fix(compliance): disclose email collection in Play Data Safety + align privacy docs (#146)
* fix(compliance): disclose email collection in Play Data Safety + align privacy docs (closes #143) Google Play rejected cc.agentlabs.opencode (2026-07-22) because the Data Safety declaration did not disclose collection of Email Address. Root cause: the optional "OpenCode Connect" waitlist card on the Connect screen (app/connection/add.tsx -> src/lib/waitlist.ts) collects an email and forwards it to Brevo (email marketing/CRM) via the beta-signup backend. Audited all other PII surfaces and confirmed no other undisclosed collection: Chatwoot support reports stay anonymous (no email/name), Sentry strips URLs/tokens and sends no default PII, and PostHog analytics uses only a random anonymous ID with coarse event properties. Updates: - distribution/play-listing.md: Data Safety table now declares Personal info / Email address (collected, shared with Brevo, optional, purpose account management); embedded privacy-policy draft and app description updated to match. - distribution/privacy-policy.md/.html + docs/privacy/index.html: new section 3c discloses the waitlist email collection, third-party services list adds Brevo, retention/rights sections and the Apple Privacy Nutrition Label table updated accordingly. - docs/playstore.md: checklist entry documents the rejection and points to the fix. - PUBLISHING.md: adds exact Play Console resubmission steps (Data types -> Personal info -> Email address -> collected/shared/purpose) plus a note on the earlier unrelated "Missing sign-in details" App access blocker in case it resurfaces. No app code changed; npm test (209 pass) and tsc --noEmit are clean. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(ci): run required checks on docs-only PRs (unblock branch protection) ios-ci.yml (which emits the required 'Typecheck and unit tests' check) had paths-ignore for docs/**, docs-site/**, distribution/**, **/*.md. A required status check that is path-filtered never runs on docs-only PRs, so those PRs sit permanently in mergeStateStatus=BLOCKED (missing required check). Remove the paths-ignore so required checks always run. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: test <test@test.local> Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
@@ -65,7 +65,7 @@ For full company facts (D-U-N-S, address, governor, etc.) see `~/.agents/skills/
|
||||
| 4 | Feature graphic — 1024×500 PNG | Agent | ✅ done — `distribution/play-graphics/feature-graphic.png` |
|
||||
| 5 | At least 2 phone screenshots (1080×1920 or similar) | Agent | ✅ done — `distribution/play-graphics/phone-{01,02,03}.png` (1080×2400 each; 3 screens: connection, chat, diff viewer) |
|
||||
| 6 | Privacy policy — live at https://dzianisv.github.io/opencode-mobile/privacy/ | Agent | ✅ done — live & verified (HTTP 200) on gh-pages; `distribution/privacy-policy.html` (source), `distribution/privacy-policy.md` (markdown mirror) |
|
||||
| 7 | Data safety form answers (drafted in `distribution/play-listing.md`) | User (in Console after app created) | ⚠️ re-verify — app now ships PostHog usage analytics (posthog-react-native) alongside Sentry, plus Chatwoot delivery of user-shared diagnostic reports (#88), all behind the same opt-in consent gate. Data safety draft updated: declare "App interactions" + "Device or other IDs" as collected, optional, shared with PostHog/Sentry; declare "User-submitted diagnostic reports" as collected, optional, shared with our self-hosted Chatwoot inbox. See `docs/analytics.md` |
|
||||
| 7 | Data safety form answers (drafted in `distribution/play-listing.md`) | User (in Console after app created) | ⚠️ **re-submit required (#143)** — Google rejected `cc.agentlabs.opencode` on 2026-07-22 because the Data Safety declaration did not disclose collection of Email Address (the "OpenCode Connect" waitlist on the Connect screen collects an email and forwards it to Brevo). Fixed in repo: `distribution/play-listing.md` Data Safety table now declares "Personal info — Email address" (collected, shared with Brevo, optional, purpose account management), and `distribution/privacy-policy.md`/`.html` + `docs/privacy/index.html` now disclose it. See resubmission steps in `PUBLISHING.md` § "Resubmitting after a Data Safety rejection". Also still declare "App interactions" + "Device or other IDs" as collected, optional, shared with PostHog/Sentry; "User-submitted diagnostic reports" as collected, optional, shared with our self-hosted Chatwoot inbox. See `docs/analytics.md` |
