diff --git a/.github/workflows/ios-ci.yml b/.github/workflows/ios-ci.yml index 152fff4..4657cee 100644 --- a/.github/workflows/ios-ci.yml +++ b/.github/workflows/ios-ci.yml @@ -10,21 +10,16 @@ name: iOS CI +# NOTE: no paths-ignore here. "Typecheck and unit tests" is a REQUIRED status +# check in branch protection; a path-filtered required check never runs on +# docs-only PRs, leaving them permanently BLOCKED. Running the cheap Linux +# typecheck/test job (and the gated macOS build) on every PR keeps the required +# check satisfiable. See #143 (docs PR stuck) for why. on: pull_request: branches: [main] - paths-ignore: - - "**/*.md" - - "docs/**" - - "docs-site/**" - - "distribution/**" push: branches: [main] - paths-ignore: - - "**/*.md" - - "docs/**" - - "docs-site/**" - - "distribution/**" # Cancel superseded runs for the same ref (e.g. new push to an open PR). concurrency: diff --git a/PUBLISHING.md b/PUBLISHING.md index 1241759..b18fcd8 100644 --- a/PUBLISHING.md +++ b/PUBLISHING.md @@ -57,6 +57,57 @@ Production is **not** published by CI by default — the service account is scop - **Recommended — Play Console:** Production → Create release → **Add from library** → select the build by its **versionName** (e.g. `0.4.10`) and confirm its `versionCode` (the run_number-derived one, e.g. `142` — not the `app.json` number) → review → roll out. If the "What's new" field is empty, paste from `distribution/whatsnew/whatsnew-en-US`. No rebuild. - **Fully automated (optional):** grant the CI service account **"Release to production"** for this app in Play Console → Users & permissions, then run the workflow's `workflow_dispatch` with `track=production`, `status=completed`. **Without that permission the production dispatch fails with `The caller does not have permission` after building** — so don't dispatch `track=production` until the service account has been granted production access. +## Resubmitting after a Data Safety rejection (issue #143) + +Google Play rejected `cc.agentlabs.opencode` on 2026-07-22 because the app's Data Safety +declaration did not disclose collection of **Email Address**. Root cause: the "OpenCode +Connect" waitlist card on the Connect screen (`app/connection/add.tsx` → +`src/lib/waitlist.ts` → `POST https://opencode.agentlabs.cc/api/beta-signup`) collects an +email address when a user opts in, and the backend forwards it to **Brevo** (email +marketing/CRM). This was true collection that the Data Safety form did not declare — Play +requires *all* personal-info collection to be declared, even when it's optional and +unrelated to the app's core function. + +The repo-side declaration is now fixed (this PR): `distribution/play-listing.md` Data Safety +table, `distribution/privacy-policy.md`/`.html`, and `docs/privacy/index.html` all disclose +the email collection. To resubmit: + +1. **Play Console → your app → App content → Data safety → Manage**. +2. Under **Data types → Personal info**, check **Email address**. + - **Is this data collected, shared, or both?** → **Collected and shared**. + - **Is this data processed ephemerally?** → No. + - **Is data collection required for your app, or can users choose whether this data is + collected?** → **Users can choose whether this data is collected** (optional — only + collected if the user opts into the waitlist). + - **Why is this user data collected?** → check **Account management** (the waitlist is a + signup for the not-yet-launched hosted service). Optionally also check **App + functionality** if Console requires at least one additional purpose. + - Under sharing: declare it is shared with a third party (Brevo) for the same purpose. +3. Re-verify the existing declared types are still accurate (unchanged by this fix): + **App activity** (PostHog analytics), **App info and performance / Crash logs** (Sentry), + and **Diagnostics — user-submitted reports** (Chatwoot) — all opt-in, default OFF, shared + with the named third parties. See the full table in `distribution/play-listing.md` → + "Data safety form". +4. Confirm the **Privacy policy URL** field still points at + `https://dzianisv.github.io/opencode-mobile/privacy/` (now updated with the email + disclosure — `docs/privacy/index.html`, mirrored from `distribution/privacy-policy.md`). +5. Save, then **Send for review** (Play re-reviews Data Safety changes; this is separate from + a binary/release review since no code changed). +6. Once Data Safety is approved, resume any blocked release rollout (e.g. 