous crash d
URL scrubbing: before any event is sent to Sentry, our code strips all server URLs, authentication tokens, and query parameters. No server hostname or port number ever leaves your device via Sentry. URL scrubbing: before any event is sent to Sentry, our code strips all server URLs, authentication tokens, and query parameters. No server hostname or port number ever leaves your device via Sentry.
## 3a. Data We Do Collect (Usage Analytics)
With the same explicit consent (there is a single opt-in covering both crash reporting and analytics), we collect a small set of anonymous usage events via **PostHog** to understand whether new users successfully connect to their server and start using the app (an "activation funnel").
Events collected, with their only properties:
| Event | When it fires | Properties |
|---|---|---|
| `app_opened` | Once per app session, after consent | `is_first_open` (true/false) |
| `connection_form_submitted` | You tap Connect/Save with a server URL entered | `mode` ("quick" or "advanced") |
| `connection_attempted` | A connection test starts | `source` ("onboarding" or "edit_test") |
| `connection_succeeded` | The connection test succeeds | `source` |
| `connection_failed` | The connection test fails | `source`, `error_class` (a coarse category such as "timeout" or "unauthorized" — never the raw error text) |
| `message_sent` | You send a message to an agent session | — |
| `response_received` | An agent response finishes | — |
What analytics events **never** contain: your server URL, hostname, IP address, or port; prompts, messages, or AI responses; code or file contents; tokens or credentials; raw error messages. Connection failures are reduced to a fixed list of coarse categories before being sent.
Analytics data is sent to PostHog's **EU region** (`eu.i.posthog.com`) and is identified only by a random, app-generated anonymous ID — not linked to your name, email, or any account.
If you decline consent, no analytics is initialised and nothing is sent. If you revoke consent later, analytics stops immediately and any events still buffered on the device are discarded, not uploaded.
---
## 3b. Data We Do Collect (Shared Support Reports)
When a connection fails or the app crashes, you can tap **Share Report** to open your device's normal share sheet with a diagnostic report. If you have granted the same consent that covers crash reporting and analytics, a copy of that report is *also* delivered directly to our support inbox, hosted on our own **Chatwoot** instance (`support.agentlabs.cc`) — this is infrastructure we operate ourselves, not a third-party SaaS vendor.
| Data type | What is included | What is NOT included |
|---|---|---|
| Diagnostic summary | Connection classification (e.g. "server unreachable"), probe results, timing | — |
| Device info | Device model, OS version, app version | Serial number, IMEI, advertising ID |
| Recent app logs | Recent internal log lines (screen names, function-level breadcrumbs) | Message bodies, prompts, AI responses |
| Your server address | — | Never included — every URL and every hostname/IP the app probed this session is redacted before the report leaves your device |
A random, per-install identifier (stored locally via secure device storage) links follow-up reports from the same install into the same support conversation so we can reply to an ongoing issue. This identifier is not linked to your name, email, or account — we only learn contact details if you volunteer them in your own reply.
Sharing a report is always a manual, explicit action — it is never sent automatically or in the background. It is only delivered to the support inbox if you have granted consent; if you decline or revoke consent, tapping **Share Report** still opens your device's normal share sheet, but nothing reaches our support inbox.
--- ---
## 4. Consent and Control ## 4. Consent and Control
Crash reporting is **opt-in and off by default**. On first launch you will see a consent prompt. You can change this at any time: Crash reporting, usage analytics, and support-inbox delivery of shared reports are all **opt-in and off by default**, controlled by a single consent decision. On first launch you will see a consent prompt. You can change this at any time:
- Open the app → **Settings** → **Privacy** → **Crash reporting** toggle. - Open the app → **Settings** → **Privacy** → **Crash Reports & Usage Analytics** toggle.
- If you decline, Sentry is never initialised. If you turn reporting off later, the active SDK is closed and no new events are captured. - If you decline, neither Sentry nor PostHog is ever initialised, and shared reports are never delivered to our support inbox (only your device's normal share sheet is used). If you turn the toggle off later, both SDKs are shut down, no new events are captured, analytics events still buffered on the device are dropped without being sent, and future shared reports stop reaching the support inbox.
--- ---
## 5. Third-Party Services ## 5. Third-Party Services
We use one third-party service for diagnostics: We use two third-party services, both consent-gated:
- **Sentry** — crash and error monitoring. - **Sentry** — crash and error monitoring.
- Privacy policy: https://sentry.io/privacy/ - Privacy policy: https://sentry.io/privacy/
- Data is sent to Sentry's US-based servers and retained for approximately 90 days per Sentry's default data-retention policy. - Data is sent to Sentry's US-based servers and retained for approximately 90 days per Sentry's default data-retention policy.
- **PostHog** — anonymous usage analytics (the activation-funnel events listed in section 3a).
- Privacy policy: https://posthog.com/privacy
- Data is sent to PostHog's EU-region servers (`eu.i.posthog.com`).
We use no advertising networks, analytics platforms, social SDKs, or any other third-party data collection services. The app contains no ads and no ad SDKs. We use no advertising networks, social SDKs, or any other third-party data collection services. The app contains no ads and no ad SDKs.
