From dc7cc749c241fc23bb57b1258d5e08f9c31ca6bf Mon Sep 17 00:00:00 2001
From: engineer
Date: Tue, 2 Jun 2026 17:11:39 -0700
Subject: [PATCH] docs(distribution): cite live GitHub Pages privacy URL for
store submissions (unblocks Play/IzzyOnDroid)
Co-Authored-By: Claude Opus 4.8
---
HANDOFF.md | 16 +++++++---------
README.md | 2 +-
distribution/PLAY-APP-CONTENT-ANSWERS.md | 2 +-
distribution/app-store-listing.md | 4 ++--
distribution/ios-enrollment-runbook.md | 2 +-
.../izzyondroid-submission/INCLUSION-REQUEST.md | 2 +-
.../SUBMISSION-CHECKLIST.md | 2 +-
distribution/play-listing.md | 4 ++--
distribution/privacy-policy.html | 4 ++--
distribution/privacy-policy.md | 2 +-
distribution/strategy.md | 2 +-
docs/applestore.md | 2 +-
docs/opencode-site-deploy.md | 2 +-
docs/playstore.md | 2 +-
docs/privacy/index.html | 4 ++--
15 files changed, 25 insertions(+), 27 deletions(-)
diff --git a/HANDOFF.md b/HANDOFF.md
index 301e382..83e0702 100644
--- a/HANDOFF.md
+++ b/HANDOFF.md
@@ -69,15 +69,13 @@ Goal: bug-free E2E + published on F-Droid & Play + 1k downloads.
commit, then `git tag v0.4.4 && git push origin main --tags`. The `v*` tag fires
`publish-fdroid.yml` and `publish-play-store.yml` automatically.
-1. **Publish privacy policy live (blocks Play production).** `https://opencode.vibebrowser.app/privacy`
- currently fails to resolve (curl exit 6 / host not found — not deployed). The Play
- "App content" answers and the IzzyOnDroid request both cite this exact URL, so it
- must serve `distribution/privacy-policy.html` at the path `/privacy`. Steps:
- (a) confirm/create DNS for `opencode.vibebrowser.app`; (b) host the file — easiest is
- any static host (e.g. add a `privacy.html`/`/privacy` route on the existing
- vibebrowser.app deployment, or a Vercel/Netlify/GitHub Pages site for this subdomain);
- (c) verify: `curl -sI https://opencode.vibebrowser.app/privacy` returns `200`.
- Source file: `distribution/privacy-policy.html` (markdown source mirror:
+1. **Privacy policy is live (Play-production blocker cleared).** Canonical privacy URL is
+ now `https://dzianisv.github.io/opencode-mobile/privacy/` — live & verified (HTTP 200) on
+ the gh-pages branch, serving `distribution/privacy-policy.html`. This GitHub Pages URL is
+ the canonical privacy URL cited across all store-submission docs (Play "App content"
+ answers, IzzyOnDroid request). If the owner later deploys the branded
+ `opencode.vibebrowser.app/privacy`, it can replace the GitHub Pages URL — this change is
+ reversible. Source file: `distribution/privacy-policy.html` (markdown mirror:
`distribution/privacy-policy.md`).
2. **Google Play → production (biggest unlock, ~15 min).**
diff --git a/README.md b/README.md
index 4af50ea..52614ec 100644
--- a/README.md
+++ b/README.md
@@ -163,7 +163,7 @@ We welcome bug reports, feature requests, and pull requests. See [CONTRIBUTING.m
OpenCode Mobile does not collect personal data. Optional Sentry crash reporting (opt-in, off by default) sends anonymised crash traces to Sentry. No analytics SDKs are bundled. Credentials are stored exclusively on-device in the OS keystore.