0.4.12 and pending + retention fixes) — those builds themselves did not need to change, only the Console-side + declaration. + +**Known earlier blocker (if it resurfaces):** a prior release (v0.4.5) was blocked by Google +with a "Missing sign-in details" rejection under **App access**, not Data Safety — Play +reviewers could not exercise the app because it requires the user's own opencode server and +Play had no way to sign in / connect one. That was resolved (see `HANDOFF.md`) by providing +reviewer instructions plus a temporary demo server URL in the **App access** form (see the +reviewer-instructions block in `distribution/play-listing.md` → "App access"). If a future +review flags "sign-in details" again, the fix is the same: confirm **App access** still has +either working temporary credentials/demo server or an accurate "all functionality available +without sign-in" declaration — this is unrelated to the Data Safety fix in this PR, but is +the other known rejection mode for this app and worth checking in the same Console pass. + ## Fastlane (Alternative) A Fastlane setup is included for local publishing: diff --git a/distribution/play-listing.md b/distribution/play-listing.md index abaa720..849bf18 100644 --- a/distribution/play-listing.md +++ b/distribution/play-listing.md @@ -79,7 +79,7 @@ Then open the app, tap Connect, paste your server URL, and you're in. Your AI co OpenCode Mobile is MIT licensed. Source code, issue tracker, and community at github.com/dzianisv/opencode-mobile. Contributions welcome. PRIVACY -OpenCode Mobile does not collect your code, prompts, or AI responses. All traffic goes directly from the app to YOUR opencode server — never through our infrastructure. With your opt-in consent we use Sentry for crash diagnostics and PostHog for anonymous usage analytics (no PII, no message content, off by default). Diagnostic reports you share are also delivered to our support inbox. +OpenCode Mobile does not collect your code, prompts, or AI responses. All traffic goes directly from the app to YOUR opencode server — never through our infrastructure. With your opt-in consent we use Sentry for crash diagnostics and PostHog for anonymous usage analytics (no PII, no message content, off by default). Diagnostic reports you share are also delivered to our support inbox. If you choose to join the optional OpenCode Connect waitlist, we collect the email address you enter to notify you at launch. Support: support@agentlabs.cc Issues: github.com/dzianisv/opencode-mobile/issues @@ -168,10 +168,10 @@ Issues: github.com/dzianisv/opencode-mobile/issues Suggested path: `https://dzianisv.github.io/opencode-mobile/privacy/` Privacy policy must cover: -- What data is collected (Sentry crash diagnostics: device model, OS version, stack trace; PostHog usage analytics: activation-funnel events with coarse properties; Chatwoot shared support reports: scrubbed diagnostic reports sent only when the user taps "Share Report"; no user content in any of them) -- How data is used (debugging crashes; measuring whether new users successfully connect/activate; responding to user-initiated support reports) -- Third-party SDKs (Sentry — https://sentry.io/privacy/; PostHog — https://posthog.com/privacy) and our own self-hosted Chatwoot support inbox (support.agentlabs.cc — not a third-party vendor) -- Data retention (Sentry default 90 days; PostHog standard retention; Chatwoot support conversations retained until resolved, then periodically purged) +- What data is collected (Sentry crash diagnostics: device model, OS version, stack trace; PostHog usage analytics: activation-funnel events with coarse properties; Chatwoot shared support reports: scrubbed diagnostic reports sent only when the user taps "Share Report"; **email address: only if the user opts into the optional "OpenCode Connect" waitlist on the Connect screen** — no other user content in any of them) +- How data is used (debugging crashes; measuring whether new users successfully connect/activate; responding to user-initiated support reports; **notifying waitlist signups when the hosted service launches**) +- Third-party SDKs (Sentry — https://sentry.io/privacy/; PostHog — https://posthog.com/privacy; **Brevo — https://www.brevo.com/legal/privacypolicy/, used only for the optional waitlist**) and our own self-hosted Chatwoot support inbox (support.agentlabs.cc — not a third-party vendor) +- Data retention (Sentry default 90 days; PostHog standard retention; Chatwoot