We also operate our own **Chatwoot** support-inbox instance (`support.agentlabs.cc`, described in section 3b) to receive diagnostic reports you explicitly choose to share. Unlike Sentry and PostHog, this is infrastructure we run ourselves rather than a third-party vendor, but data sent to it still leaves your device and is retained by us as described below.
--- ---
## 6. Data Retention ## 6. Data Retention
Crash reports sent to Sentry are retained for approximately 90 days, after which they are automatically deleted per Sentry's retention defaults. Crash reports sent to Sentry are retained for approximately 90 days, after which they are automatically deleted per Sentry's retention defaults. Usage analytics events sent to PostHog are retained per PostHog's standard retention policy. Shared support reports delivered to our Chatwoot inbox are retained until the associated support conversation is resolved and periodically purged thereafter; email support@agentlabs.cc to request earlier deletion of a specific report.
We do not operate our own servers that store your data; there is no VIBE TECHNOLOGIES back end involved in normal app usage. Beyond that support inbox, we do not operate our own servers that store your data; there is no other VIBE TECHNOLOGIES back end involved in normal app usage.
--- ---
@@ -83,8 +127,8 @@ We do not operate our own servers that store your data; there is no VIBE TECHNOL
You have the right to: You have the right to:
- **Opt out** — disable crash reporting at any time in Settings → Privacy. - **Opt out** — disable crash reporting, usage analytics, and support-inbox delivery of shared reports at any time in Settings → Privacy.
- **Request deletion** — email support@agentlabs.cc with subject "Data deletion request" and we will request deletion of any crash events associated with your device from Sentry. - **Request deletion** — email support@agentlabs.cc with subject "Data deletion request" and we will request deletion of any crash events (Sentry), analytics events (PostHog), and shared support-report conversations (Chatwoot) associated with your device.
- **Access** — request a summary of what diagnostic data (if any) we hold about your device by emailing the same address. - **Access** — request a summary of what diagnostic data (if any) we hold about your device by emailing the same address.
Residents of the EU/EEA/UK may exercise rights under GDPR/UK GDPR. California residents may exercise rights under the CCPA. Residents of the EU/EEA/UK may exercise rights under GDPR/UK GDPR. California residents may exercise rights under the CCPA.
@@ -99,7 +143,7 @@ OpenCode Mobile is a developer tool intended for users aged 18 and over. We do n
## 9. Security ## 9. Security
All diagnostic data is transmitted over HTTPS (TLS 1.2+) to Sentry. We do not transmit any data over unencrypted connections. All diagnostic and analytics data — including shared support reports — is transmitted over HTTPS (TLS 1.2+) to Sentry, PostHog, and our Chatwoot support inbox. We do not transmit any data over unencrypted connections.
--- ---
@@ -151,14 +195,14 @@ The following table maps our data practices to Apple's official App Privacy cate
| Browsing History | Any | No | N/A | No | | Browsing History | Any | No | N/A | No |
| Search History | Any | No | N/A | No | | Search History | Any | No | N/A | No |
| Identifiers | User ID | No | N/A | No | | Identifiers | User ID | No | N/A | No |
| Identifiers | Device ID | Yes (Sentry anonymous ID) | No — not linked to Apple ID or personal info | No | | Identifiers | Device ID | Yes (Sentry / PostHog anonymous IDs) | No — not linked to Apple ID or personal info | No |
| Purchases | Any | No | N/A | No | | Purchases | Any | No | N/A | No |
| Usage Data | Product interaction | No | N/A | No | | Usage Data | Product interaction | Yes (PostHog activation events, with consent) | No | No |
| Diagnostics | Crash Data | Yes (Sentry, with consent) | No | No | | Diagnostics | Crash Data | Yes (Sentry, with consent) | No | No |
| Diagnostics | Performance Data | Yes (Sentry, with consent) | No | No | | Diagnostics | Performance Data | Yes (Sentry, with consent) | No | No |
| Diagnostics | Other Diagnostic Data | No | N/A | No | | Diagnostics | Other Diagnostic Data | Yes (shared support reports delivered to our Chatwoot inbox, only when the user taps "Share Report" with consent) | No | No |
**Summary for App Store Connect App Privacy section**: **Summary for App Store Connect App Privacy section**:
- Data Linked to You: **None** - Data Linked to You: **None**
- Data Not Linked to You: **Crash Data, Performance Data** (Sentry diagnostics, when user consents) - Data Not Linked to You: **Crash Data, Performance Data** (Sentry diagnostics, when user consents), **Product Interaction** (PostHog activation events, when user consents), **Other Diagnostic Data** (shared support reports via Chatwoot, when user consents)
- Tracking: **No** - Tracking: **No**

100
docs/analytics.md Normal file
View File

@@ -0,0 +1,100 @@
# Activation Analytics — Design Record
Design record for the PostHog-based activation-funnel analytics added to OpenCode Mobile,
and how it is disclosed and consent-gated. Companion to `docs/playstore.md` (Data safety)
and `distribution/privacy-policy.md` (user-facing policy). GitHub issue: #63.