|
||||
| 8 | Content rating questionnaire (IARC, drafted) | User (in Console after app created) | ✅ verified — no violence/sexual/gambling/UGC; "interact with other users" = No (user talks to own AI agent) |
|
||||
| 9 | App access — reviewer instructions for self-hosted opencode (drafted) | User | ✅ verified — instructions accurate; `npm install -g opencode-ai && opencode serve` flow confirmed in `play-listing.md` |
|
||||
| 10 | Sentry opt-in consent gate (for F-Droid parity + GDPR friendly) | Agent | ✅ done — `src/lib/telemetry.ts` (consent store), `src/components/TelemetryConsentModal.tsx` (first-launch modal), `app/_layout.tsx` (gated init), `app/(tabs)/settings.tsx` (Privacy section toggle) |
|
||||
|
||||
@@ -95,7 +95,7 @@
|
||||
<header>
|
||||
<h1>OpenCode Mobile — Privacy Policy</h1>
|
||||
<p class="meta">
|
||||
Effective date: 2026-07-18 |
|
||||
Effective date: 2026-07-23 |
|
||||
Operator: VIBE TECHNOLOGIES, LLC |
|
||||
App: OpenCode Mobile (<code>cc.agentlabs.opencode</code>)
|
||||
</p>
|
||||
@@ -106,7 +106,9 @@
|
||||
server URLs, or any chat content. All AI traffic goes directly from the app to your own
|
||||
opencode server. With your consent, we use Sentry for anonymous crash diagnostics, PostHog
|
||||
for anonymous usage analytics, and — only when you tap "Share Report" — deliver a
|
||||
scrubbed copy of that diagnostic report to our support inbox.
|
||||
scrubbed copy of that diagnostic report to our support inbox. If you choose to join the
|
||||
optional "OpenCode Connect" waitlist, we collect the email address you submit and
|
||||
share it with Brevo to notify you at launch.
|
||||
</div>
|
||||
|
||||
<h2>1. Who We Are</h2>
|
||||
@@ -131,12 +133,16 @@
|
||||
<li>Your prompts, chat messages, or AI responses</li>
|
||||
<li>Your opencode server URL, IP address, or hostname</li>
|
||||
<li>Authentication tokens, API keys, or credentials you enter</li>
|
||||
<li>Account information, email addresses, or names</li>
|
||||
<li>Account information or names</li>
|
||||
<li>Location data</li>
|
||||
<li>Photos, microphone recordings, or camera data (unless you attach them to a message,
|
||||
in which case they go only to your own server)</li>
|
||||
<li>Contacts, calendar, or any other personal data</li>
|
||||
</ul>
|
||||
<p>
|
||||
The one exception is your <strong>email address</strong>, and only if you choose to type it
|
||||
in and join the optional "OpenCode Connect" waitlist — see section 3c below.
|
||||
</p>
|
||||
<p>
|
||||
All communication between the app and your AI coding agent travels directly between your
|
||||
device and your self-hosted opencode server. VIBE TECHNOLOGIES, LLC never sees this traffic.
|
||||
@@ -336,6 +342,45 @@
|
||||
normal share sheet, but nothing reaches our support inbox.
|
||||
</p>
|
||||
|
||||
<h2>3c. Data We Do Collect (Optional Waitlist Signup)</h2>
|
||||
<p>
|
||||
The <strong>Connect</strong> screen offers an optional waitlist for <strong>OpenCode
|
||||
Connect</strong>, our not-yet-launched hosted opencode service. If you choose to type in your
|
||||
email address and tap <strong>Join waitlist</strong>, we collect that email address and send
|
||||
it to <strong>Brevo</strong>, a third-party email marketing/CRM platform, so we can add you to
|
||||
the waitlist and notify you when the hosted service becomes available.
|
||||
</p>
|
||||
<p>
|
||||
This is entirely separate from — and independent of — the crash-reporting/analytics consent
|
||||
toggle described in section 4. It only happens if you open the waitlist card and submit an
|
||||
email; if you never do, no email address is ever collected.