support conversations retained until resolved, then periodically purged; **waitlist emails retained in Brevo until the user unsubscribes or requests deletion**) - User rights (delete request via email, contact us) - Contact: support@agentlabs.cc @@ -205,24 +205,37 @@ Via our own Chatwoot support inbox (support.agentlabs.cc), only when you tap - A random per-install identifier links follow-up reports into the same support conversation; not linked to your name, email, or account +Separately, and independent of the consent toggle above, if you choose to +join the optional "OpenCode Connect" waitlist on the Connect screen: +- We collect the email address you type into that field +- We send it to Brevo, a third-party email marketing/CRM platform, to add + you to the waitlist and notify you when the hosted service launches +- This is entirely optional — nothing is collected unless you open the + waitlist card and submit an email + Data is sent to Sentry (sentry.io, ~90 days retention), PostHog -(eu.i.posthog.com, standard retention), and our Chatwoot instance +(eu.i.posthog.com, standard retention), Brevo (waitlist emails, retained +until you unsubscribe or request deletion), and our Chatwoot instance (support.agentlabs.cc, retained until the conversation is resolved and periodically purged thereafter). Third-party services: - Sentry — crash reporting. https://sentry.io/privacy/ - PostHog — usage analytics. https://posthog.com/privacy +- Brevo — waitlist email management (only if you join the waitlist). + https://www.brevo.com/legal/privacypolicy/ Self-hosted infrastructure: - Chatwoot support inbox (support.agentlabs.cc) — we operate this ourselves; it is not a third-party vendor. -Data sharing: none beyond Sentry, PostHog, and our own Chatwoot support inbox. +Data sharing: Sentry, PostHog, Brevo (waitlist only), and our own Chatwoot +support inbox. User rights: - Email support@agentlabs.cc to request deletion of crash records, analytics - records, or shared support-report conversations associated with your device. + records, waitlist email records, or shared support-report conversations + associated with your device. Contact: support@agentlabs.cc ``` @@ -236,7 +249,7 @@ Google requires this before publishing. Answers for OpenCode Mobile current stat | Question | Answer | |---|---| | Does your app collect or share any of the required user data types? | Yes | -| Is all of the user data collected by your app encrypted in transit? | Yes (HTTPS to Sentry, PostHog, and our Chatwoot support inbox) | +| Is all of the user data collected by your app encrypted in transit? | Yes (HTTPS to Sentry, PostHog, Brevo, and our Chatwoot support inbox) | | Do you provide a way for users to request that their data is deleted? | Yes — via support@agentlabs.cc | ### Data types collected @@ -247,7 +260,7 @@ Google requires this before publishing. Answers for OpenCode Mobile current stat | App interactions (App activity) | Yes | Yes (PostHog) | **Yes (opt-in, default OFF, same toggle)** | Analytics (activation funnel: app opened, connection attempted/succeeded/failed, message sent, response received) | Yes | | Device or other IDs | Yes | Yes (Sentry/PostHog anonymous IDs) | **Yes (opt-in, default OFF)** | Diagnostics, analytics — random app-generated IDs, not linked to identity | Yes | | User-submitted diagnostic reports (Diagnostics) | Yes | Yes (delivered to our own self-hosted Chatwoot support inbox) | **Yes (opt-in, default OFF, same toggle; also requires the user to manually tap "Share Report")** | Customer support — troubleshooting a connection failure or crash the user chose to report; server address always redacted first | Yes | -| Personal info (name, email, etc.) | No | – | – | – | – | +| Personal info — Email address | **Yes** | **Yes (Brevo, third-party email marketing/CRM platform)** | **Yes — entirely optional; only collected if the user opens the "OpenCode Connect" waitlist card on the Connect screen and submits an email. Independent of the Sentry/PostHog consent toggle.** | **Account management (waitlist signup for the not-yet-launched "OpenCode Connect" hosted service) / App functionality** | Yes | | Financial info | No | – | – | – | – | | Health / fitness | No | – | – | – | – | | Messages | No | – | – | – | – | diff --git a/distribution/privacy-policy.html b/distribution/privacy-policy.html index 6e3a028..cd45a36 100644 --- a/distribution/privacy-policy.html +++ b/distribution/privacy-policy.html @@ -88,7 +88,7 @@