> **Note:** the same consent flag also gates a third, separate data flow not covered by this
> doc: delivery of user-shared diagnostic reports to our self-hosted Chatwoot support inbox
> (`src/lib/chatwoot.ts`, `src/lib/diagnostics.ts`, issue #85/#88). That flow is triggered
> manually ("Share Report"), not automatic like Sentry/PostHog. It is disclosed alongside
> Sentry and PostHog in every surface in the table below; see `distribution/privacy-policy.md`
> §3b for the full description.
---
## Goal
Answer one product question: **do new users successfully connect to their opencode server
and reach first value (message sent → response received)?** Nothing else is tracked.
## SDK and destination
| Item | Value |
|---|---|
| SDK | `posthog-react-native`, self-instantiated (no `PostHogProvider`, no autocapture) |
| Destination | PostHog **EU region** — `https://eu.i.posthog.com` (override: `EXPO_PUBLIC_POSTHOG_HOST`) |
| API key | `EXPO_PUBLIC_POSTHOG_KEY` (CI secret; unset ⇒ analytics is a strict no-op) |
| Identity | PostHog's random app-generated anonymous ID only; no `identify()` calls, no user IDs |
| Code | `src/lib/analytics.ts` (wrapper), `src/lib/analytics-classify.ts` (error bucketing), `src/lib/telemetry.ts` (consent gate) |
## Event schema
Keep this table in 1:1 sync with `AnalyticsEvent` in `src/lib/analytics.ts` and with
section 3a of `distribution/privacy-policy.md`.
| Event | Fired when | Properties | Call site |
|---|---|---|---|
| `app_opened` | Once per JS session, as soon as analytics is enabled (cold start with prior consent, or immediately after consent grant) | `is_first_open: boolean` | `app/_layout.tsx`, `src/lib/telemetry.ts` |
| `connection_form_submitted` | User taps Connect/Save with a non-empty server URL | `mode: "quick" \| "advanced"` | `app/connection/add.tsx` |
| `connection_attempted` | A real connection test starts (advanced mode: fired on save, no pre-flight check) | `source: "onboarding" \| "edit_test"` | `src/stores/connections.ts`, `app/connection/add.tsx` |
| `connection_succeeded` | Health check responds OK | `source` | `src/stores/connections.ts` |
| `connection_failed` | Health check fails | `source`, `error_class` | `src/stores/connections.ts` |
| `message_sent` | User sends a prompt to an agent session (excludes slash commands) | — | `src/stores/sessions.ts` |
| `response_received` | Agent response finishes streaming (busy → idle), excluding user-aborted runs | — | `src/stores/events.ts` |
`error_class` is one of a fixed enum — `malformed-url`, `no-internet`, `server-unreachable`,
`unauthorized`, `tls-error`, `timeout`, `unknown` (`src/lib/analytics-classify.ts`). The raw
error string is never sent (it can embed hostnames/IPs/tokens).
**PII rule:** properties are flat primitives only (`AnalyticsProps`). Never add server URLs,
hostnames, ports, prompts, message/file content, tokens, or raw error text. Adding any new
event or property requires updating the privacy policy (section 3a) and the consent modal
copy in the same PR.
## Consent gating
Single consent flag (`opencode_telemetry_consent` in expo-secure-store) gates **both**
Sentry and PostHog — there is no separate analytics toggle. Managed by `src/lib/telemetry.ts`.
- **Off by default.** First launch shows `TelemetryConsentModal` (discloses crash reports
AND usage analytics). No SDK is initialised before a "granted" decision.
- **Grant:** `initSentry()` + `initAnalytics()`; `app_opened` fires (once-per-session guard).
- **Decline / never asked:** `track()` is a strict no-op; the PostHog client is never created;
nothing is written locally (the first-open flag is only touched post-consent).
- **Revoke (Settings → Privacy → Crash Reports & Usage Analytics):**
- Sentry client closed.
- PostHog: **buffered-but-unsent events are DROPPED, not flushed.** `ConsentGatedPostHog`
overrides the SDK `fetch()` transport; after revocation every request short-circuits to a
synthetic 200, so `shutdown()` drains the queue with zero bytes leaving the device. SDK
`optOut()` is persisted first so a re-created client can't capture either.
- **Re-grant mid-session:** `optIn()` clears the persisted opt-out; the `app_opened`
session guard prevents double-counting.
## Disclosure surfaces (must stay in sync)
| Surface | File |
|---|---|
| First-launch consent modal | `src/components/TelemetryConsentModal.tsx` |
| Settings toggle label/description | `app/(tabs)/settings.tsx` |
| Privacy policy (canonical md) | `distribution/privacy-policy.md` §3a, §3b, §4, §5 |
| Privacy policy (store/site html) | `distribution/privacy-policy.html`, `docs/privacy/index.html` (live gh-pages) |
| Play Data safety draft | `distribution/play-listing.md` |
| Play ops checklist | `docs/playstore.md` item 7 |
| Apple nutrition label | Apple addendum in `distribution/privacy-policy.md` (Usage Data → Product Interaction: Yes) |
## Verification checklist — TODO
Not yet verified end-to-end. Each item needs a real device/emulator run with a network
sniffer or PostHog live-events view:
- [ ] TODO: Fresh install → decline consent → exercise full app flow → confirm zero requests to `eu.i.posthog.com` and `sentry.io`.