|
||||
</p>
|
||||
|
||||
<table>
|
||||
<thead>
|
||||
<tr>
|
||||
<th>Data type</th>
|
||||
<th>What is collected</th>
|
||||
<th>Shared with</th>
|
||||
<th>Purpose</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
<tr>
|
||||
<td>Email address</td>
|
||||
<td>The email address you type into the waitlist field</td>
|
||||
<td>Brevo (email marketing/CRM platform)</td>
|
||||
<td>Notify you when OpenCode Connect launches; waitlist/account management</td>
|
||||
</tr>
|
||||
</tbody>
|
||||
</table>
|
||||
|
||||
<p>
|
||||
We do not use this email address for any other purpose (no other marketing, no ads, no sale
|
||||
or rental to any other party). To unsubscribe or request deletion, use the unsubscribe link
|
||||
in any waitlist email, or email <a href="mailto:support@agentlabs.cc">support@agentlabs.cc</a>.
|
||||
</p>
|
||||
|
||||
<h2>4. Consent and Control</h2>
|
||||
<p>
|
||||
Crash reporting, usage analytics, and support-inbox delivery of shared reports are all
|
||||
@@ -354,21 +399,29 @@
|
||||
|
||||
<h2>5. Third-Party Services</h2>
|
||||
<p>
|
||||
We use two third-party services, both consent-gated:
|
||||
We use three third-party services:
|
||||
</p>
|
||||
<ul>
|
||||
<li>
|
||||
<strong>Sentry</strong> — crash and error monitoring.<br>
|
||||
<strong>Sentry</strong> — crash and error monitoring (consent-gated).<br>
|
||||
Privacy policy: <a href="https://sentry.io/privacy/" target="_blank" rel="noopener">sentry.io/privacy</a><br>
|
||||
Data is sent to Sentry's US-based servers and retained for approximately 90 days
|
||||
per Sentry's default data-retention policy.
|
||||
</li>
|
||||
<li>
|
||||
<strong>PostHog</strong> — anonymous usage analytics (the activation-funnel events listed
|
||||
in section 3a).<br>
|
||||
in section 3a; consent-gated).<br>
|
||||
Privacy policy: <a href="https://posthog.com/privacy" target="_blank" rel="noopener">posthog.com/privacy</a><br>
|
||||
Data is sent to PostHog's EU-region servers (<code>eu.i.posthog.com</code>).
|
||||
</li>
|
||||
<li>
|
||||
<strong>Brevo</strong> — email marketing/CRM platform used only if you join the optional
|
||||
OpenCode Connect waitlist described in section 3c. This is a separate, independent action
|
||||
from the consent toggle above — nothing is sent to Brevo unless you submit an email to the
|
||||
waitlist form.<br>
|
||||
Privacy policy: <a href="https://www.brevo.com/legal/privacypolicy/" target="_blank" rel="noopener">brevo.com/legal/privacypolicy</a><br>
|
||||
Data sent: only the email address you submit to the waitlist form.
|
||||
</li>
|
||||
</ul>
|
||||
<p>
|
||||
We use no advertising networks, social SDKs, or any other
|
||||
@@ -389,7 +442,8 @@
|
||||
PostHog are retained per PostHog's standard retention policy. Shared support reports
|
||||
delivered to our Chatwoot inbox are retained until the associated support conversation is
|
||||
resolved and periodically purged thereafter; email support@agentlabs.cc to request earlier
|
||||
deletion of a specific report.
|
||||
deletion of a specific report. Waitlist email addresses submitted via the optional OpenCode
|
||||
Connect waitlist are retained in Brevo until you unsubscribe or request deletion.