OpenCode Mobile — Privacy Policy

- Effective date: 2026-07-18  |  + Effective date: 2026-07-23  |  Operator: VIBE TECHNOLOGIES, LLC  |  App: OpenCode Mobile (cc.agentlabs.opencode)

@@ -99,7 +99,9 @@ server URLs, or any chat content. All AI traffic goes directly from the app to your own opencode server. With your consent, we use Sentry for anonymous crash diagnostics, PostHog for anonymous usage analytics, and — only when you tap "Share Report" — deliver a - scrubbed copy of that diagnostic report to our support inbox. + scrubbed copy of that diagnostic report to our support inbox. If you choose to join the + optional "OpenCode Connect" waitlist, we collect the email address you submit and + share it with Brevo to notify you at launch.

1. Who We Are

@@ -124,12 +126,16 @@
  • Your prompts, chat messages, or AI responses
  • Your opencode server URL, IP address, or hostname
  • Authentication tokens, API keys, or credentials you enter
  • -
  • Account information, email addresses, or names
  • +
  • Account information or names
  • Location data
  • Photos, microphone recordings, or camera data (unless you attach them to a message, in which case they go only to your own server)
  • Contacts, calendar, or any other personal data
  • +

    + The one exception is your email address, and only if you choose to type it + in and join the optional "OpenCode Connect" waitlist — see section 3c below. +

    All communication between the app and your AI coding agent travels directly between your device and your self-hosted opencode server. VIBE TECHNOLOGIES, LLC never sees this traffic. @@ -329,6 +335,45 @@ normal share sheet, but nothing reaches our support inbox.

    +

    3c. Data We Do Collect (Optional Waitlist Signup)

    +

    + The Connect screen offers an optional waitlist for OpenCode + Connect, our not-yet-launched hosted opencode service. If you choose to type in your + email address and tap Join waitlist, we collect that email address and send + it to Brevo, a third-party email marketing/CRM platform, so we can add you to + the waitlist and notify you when the hosted service becomes available. +

    +

    + This is entirely separate from — and independent of — the crash-reporting/analytics consent + toggle described in section 4. It only happens if you open the waitlist card and submit an + email; if you never do, no email address is ever collected. +

    + + + + + + + + + + + + + + + + + + +
    Data typeWhat is collectedShared withPurpose
    Email addressThe email address you type into the waitlist fieldBrevo (email marketing/CRM platform)Notify you when OpenCode Connect launches; waitlist/account management
    + +

    + We do not use this email address for any other purpose (no other marketing, no ads, no sale + or rental to any other party). To unsubscribe or request deletion, use the unsubscribe link + in any waitlist email, or email support@agentlabs.cc. +

    +

    4. Consent and Control

    Crash reporting, usage analytics, and support-inbox delivery of shared reports are all @@ -347,21 +392,29 @@

    5. Third-Party Services

    - We use two third-party services, both consent-gated: + We use three third-party services:

    We use no advertising networks, social SDKs, or any other @@ -382,7 +435,8 @@ PostHog are retained per PostHog's standard retention policy. Shared support reports delivered to our Chatwoot inbox are retained until the associated support conversation is resolved and periodically purged thereafter; email support@agentlabs.cc to request earlier - deletion of a specific report. + deletion of a specific report. Waitlist email addresses submitted via the optional OpenCode + Connect waitlist are retained in Brevo until you unsubscribe or request deletion.

    Beyond that support inbox, we do not operate our own servers that store your data; there is @@ -395,12 +449,13 @@

    @@ -470,7 +525,8 @@ - Contact InfoNoN/ANo + Contact Info — Name/Phone/AddressNoN/ANo + Contact Info — Email AddressYes — only if you join the optional OpenCode Connect waitlistYes — stored in Brevo to contact you about the waitlistNo LocationNoN/ANo Identifiers (Device ID)Yes (Sentry / PostHog anonymous IDs, with consent)NoNo Usage Data — Product InteractionYes (PostHog activation events, with consent)NoNo @@ -480,11 +536,11 @@ All other categoriesNoN/ANo -

    App Store Connect summary: Data Linked to You: None. Data Not Linked to You: Crash Data, Performance Data, Product Interaction, Other Diagnostic Data (when user consents). Tracking: No.