- [ ] TODO: Fresh install → allow consent → confirm `app_opened` arrives with `is_first_open=true`; second launch sends `is_first_open=false`.
- [ ] TODO: Onboarding quick-connect success path emits `connection_form_submitted(mode=quick)` → `connection_attempted(source=onboarding)` → `connection_succeeded`.
- [ ] TODO: Failure path emits `connection_failed` with a coarse `error_class` and no raw error text/hostname in the payload.
- [ ] TODO: Send message + receive response emits `message_sent` and `response_received`; aborted run emits no `response_received`.
- [ ] TODO: Revoke mid-session while offline (events buffered) → go online → confirm buffered events are dropped (no PostHog traffic after revoke).
- [ ] TODO: Revoke → re-grant in same session → `app_opened` not double-counted.
- [ ] TODO: Build without `EXPO_PUBLIC_POSTHOG_KEY` → analytics is a complete no-op (no init log, no network).
- [ ] TODO: Inspect one real payload of every event type in PostHog and confirm property allowlist matches the schema table above.
- [ ] TODO: Play Console Data safety form re-submitted to match `distribution/play-listing.md` draft before next release.

View File

@@ -65,7 +65,7 @@ For full company facts (D-U-N-S, address, governor, etc.) see `~/.agents/skills/
| 4 | Feature graphic — 1024×500 PNG | Agent | ✅ done — `distribution/play-graphics/feature-graphic.png` | | 4 | Feature graphic — 1024×500 PNG | Agent | ✅ done — `distribution/play-graphics/feature-graphic.png` |
| 5 | At least 2 phone screenshots (1080×1920 or similar) | Agent | ✅ done — `distribution/play-graphics/phone-{01,02,03}.png` (1080×2400 each; 3 screens: connection, chat, diff viewer) | | 5 | At least 2 phone screenshots (1080×1920 or similar) | Agent | ✅ done — `distribution/play-graphics/phone-{01,02,03}.png` (1080×2400 each; 3 screens: connection, chat, diff viewer) |
| 6 | Privacy policy — live at https://dzianisv.github.io/opencode-mobile/privacy/ | Agent | ✅ done — live & verified (HTTP 200) on gh-pages; `distribution/privacy-policy.html` (source), `distribution/privacy-policy.md` (markdown mirror) | | 6 | Privacy policy — live at https://dzianisv.github.io/opencode-mobile/privacy/ | Agent | ✅ done — live & verified (HTTP 200) on gh-pages; `distribution/privacy-policy.html` (source), `distribution/privacy-policy.md` (markdown mirror) |
| 7 | Data safety form answers (drafted in `distribution/play-listing.md`) | User (in Console after app created) | ✅ verified — no analytics/ad SDKs found; crash logs updated to "Optional (opt-in, default OFF)" per new consent gate | | 7 | Data safety form answers (drafted in `distribution/play-listing.md`) | User (in Console after app created) | ⚠️ re-verify — app now ships PostHog usage analytics (posthog-react-native) alongside Sentry, plus Chatwoot delivery of user-shared diagnostic reports (#88), all behind the same opt-in consent gate. Data safety draft updated: declare "App interactions" + "Device or other IDs" as collected, optional, shared with PostHog/Sentry; declare "User-submitted diagnostic reports" as collected, optional, shared with our self-hosted Chatwoot inbox. See `docs/analytics.md` |
| 8 | Content rating questionnaire (IARC, drafted) | User (in Console after app created) | ✅ verified — no violence/sexual/gambling/UGC; "interact with other users" = No (user talks to own AI agent) | | 8 | Content rating questionnaire (IARC, drafted) | User (in Console after app created) | ✅ verified — no violence/sexual/gambling/UGC; "interact with other users" = No (user talks to own AI agent) |
| 9 | App access — reviewer instructions for self-hosted opencode (drafted) | User | ✅ verified — instructions accurate; `npm install -g opencode-ai && opencode serve` flow confirmed in `play-listing.md` | | 9 | App access — reviewer instructions for self-hosted opencode (drafted) | User | ✅ verified — instructions accurate; `npm install -g opencode-ai && opencode serve` flow confirmed in `play-listing.md` |
| 10 | Sentry opt-in consent gate (for F-Droid parity + GDPR friendly) | Agent | ✅ done — `src/lib/telemetry.ts` (consent store), `src/components/TelemetryConsentModal.tsx` (first-launch modal), `app/_layout.tsx` (gated init), `app/(tabs)/settings.tsx` (Privacy section toggle) | | 10 | Sentry opt-in consent gate (for F-Droid parity + GDPR friendly) | Agent | ✅ done — `src/lib/telemetry.ts` (consent store), `src/components/TelemetryConsentModal.tsx` (first-launch modal), `app/_layout.tsx` (gated init), `app/(tabs)/settings.tsx` (Privacy section toggle) |

View File

@@ -104,8 +104,9 @@
<div class="highlight-box"> <div class="highlight-box">
<strong>Summary:</strong> OpenCode Mobile does not collect your code, prompts, AI responses, <strong>Summary:</strong> OpenCode Mobile does not collect your code, prompts, AI responses,
server URLs, or any chat content. All AI traffic goes directly from the app to your own server URLs, or any chat content. All AI traffic goes directly from the app to your own
opencode server. We use Sentry only for anonymous crash diagnostics, and only with your opencode server. With your consent, we use Sentry for anonymous crash diagnostics, PostHog
consent. for anonymous usage analytics, and — only when you tap &quot;Share Report&quot; — deliver a
scrubbed copy of that diagnostic report to our support inbox.