|
||||
</p>
|
||||
<p>
|
||||
Beyond that support inbox, we do not operate our own servers that store your data; there is
|
||||
@@ -402,12 +456,13 @@
|
||||
</p>
|
||||
<ul>
|
||||
<li><strong>Opt out</strong> — disable crash reporting, usage analytics, and support-inbox
|
||||
delivery of shared reports at any time in Settings → Privacy.</li>
|
||||
delivery of shared reports at any time in Settings → Privacy. Unsubscribe from the
|
||||
waitlist at any time using the link in any waitlist email.</li>
|
||||
<li><strong>Request deletion</strong> — email <a href="mailto:support@agentlabs.cc">support@agentlabs.cc</a>
|
||||
with subject "Data deletion request" and we will request deletion of any crash events
|
||||
(Sentry), analytics events (PostHog), and shared support-report conversations (Chatwoot)
|
||||
associated with your device. Include your device model and approximate date range to
|
||||
help us identify your records.</li>
|
||||
(Sentry), analytics events (PostHog), shared support-report conversations (Chatwoot), and
|
||||
waitlist email records (Brevo) associated with your device or email address. Include your
|
||||
device model and approximate date range to help us identify your records.</li>
|
||||
<li><strong>Access</strong> — request a summary of what diagnostic data (if any) we hold
|
||||
about your device by emailing the same address.</li>
|
||||
</ul>
|
||||
@@ -477,7 +532,8 @@
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
<tr><td style="border:1px solid #e2e8f0;padding:8px;">Contact Info</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td><td style="border:1px solid #e2e8f0;padding:8px;">N/A</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td></tr>
|
||||
<tr><td style="border:1px solid #e2e8f0;padding:8px;">Contact Info — Name/Phone/Address</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td><td style="border:1px solid #e2e8f0;padding:8px;">N/A</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td></tr>
|
||||
<tr><td style="border:1px solid #e2e8f0;padding:8px;">Contact Info — Email Address</td><td style="border:1px solid #e2e8f0;padding:8px;">Yes — only if you join the optional OpenCode Connect waitlist</td><td style="border:1px solid #e2e8f0;padding:8px;">Yes — stored in Brevo to contact you about the waitlist</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td></tr>
|
||||
<tr><td style="border:1px solid #e2e8f0;padding:8px;">Location</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td><td style="border:1px solid #e2e8f0;padding:8px;">N/A</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td></tr>
|
||||
<tr><td style="border:1px solid #e2e8f0;padding:8px;">Identifiers (Device ID)</td><td style="border:1px solid #e2e8f0;padding:8px;">Yes (Sentry / PostHog anonymous IDs, with consent)</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td></tr>
|
||||
<tr><td style="border:1px solid #e2e8f0;padding:8px;">Usage Data — Product Interaction</td><td style="border:1px solid #e2e8f0;padding:8px;">Yes (PostHog activation events, with consent)</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td></tr>
|
||||
@@ -487,11 +543,11 @@
|
||||
<tr><td style="border:1px solid #e2e8f0;padding:8px;">All other categories</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td><td style="border:1px solid #e2e8f0;padding:8px;">N/A</td><td style="border:1px solid #e2e8f0;padding:8px;">No</td></tr>
|
||||
</tbody>
|
||||
</table>
|
||||
<p><strong>App Store Connect summary:</strong> Data Linked to You: <em>None</em>. Data Not Linked to You: <em>Crash Data, Performance Data, Product Interaction, Other Diagnostic Data</em> (when user consents). Tracking: <em>No</em>.</p>
|
||||
<p><strong>App Store Connect summary:</strong> Data Linked to You: <em>Email Address</em> (only if you join the optional OpenCode Connect waitlist). Data Not Linked to You: <em>Crash Data, Performance Data, Product Interaction, Other Diagnostic Data</em> (when user consents). Tracking: <em>No</em>.</p>
|
||||
|
||||
<footer>
|
||||
© 2026 VIBE TECHNOLOGIES, LLC. OpenCode Mobile is MIT-licensed open-source software.
|
||||
Privacy policy effective 2026-07-18.<br>
|
||||
Privacy policy effective 2026-07-23.<br>
|
||||
<a href="https://dzianisv.github.io/opencode-mobile/">Home</a> ·
|
||||
<a href="https://dzianisv.github.io/opencode-mobile/guide/">Setup guide</a> ·
|
||||
<a href="https://github.com/dzianisv/opencode-mobile">GitHub</a>
|
||||
|
||||
Reference in New Issue
Block a user