    +

    App Store Connect summary: Data Linked to You: Email Address (only if you join the optional OpenCode Connect waitlist). Data Not Linked to You: Crash Data, Performance Data, Product Interaction, Other Diagnostic Data (when user consents). Tracking: No.

    diff --git a/distribution/privacy-policy.md b/distribution/privacy-policy.md index c966fdc..b7d1a8c 100644 --- a/distribution/privacy-policy.md +++ b/distribution/privacy-policy.md @@ -1,10 +1,10 @@ # OpenCode Mobile — Privacy Policy -**Effective date:** 2026-07-18 +**Effective date:** 2026-07-23 **Operator:** VIBE TECHNOLOGIES, LLC **App:** OpenCode Mobile (`cc.agentlabs.opencode`) -> **Summary:** OpenCode Mobile does not collect your code, prompts, AI responses, server URLs, or any chat content. All AI traffic goes directly from the app to your own opencode server. With your consent, we use Sentry for anonymous crash diagnostics, PostHog for anonymous usage analytics, and — only when you tap "Share Report" — deliver a scrubbed copy of that diagnostic report to our support inbox. +> **Summary:** OpenCode Mobile does not collect your code, prompts, AI responses, server URLs, or any chat content. All AI traffic goes directly from the app to your own opencode server. With your consent, we use Sentry for anonymous crash diagnostics, PostHog for anonymous usage analytics, and — only when you tap "Share Report" — deliver a scrubbed copy of that diagnostic report to our support inbox. If you choose to join the optional "OpenCode Connect" waitlist, we collect the email address you submit and share it with Brevo to notify you at launch. --- @@ -26,11 +26,14 @@ We never collect, transmit to our servers, or share with third parties: - Your prompts, chat messages, or AI responses - Your opencode server URL, IP address, or hostname - Authentication tokens, API keys, or credentials you enter -- Account information, email addresses, or names +- Account information or names - Location data - Photos, microphone recordings, or camera data (these go only to your own server if you attach them to a message) - Contacts, calendar, or any other personal data +The one exception is your **email address**, and only if you choose to type +it in and join the optional "OpenCode Connect" waitlist — see section 3c below. + All communication between the app and your AI coding agent travels directly between your device and your self-hosted opencode server. VIBE TECHNOLOGIES, LLC never sees this traffic. --- @@ -93,6 +96,20 @@ Sharing a report is always a manual, explicit action — it is never sent automa --- +## 3c. Data We Do Collect (Optional Waitlist Signup) + +The **Connect** screen offers an optional waitlist for **OpenCode Connect**, our not-yet-launched hosted opencode service. If you choose to type in your email address and tap **Join waitlist**, we collect that email address and send it to **Brevo**, a third-party email marketing/CRM platform, so we can add you to the waitlist and notify you when the hosted service becomes available. + +This is entirely separate from — and independent of — the crash-reporting/analytics consent toggle described in section 4. It only happens if you open the waitlist card and submit an email; if you never do, no email address is ever collected. + +| Data type | What is collected | Shared with | Purpose | +|---|---|---|---| +| Email address | The email address you type into the waitlist field | Brevo (email marketing/CRM platform) | Notify you when OpenCode Connect launches; waitlist/account management | + +We do not use this email address for any other purpose (no other marketing, no ads, no sale or rental to any other party). To unsubscribe or request deletion, use the unsubscribe link in any waitlist email, or email support@agentlabs.cc. + +--- + ## 4. Consent and Control Crash reporting, usage analytics, and support-inbox delivery of shared reports are all **opt-in and off by default**, controlled by a single consent decision. On first launch you will see a consent prompt. You can change this at any time: @@ -104,14 +121,17 @@ Crash reporting, usage analytics, and support-inbox delivery of shared reports a ## 5. Third-Party Services -We use two third-party services, both consent-gated: +We use three third-party services: -- **Sentry** — crash and error monitoring. +- **Sentry** — crash and error monitoring (consent-gated). - Privacy policy: https://sentry.io/privacy/ - Data is sent to Sentry's US-based servers and retained for approximately 90 days per Sentry's default data-retention policy. -- **PostHog** — anonymous usage analytics (the activation-funnel events listed in section 3a). +- **PostHog** — anonymous usage analytics (the activation-funnel events listed in section 3a; consent-gated). - Privacy policy: https://posthog.com/privacy - Data is sent to PostHog's EU-region servers (`eu.i.posthog.com`). +- **Brevo** — email marketing/CRM platform used only if you join the optional OpenCode Connect waitlist described in section 3c. This is a separate, independent action from the consent toggle above — nothing is sent to Brevo unless you submit an email to the waitlist form. + - Privacy policy: https://www.brevo.com/legal/privacypolicy/ + - Data sent: only the email address you submit to the waitlist form. We use no advertising networks, social SDKs, or any other third-party data collection services. The app contains no ads and no ad SDKs. @@ -121,7 +141,7 @@ We also operate our own **Chatwoot** support-inbox instance (`support.agentlabs. ## 6. Data Retention -Crash reports sent to Sentry are retained for approximately 90 days, after which they are automatically deleted per Sentry's retention defaults. Usage analytics events sent to PostHog are retained per PostHog's standard retention policy. Shared support reports delivered to our Chatwoot inbox are retained until the associated support conversation is resolved and periodically purged thereafter; email support@agentlabs.cc to request earlier deletion of a specific report. +Crash reports sent to Sentry are retained for approximately 90 days, after which they are automatically deleted per Sentry's retention defaults. Usage analytics events sent to PostHog are retained per PostHog's standard retention policy. Shared support reports delivered to our Chatwoot inbox are retained until the associated support conversation is resolved and periodically purged thereafter; email support@agentlabs.cc to request earlier deletion of a specific report. Waitlist email addresses submitted via the optional OpenCode Connect waitlist are retained in Brevo until you unsubscribe or request deletion. Beyond that support inbox, we do not operate our own servers that store your data; there is no other VIBE TECHNOLOGIES back end involved in normal app usage. @@ -131,8 +151,8 @@ Beyond that support inbox, we do not operate our own servers that store your dat You have the right to: -- **Opt out** — disable crash reporting, usage analytics, and support-inbox delivery of shared reports at any time in Settings → Privacy. -- **Request deletion** — email support@agentlabs.cc with subject "Data deletion request" and we will request deletion of any crash events (Sentry), analytics events (PostHog), and shared support-report conversations (Chatwoot) associated with your device. +- **Opt out** — disable crash reporting, usage analytics, and support-inbox delivery of shared reports at any time in Settings → Privacy. Unsubscribe from the waitlist at any time using the link in any waitlist email. +- **Request deletion** — email support@agentlabs.cc with subject "Data deletion request" and we will request deletion of any crash events (Sentry), analytics events (PostHog), shared support-report conversations (Chatwoot), and waitlist email records (Brevo) associated with your device or email address. - **Access** — request a summary of what diagnostic data (if any) we hold about your device by emailing the same address. Residents of the EU/EEA/UK may exercise rights under GDPR/UK GDPR. California residents may exercise rights under the CCPA. @@ -189,7 +209,8 @@ The following table maps our data practices to Apple's official App Privacy cate | Apple Category | Sub-category | Collected? | Linked to identity? | Used for tracking? | |---|---|---|---|---| -| Contact Info | Name, email, phone, address | No | N/A | No | +| Contact Info | Name, phone, address | No | N/A | No | +| Contact Info | Email Address | Yes — only if