</div> </div>
<h2>1. Who We Are</h2> <h2>1. Who We Are</h2>
@@ -185,20 +186,153 @@
No server hostname or port number ever leaves your device via Sentry. No server hostname or port number ever leaves your device via Sentry.
</p> </p>
<h2>3a. Data We Do Collect (Usage Analytics)</h2>
<p>
With the same explicit consent (a single opt-in covers both crash reporting and analytics),
we collect a small set of anonymous usage events via <strong>PostHog</strong> to understand
whether new users successfully connect to their server and start using the app
(an "activation funnel").
</p>
<table>
<thead>
<tr>
<th>Event</th>
<th>When it fires</th>
<th>Properties</th>
</tr>
</thead>
<tbody>
<tr>
<td><code>app_opened</code></td>
<td>Once per app session, after consent</td>
<td><code>is_first_open</code> (true/false)</td>
</tr>
<tr>
<td><code>connection_form_submitted</code></td>
<td>You tap Connect/Save with a server URL entered</td>
<td><code>mode</code> ("quick" or "advanced")</td>
</tr>
<tr>
<td><code>connection_attempted</code></td>
<td>A connection test starts</td>
<td><code>source</code> ("onboarding" or "edit_test")</td>
</tr>
<tr>
<td><code>connection_succeeded</code></td>
<td>The connection test succeeds</td>
<td><code>source</code></td>
</tr>
<tr>
<td><code>connection_failed</code></td>
<td>The connection test fails</td>
<td><code>source</code>, <code>error_class</code> (a coarse category such as "timeout" or
"unauthorized" — never the raw error text)</td>
</tr>
<tr>
<td><code>message_sent</code></td>
<td>You send a message to an agent session</td>
<td>—</td>
</tr>
<tr>
<td><code>response_received</code></td>
<td>An agent response finishes</td>
<td>—</td>
</tr>
</tbody>
</table>
<p>
What analytics events <strong>never</strong> contain: your server URL, hostname, IP address,
or port; prompts, messages, or AI responses; code or file contents; tokens or credentials;
raw error messages. Connection failures are reduced to a fixed list of coarse categories
before being sent.
</p>
<p>
Analytics data is sent to PostHog's <strong>EU region</strong> (<code>eu.i.posthog.com</code>)
and is identified only by a random, app-generated anonymous ID — not linked to your name,
email, or any account.
</p>
<p>
If you decline consent, no analytics is initialised and nothing is sent. If you revoke
consent later, analytics stops immediately and any events still buffered on the device are
discarded, not uploaded.
</p>
<h2>3b. Data We Do Collect (Shared Support Reports)</h2>
<p>
When a connection fails or the app crashes, you can tap <strong>Share Report</strong> to open
your device's normal share sheet with a diagnostic report. If you have granted the same
consent that covers crash reporting and analytics, a copy of that report is <em>also</em>
delivered directly to our support inbox, hosted on our own <strong>Chatwoot</strong> instance
(<code>support.agentlabs.cc</code>) — this is infrastructure we operate ourselves, not a
third-party SaaS vendor.
</p>
<table>
<thead>
<tr>
<th>Data type</th>
<th>What is included</th>
<th>What is NOT included</th>
</tr>
</thead>
<tbody>
<tr>
<td>Diagnostic summary</td>
<td>Connection classification (e.g. "server unreachable"), probe results, timing</td>
<td>—</td>
</tr>
<tr>
<td>Device info</td>
<td>Device model, OS version, app version</td>
<td>Serial number, IMEI, advertising ID</td>
</tr>
<tr>
<td>Recent app logs</td>
<td>Recent internal log lines (screen names, function-level breadcrumbs)</td>
<td>Message bodies, prompts, AI responses</td>
</tr>
<tr>
<td>Your server address</td>
<td>—</td>
<td>Never included — every URL and every hostname/IP the app probed this session is redacted before the report leaves your device</td>
</tr>
</tbody>
</table>
<p>
A random, per-install identifier (stored locally via secure device storage) links follow-up
reports from the same install into the same support conversation so we can reply to an
ongoing issue. This identifier is not linked to your name, email, or account — we only learn
contact details if you volunteer them in your own reply.
</p>
<p>
Sharing a report is always a manual, explicit action — it is never sent automatically or in
the background. It is only delivered to the support inbox if you have granted consent; if you
decline or revoke consent, tapping <strong>Share Report</strong> still opens your device's
normal share sheet, but nothing reaches our support inbox.
</p>
<h2>4. Consent and Control</h2> <h2>4. Consent and Control</h2>
<p> <p>
Crash reporting is <strong>opt-in and off by default</strong>. The first time you launch Crash reporting, usage analytics, and support-inbox delivery of shared reports are all
the app you will see a consent prompt. You can change this at any time: <strong>opt-in and off by default</strong>, controlled by a single consent decision. The
first time you launch the app you will see a consent prompt. You can change this at any time:
</p> </p>
<ul> <ul>
<li>Open the app → <strong>Settings</strong> → <strong>Privacy</strong> → <li>Open the app → <strong>Settings</strong> → <strong>Privacy</strong> →
<strong>Crash reporting</strong> toggle.</li> <strong>Crash Reports &amp; Usage Analytics</strong> toggle.</li>
<li>When the toggle is off, Sentry is never initialised and no data leaves your device.</li> <li>When the toggle is off, neither Sentry nor PostHog is ever initialised and no data
leaves your device, and shared reports are never delivered to our support inbox (only
your device's normal share sheet is used). If you turn the toggle off later, both SDKs
are shut down, analytics events still buffered on the device are dropped without being
sent, and future shared reports stop reaching the support inbox.</li>
</ul> </ul>
<h2>5. Third-Party Services</h2> <h2>5. Third-Party Services</h2>
<p> <p>
We use one third-party service for diagnostics: We use two third-party services, both consent-gated:
</p> </p>
<ul> <ul>
<li> <li>
@@ -207,20 +341,37 @@
Data is sent to Sentry's US-based servers and retained for approximately 90 days Data is sent to Sentry's US-based servers and retained for approximately 90 days
per Sentry's default data-retention policy. per Sentry's default data-retention policy.
</li> </li>
<li>
<strong>PostHog</strong> — anonymous usage analytics (the activation-funnel events listed
in section 3a).<br>
Privacy policy: <a href="https://posthog.com/privacy" target="_blank" rel="noopener">posthog.com/privacy</a><br>
Data is sent to PostHog's EU-region servers (<code>eu.i.posthog.com</code>).
</li>
</ul> </ul>
<p> <p>
We use no advertising networks, analytics platforms, social SDKs, or any other We use no advertising networks, social SDKs, or any other
third-party data collection services. The app contains no ads and no ad SDKs. third-party data collection services. The app contains no ads and no ad SDKs.
</p> </p>
<p>
We also operate our own <strong>Chatwoot</strong> support-inbox instance
(<code>support.agentlabs.cc</code>, described in section 3b) to receive diagnostic reports
you explicitly choose to share. Unlike Sentry and PostHog, this is infrastructure we run
ourselves rather than a third-party vendor, but data sent to it still leaves your device and
is retained by us as described below.
</p>
<h2>6. Data Retention</h2> <h2>6. Data Retention</h2>
<p> <p>
Crash reports sent to Sentry are retained for approximately 90 days, after which they are Crash reports sent to Sentry are retained for approximately 90 days, after which they are
automatically deleted per Sentry's retention defaults. automatically deleted per Sentry's retention defaults. Usage analytics events sent to
PostHog are retained per PostHog's standard retention policy. Shared support reports
delivered to our Chatwoot inbox are retained until the associated support conversation is
resolved and periodically purged thereafter; email support@agentlabs.cc to request earlier
deletion of a specific report.
</p> </p>
<p> <p>
We do not operate our own servers that store your data; there is no VIBE TECHNOLOGIES Beyond that support inbox, we do not operate our own servers that store your data; there is
back end involved in normal app usage. no other VIBE TECHNOLOGIES back end involved in normal app usage.
</p> </p>
<h2>7. Your Rights</h2> <h2>7. Your Rights</h2>
@@ -228,11 +379,13 @@
You have the right to: You have the right to:
</p> </p>
<ul> <ul>
<li><strong>Opt out</strong> — disable crash reporting at any time in Settings → Privacy.</li> <li><strong>Opt out</strong> — disable crash reporting, usage analytics, and support-inbox
delivery of shared reports at any time in Settings → Privacy.</li>
<li><strong>Request deletion</strong> — email <a href="mailto:support@agentlabs.cc">support@agentlabs.cc</a> <li><strong>Request deletion</strong> — email <a href="mailto:support@agentlabs.cc">support@agentlabs.cc</a>
with subject "Data deletion request" and we will request deletion of any crash events with subject "Data deletion request" and we will request deletion of any crash events
associated with your device from Sentry. Include your device model and approximate date (Sentry), analytics events (PostHog), and shared support-report conversations (Chatwoot)
range to help us identify your records.</li> associated with your device. Include your device model and approximate date range to
help us identify your records.</li>
<li><strong>Access</strong> — request a summary of what diagnostic data (if any) we hold <li><strong>Access</strong> — request a summary of what diagnostic data (if any) we hold
about your device by emailing the same address.</li> about your device by emailing the same address.</li>
</ul> </ul>
@@ -250,7 +403,8 @@
<h2>9. Security</h2> <h2>9. Security</h2>
<p> <p>
All diagnostic data is transmitted over HTTPS (TLS 1.2+) to Sentry. We do not transmit All diagnostic and analytics data — including shared support reports — is transmitted over
HTTPS (TLS 1.2+) to Sentry, PostHog, and our Chatwoot support inbox. We do not transmit
any data over unencrypted connections. Your opencode server traffic uses whatever transport any data over unencrypted connections. Your opencode server traffic uses whatever transport
security your server provides — we recommend HTTPS for all self-hosted deployments. security your server provides — we recommend HTTPS for all self-hosted deployments.