you join the optional OpenCode Connect waitlist and submit your email | Yes — the email itself identifies you and is stored in Brevo to contact you about the waitlist | No | | Health & Fitness | Any | No | N/A | No | | Financial Info | Any | No | N/A | No | | Location | Precise or coarse | No | N/A | No | @@ -207,6 +228,6 @@ The following table maps our data practices to Apple's official App Privacy cate | Diagnostics | Other Diagnostic Data | Yes (shared support reports delivered to our Chatwoot inbox, only when the user taps "Share Report" with consent) | No | No | **Summary for App Store Connect App Privacy section**: -- Data Linked to You: **None** +- Data Linked to You: **Email Address** (only if you join the optional OpenCode Connect waitlist) - Data Not Linked to You: **Crash Data, Performance Data** (Sentry diagnostics, when user consents), **Product Interaction** (PostHog activation events, when user consents), **Other Diagnostic Data** (shared support reports via Chatwoot, when user consents) - Tracking: **No** diff --git a/docs/playstore.md b/docs/playstore.md index eac6479..e790cd0 100644 --- a/docs/playstore.md +++ b/docs/playstore.md @@ -65,7 +65,7 @@ For full company facts (D-U-N-S, address, governor, etc.) see `~/.agents/skills/ | 4 | Feature graphic — 1024×500 PNG | Agent | ✅ done — `distribution/play-graphics/feature-graphic.png` | | 5 | At least 2 phone screenshots (1080×1920 or similar) | Agent | ✅ done — `distribution/play-graphics/phone-{01,02,03}.png` (1080×2400 each; 3 screens: connection, chat, diff viewer) | | 6 | Privacy policy — live at https://dzianisv.github.io/opencode-mobile/privacy/ | Agent | ✅ done — live & verified (HTTP 200) on gh-pages; `distribution/privacy-policy.html` (source), `distribution/privacy-policy.md` (markdown mirror) | -| 7 | Data safety form answers (drafted in `distribution/play-listing.md`) | User (in Console after app created) | ⚠️ re-verify — app now ships PostHog usage analytics (posthog-react-native) alongside Sentry, plus Chatwoot delivery of user-shared diagnostic reports (#88), all behind the same opt-in consent gate. Data safety draft updated: declare "App interactions" + "Device or other IDs" as collected, optional, shared with PostHog/Sentry; declare "User-submitted diagnostic reports" as collected, optional, shared with our self-hosted Chatwoot inbox. See `docs/analytics.md` | +| 7 | Data safety form answers (drafted in `distribution/play-listing.md`) | User (in Console after app created) | ⚠️ **re-submit required (#143)** — Google rejected `cc.agentlabs.opencode` on 2026-07-22 because the Data Safety declaration did not disclose collection of Email Address (the "OpenCode Connect" waitlist on the Connect screen collects an email and forwards it to Brevo). Fixed in repo: `distribution/play-listing.md` Data Safety table now declares "Personal info — Email address" (collected, shared with Brevo, optional, purpose account management), and `distribution/privacy-policy.md`/`.html` + `docs/privacy/index.html` now disclose it. See resubmission steps in `PUBLISHING.md` § "Resubmitting after a Data Safety rejection". Also still declare "App interactions" + "Device or other IDs" as collected, optional, shared with PostHog/Sentry; "User-submitted diagnostic reports" as collected, optional, shared with our self-hosted Chatwoot inbox. See `docs/analytics.md` | | 8 | Content rating questionnaire (IARC, drafted) | User (in Console after app created) | ✅ verified — no violence/sexual/gambling/UGC; "interact with other users" = No (user talks to own AI agent) | | 9 | App access — reviewer instructions for self-hosted opencode (drafted) | User | ✅ verified — instructions accurate; `npm install -g opencode-ai && opencode serve` flow confirmed in `play-listing.md` | | 10 | Sentry opt-in consent gate (for F-Droid parity + GDPR friendly) | Agent | ✅ done — `src/lib/telemetry.ts` (consent store), `src/components/TelemetryConsentModal.tsx` (first-launch modal), `app/_layout.tsx` (gated init), `app/(tabs)/settings.tsx` (Privacy section toggle) | diff --git a/docs/privacy/index.html b/docs/privacy/index.html index 99805ef..bea4cdb 100644 --- a/docs/privacy/index.html +++ b/docs/privacy/index.html @@ -95,7 +95,7 @@