</p> </p>
@@ -303,13 +457,15 @@
<tbody> <tbody>
<tr><td style="border:1px solid #e2e8f0;padding:8px;">Contact Info</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td><td style="border:1px solid #e2e8f0;padding:8px;">N/A</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td></tr> <tr><td style="border:1px solid #e2e8f0;padding:8px;">Contact Info</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td><td style="border:1px solid #e2e8f0;padding:8px;">N/A</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td></tr>
<tr><td style="border:1px solid #e2e8f0;padding:8px;">Location</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td><td style="border:1px solid #e2e8f0;padding:8px;">N/A</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td></tr> <tr><td style="border:1px solid #e2e8f0;padding:8px;">Location</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td><td style="border:1px solid #e2e8f0;padding:8px;">N/A</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td></tr>
<tr><td style="border:1px solid #e2e8f0;padding:8px;">Identifiers (Device ID)</td><td style="border:1px solid #e2e8f0;padding:8px;">Yes (Sentry anonymous ID, with consent)</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td></tr> <tr><td style="border:1px solid #e2e8f0;padding:8px;">Identifiers (Device ID)</td><td style="border:1px solid #e2e8f0;padding:8px;">Yes (Sentry / PostHog anonymous IDs, with consent)</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td></tr>
<tr><td style="border:1px solid #e2e8f0;padding:8px;">Usage Data — Product Interaction</td><td style="border:1px solid #e2e8f0;padding:8px;">Yes (PostHog activation events, with consent)</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td></tr>
<tr><td style="border:1px solid #e2e8f0;padding:8px;">Diagnostics — Crash Data</td><td style="border:1px solid #e2e8f0;padding:8px;">Yes (Sentry, with consent)</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td></tr> <tr><td style="border:1px solid #e2e8f0;padding:8px;">Diagnostics — Crash Data</td><td style="border:1px solid #e2e8f0;padding:8px;">Yes (Sentry, with consent)</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td></tr>
<tr><td style="border:1px solid #e2e8f0;padding:8px;">Diagnostics — Performance Data</td><td style="border:1px solid #e2e8f0;padding:8px;">Yes (Sentry, with consent)</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td></tr> <tr><td style="border:1px solid #e2e8f0;padding:8px;">Diagnostics — Performance Data</td><td style="border:1px solid #e2e8f0;padding:8px;">Yes (Sentry, with consent)</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td></tr>
<tr><td style="border:1px solid #e2e8f0;padding:8px;">Diagnostics — Other Diagnostic Data</td><td style="border:1px solid #e2e8f0;padding:8px;">Yes (shared support reports delivered to our Chatwoot inbox, only when the user taps "Share Report" with consent)</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td></tr>
<tr><td style="border:1px solid #e2e8f0;padding:8px;">All other categories</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td><td style="border:1px solid #e2e8f0;padding:8px;">N/A</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td></tr> <tr><td style="border:1px solid #e2e8f0;padding:8px;">All other categories</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td><td style="border:1px solid #e2e8f0;padding:8px;">N/A</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td></tr>
</tbody> </tbody>
</table> </table>
<p><strong>App Store Connect summary:</strong> Data Linked to You: <em>None</em>. Data Not Linked to You: <em>Crash Data, Performance Data</em> (when user consents). Tracking: <em>No</em>.</p> <p><strong>App Store Connect summary:</strong> Data Linked to You: <em>None</em>. Data Not Linked to You: <em>Crash Data, Performance Data, Product Interaction, Other Diagnostic Data</em> (when user consents). Tracking: <em>No</em>.</p>
<footer> <footer>
&copy; 2026 VIBE TECHNOLOGIES, LLC. OpenCode Mobile is MIT-licensed open-source software. &copy; 2026 VIBE TECHNOLOGIES, LLC. OpenCode Mobile is MIT-licensed open-source software.

View File

@@ -1,5 +1,9 @@
/** /**
* First-launch consent modal for Sentry crash reporting. * First-launch consent modal for crash reporting AND activation analytics.
*
* A single "Allow" decision gates both Sentry (crash reports) and PostHog
* (anonymous usage analytics) — see src/lib/telemetry.ts. There is no
* separate toggle for analytics, so this modal must disclose both.
* *
* Shows once when the user hasn't yet made a consent decision. * Shows once when the user hasn't yet made a consent decision.
* Matches the app's existing Settings screen visual conventions. * Matches the app's existing Settings screen visual conventions.
@@ -33,15 +37,21 @@ export function TelemetryConsentModal({ visible, onAllow, onDecline }: Props) {
{/* Body */} {/* Body */}
<Text style={[styles.body, isDark && styles.bodyDark]}> <Text style={[styles.body, isDark && styles.bodyDark]}>
Share anonymous crash reports to help us find and fix bugs faster. Diagnostic reports Share anonymous crash reports and usage analytics to help us find and fix bugs
you share are also delivered to our support inbox. No code, prompts, or server faster. Diagnostic reports you share are also delivered to our support inbox. No
addresses are ever included. code, prompts, or server addresses are ever included.
</Text> </Text>
{/* Detail bullets */} {/* Detail bullets */}
<View style={styles.bullets}> <View style={styles.bullets}>
<BulletRow icon="checkmark-circle" text="Device model, OS version, app version" isDark={isDark} positive /> <BulletRow icon="checkmark-circle" text="Device model, OS version, app version" isDark={isDark} positive />
<BulletRow icon="checkmark-circle" text="Stack traces of crashes (no variable values)" isDark={isDark} positive /> <BulletRow icon="checkmark-circle" text="Stack traces of crashes (no variable values)" isDark={isDark} positive />
<BulletRow
icon="checkmark-circle"
text="Anonymous usage events (app opened, connection attempts, messages sent) — sent to PostHog EU"
isDark={isDark}
positive
/>
<BulletRow icon="close-circle" text="Your code, prompts, or chat messages" isDark={isDark} positive={false} /> <BulletRow icon="close-circle" text="Your code, prompts, or chat messages" isDark={isDark} positive={false} />
<BulletRow icon="close-circle" text="Server URLs or authentication tokens" isDark={isDark} positive={false} /> <BulletRow icon="close-circle" text="Server URLs or authentication tokens" isDark={isDark} positive={false} />
</View> </View>
@@ -56,7 +66,7 @@ export function TelemetryConsentModal({ visible, onAllow, onDecline }: Props) {
<TouchableOpacity <TouchableOpacity
style={[styles.btn, styles.btnDecline, isDark && styles.btnDeclineDark]} style={[styles.btn, styles.btnDecline, isDark && styles.btnDeclineDark]}
onPress={onDecline} onPress={onDecline}
accessibilityLabel="No thanks, decline crash reporting" accessibilityLabel="No thanks, decline crash reporting and analytics"
testID="telemetry-decline-button" testID="telemetry-decline-button"
> >
<Text style={[styles.btnDeclineText, isDark && styles.btnDeclineTextDark]}>No thanks</Text> <Text style={[styles.btnDeclineText, isDark && styles.btnDeclineTextDark]}>No thanks</Text>
@@ -64,7 +74,7 @@ export function TelemetryConsentModal({ visible, onAllow, onDecline }: Props) {
<TouchableOpacity <TouchableOpacity
style={[styles.btn, styles.btnAllow]} style={[styles.btn, styles.btnAllow]}
onPress={onAllow} onPress={onAllow}
accessibilityLabel="Allow anonymous crash reports" accessibilityLabel="Allow anonymous crash reports and usage analytics"
testID="telemetry-allow-button" testID="telemetry-allow-button"
> >
<Text style={styles.btnAllowText}>Allow</Text> <Text style={styles.btnAllowText}>Allow</Text>

View File

@@ -29,8 +29,8 @@
}, },
"privacy": { "privacy": {
"crashReporting": { "crashReporting": {
"label": "Crash Reporting", "label": "Crash Reports & Usage Analytics",
"description": "Share anonymous crash reports via Sentry to help improve OpenCode. No code or prompts are included." "description": "Share anonymous crash reports (Sentry) and usage analytics (PostHog) to help improve OpenCode. Diagnostic reports you share are also delivered to our support inbox. No code or prompts are included."
}, },
"privacyPolicy": { "privacyPolicy": {
"label": "Privacy Policy", "label": "Privacy Policy",

View File

@@ -29,8 +29,8 @@
}, },
"privacy": { "privacy": {
"crashReporting": { "crashReporting": {
"label": "崩溃报告", "label": "崩溃报告与使用分析",
"description": "通过 Sentry 分享匿名崩溃报告,帮助改进 OpenCode。报告不包含代码或提示词内容。" "description": "分享匿名崩溃报告(Sentry)和使用分析(PostHog),帮助改进 OpenCode。您分享的诊断报告也会发送至我们的支持收件箱。不包含代码或提示词内容。"
}, },
"privacyPolicy": { "privacyPolicy": {
"label": "隐私政策", "label": "隐私政策",

View File

@@ -5,11 +5,11 @@ import path from 'path'
export const metadata: Metadata = { export const metadata: Metadata = {
title: 'Privacy Policy', title: 'Privacy Policy',
description: description:
'OpenCode Mobile privacy policy. We do not collect your code, prompts, or AI responses. Crash diagnostics via Sentry are opt-in only.', 'OpenCode Mobile privacy policy. We do not collect your code, prompts, or AI responses. Crash diagnostics (Sentry), usage analytics (PostHog), and shared support reports (Chatwoot) are opt-in only.',
alternates: { canonical: 'https://opencode.agentlabs.cc/privacy' }, alternates: { canonical: 'https://opencode.agentlabs.cc/privacy' },
openGraph: { openGraph: {
title: 'Privacy Policy | OpenCode Mobile', title: 'Privacy Policy | OpenCode Mobile',
description: 'OpenCode Mobile privacy policy — minimal data collection, opt-in crash reporting.', description: 'OpenCode Mobile privacy policy — minimal data collection, opt-in crash reporting and analytics.',
url: 'https://opencode.agentlabs.cc/privacy', url: 'https://opencode.agentlabs.cc/privacy',
}, },
} }