    OpenCode Mobile — Privacy Policy

    - Effective date: 2026-07-18  |  + Effective date: 2026-07-23  |  Operator: VIBE TECHNOLOGIES, LLC  |  App: OpenCode Mobile (cc.agentlabs.opencode)

    @@ -106,7 +106,9 @@ server URLs, or any chat content. All AI traffic goes directly from the app to your own opencode server. With your consent, we use Sentry for anonymous crash diagnostics, PostHog for anonymous usage analytics, and — only when you tap "Share Report" — deliver a - scrubbed copy of that diagnostic report to our support inbox. + scrubbed copy of that diagnostic report to our support inbox. If you choose to join the + optional "OpenCode Connect" waitlist, we collect the email address you submit and + share it with Brevo to notify you at launch.

    1. Who We Are

    @@ -131,12 +133,16 @@
  • Your prompts, chat messages, or AI responses
  • Your opencode server URL, IP address, or hostname
  • Authentication tokens, API keys, or credentials you enter
  • -
  • Account information, email addresses, or names
  • +
  • Account information or names
  • Location data
  • Photos, microphone recordings, or camera data (unless you attach them to a message, in which case they go only to your own server)
  • Contacts, calendar, or any other personal data
  • +

    + The one exception is your email address, and only if you choose to type it + in and join the optional "OpenCode Connect" waitlist — see section 3c below. +

    All communication between the app and your AI coding agent travels directly between your device and your self-hosted opencode server. VIBE TECHNOLOGIES, LLC never sees this traffic. @@ -336,6 +342,45 @@ normal share sheet, but nothing reaches our support inbox.

    +

    3c. Data We Do Collect (Optional Waitlist Signup)

    +

    + The Connect screen offers an optional waitlist for OpenCode + Connect, our not-yet-launched hosted opencode service. If you choose to type in your + email address and tap Join waitlist, we collect that email address and send + it to Brevo, a third-party email marketing/CRM platform, so we can add you to + the waitlist and notify you when the hosted service becomes available. +

    +

    + This is entirely separate from — and independent of — the crash-reporting/analytics consent + toggle described in section 4. It only happens if you open the waitlist card and submit an + email; if you never do, no email address is ever collected. +

    + + + + + + + + + + + + + + + + + + +
    Data typeWhat is collectedShared withPurpose
    Email addressThe email address you type into the waitlist fieldBrevo (email marketing/CRM platform)Notify you when OpenCode Connect launches; waitlist/account management
    + +

    + We do not use this email address for any other purpose (no other marketing, no ads, no sale + or rental to any other party). To unsubscribe or request deletion, use the unsubscribe link + in any waitlist email, or email support@agentlabs.cc. +

    +

    4. Consent and Control

    Crash reporting, usage analytics, and support-inbox delivery of shared reports are all @@ -354,21 +399,29 @@

    5. Third-Party Services

    - We use two third-party services, both consent-gated: + We use three third-party services:

    We use no advertising networks, social SDKs, or any other @@ -389,7 +442,8 @@ PostHog are retained per PostHog's standard retention policy. Shared support reports delivered to our Chatwoot inbox are retained until the associated support conversation is resolved and periodically purged thereafter; email support@agentlabs.cc to request earlier - deletion of a specific report. + deletion of a specific report. Waitlist email addresses submitted via the optional OpenCode + Connect waitlist are retained in Brevo until you unsubscribe or request deletion.

    Beyond that support inbox, we do not operate our own servers that store your data; there is @@ -402,12 +456,13 @@

    @@ -477,7 +532,8 @@ - Contact InfoNoN/ANo + Contact Info — Name/Phone/AddressNoN/ANo + Contact Info — Email AddressYes — only if you join the optional OpenCode Connect waitlistYes — stored in Brevo to contact you about the waitlistNo LocationNoN/ANo Identifiers (Device ID)Yes (Sentry / PostHog anonymous IDs, with consent)NoNo Usage Data — Product InteractionYes (PostHog activation events, with consent)NoNo @@ -487,11 +543,11 @@ All other categoriesNoN/ANo -

    App Store Connect summary: Data Linked to You: None. Data Not Linked to You: Crash Data, Performance Data, Product Interaction, Other Diagnostic Data (when user consents). Tracking: No.

    +

    App Store Connect summary: Data Linked to You: Email Address (only if you join the optional OpenCode Connect waitlist). Data Not Linked to You: Crash Data, Performance Data, Product Interaction, Other Diagnostic Data (when user consents). Tracking: No.