-Full privacy policy: [opencode.vibebrowser.app/privacy](https://opencode.vibebrowser.app/privacy)
+Full privacy policy: [dzianisv.github.io/opencode-mobile/privacy](https://dzianisv.github.io/opencode-mobile/privacy/)
---
diff --git a/distribution/PLAY-APP-CONTENT-ANSWERS.md b/distribution/PLAY-APP-CONTENT-ANSWERS.md
index 662ff43..3ede983 100644
--- a/distribution/PLAY-APP-CONTENT-ANSWERS.md
+++ b/distribution/PLAY-APP-CONTENT-ANSWERS.md
@@ -16,7 +16,7 @@ App facts these answers derive from:
---
## 1. Privacy policy
-- URL: `https://opencode.vibebrowser.app/privacy`
+- URL: `https://dzianisv.github.io/opencode-mobile/privacy/`
## 2. Data safety
**Does your app collect or share any required user data types?**
diff --git a/distribution/app-store-listing.md b/distribution/app-store-listing.md
index 456652f..13811c8 100644
--- a/distribution/app-store-listing.md
+++ b/distribution/app-store-listing.md
@@ -103,7 +103,7 @@ Alternative / supplemental terms to rotate in A/B: `code review`, `AI assistant`
|---|---|
| Support URL | https://agentlabs.cc/opencode |
| Marketing URL | https://github.com/dzianisv/opencode-mobile |
-| Privacy Policy URL | https://opencode.vibebrowser.app/privacy |
+| Privacy Policy URL | https://dzianisv.github.io/opencode-mobile/privacy/ |
---
@@ -339,7 +339,7 @@ To use: you need opencode running somewhere accessible (local Wi-Fi, Tailscale,
- [ ] App icon 1024×1024 PNG (no alpha, no rounded corners)
- [ ] iPhone screenshots (6.7" minimum; 6.5" strongly recommended)
- [ ] iPad screenshots (12.9" minimum)
-- [ ] Privacy policy live at https://opencode.vibebrowser.app/privacy
+- [ ] Privacy policy live at https://dzianisv.github.io/opencode-mobile/privacy/
- [ ] App Store Connect API key created (for CI — Key ID, Issuer ID, .p8 file)
- [ ] Apple Distribution certificate + provisioning profile (or use EAS managed signing)
- [ ] Export compliance answered (No to custom encryption)
diff --git a/distribution/ios-enrollment-runbook.md b/distribution/ios-enrollment-runbook.md
index c524f08..01b7f26 100644
--- a/distribution/ios-enrollment-runbook.md
+++ b/distribution/ios-enrollment-runbook.md
@@ -113,7 +113,7 @@ While waiting for Apple's verification call and approval:
- [ ] Create app icon 1024×1024 PNG
- [ ] Capture iPhone screenshots (use iOS Simulator in Xcode on any Mac)
- [ ] Capture iPad screenshots
-- [ ] Write/publish privacy policy at https://opencode.vibebrowser.app/privacy
+- [ ] Write/publish privacy policy at https://dzianisv.github.io/opencode-mobile/privacy/
- [ ] Set up EAS account at https://expo.dev/ (free tier, log in with Expo account)
- [ ] Add iOS config patches to `app.json` (done in this PR)
- [ ] Run `npx expo prebuild --platform ios` on a Mac to validate the Xcode project
diff --git a/distribution/izzyondroid-submission/INCLUSION-REQUEST.md b/distribution/izzyondroid-submission/INCLUSION-REQUEST.md
index 6200c78..0091930 100644
--- a/distribution/izzyondroid-submission/INCLUSION-REQUEST.md
+++ b/distribution/izzyondroid-submission/INCLUSION-REQUEST.md
@@ -107,4 +107,4 @@ We will notify the IzzyOnDroid team via this issue when that happens.
Developer: VIBE TECHNOLOGIES, LLC
Email: support@vibebrowser.app
Website: https://agentlabs.cc/opencode
-Privacy policy: https://opencode.vibebrowser.app/privacy
+Privacy policy: https://dzianisv.github.io/opencode-mobile/privacy/
diff --git a/distribution/izzyondroid-submission/SUBMISSION-CHECKLIST.md b/distribution/izzyondroid-submission/SUBMISSION-CHECKLIST.md
index fbd3187..95da24e 100644
--- a/distribution/izzyondroid-submission/SUBMISSION-CHECKLIST.md
+++ b/distribution/izzyondroid-submission/SUBMISSION-CHECKLIST.md
@@ -17,7 +17,7 @@ IzzyOnDroid is the fastest OSS distribution channel — typical inclusion is
- [ ] APK is signed with `keystores/production-release.jks`
- [ ] SHA-256 fingerprint confirmed: see `distribution/SIGNING-KEY-FINGERPRINTS.md`
- [ ] Sentry opt-in gate is in production (avoids `Tracking` anti-feature escalation)
-- [ ] Privacy policy is live at `https://opencode.vibebrowser.app/privacy`
+- [ ] Privacy policy is live at `https://dzianisv.github.io/opencode-mobile/privacy/`
- [ ] `app.json` `version` and `android.versionCode` are set correctly in the tagged commit
---
diff --git a/distribution/play-listing.md b/distribution/play-listing.md
index 60211c5..969b81d 100644
--- a/distribution/play-listing.md
+++ b/distribution/play-listing.md
@@ -144,7 +144,7 @@ Issues: github.com/dzianisv/opencode-mobile/issues
**Required.** Must be a public URL.
-Suggested path: `https://opencode.vibebrowser.app/privacy`
+Suggested path: `https://dzianisv.github.io/opencode-mobile/privacy/`
Privacy policy must cover:
- What data is collected (Sentry crash diagnostics: device model, OS version, stack trace; no user content)
@@ -297,7 +297,7 @@ CI currently publishes to `internal` track. ✅
- [ ] Adaptive icon (real PNG)
- [ ] Feature graphic 1024×500
- [ ] At least 2 phone screenshots
-- [ ] Privacy policy live at https://opencode.vibebrowser.app/privacy
+- [ ] Privacy policy live at https://dzianisv.github.io/opencode-mobile/privacy/
- [ ] Decide pricing model
- [ ] Run IARC content rating questionnaire (after app created in Play Console)
- [ ] Complete Data safety form (after app created in Play Console)
diff --git a/distribution/privacy-policy.html b/distribution/privacy-policy.html
index ddfe70c..f9d6a67 100644
--- a/distribution/privacy-policy.html
+++ b/distribution/privacy-policy.html
@@ -253,8 +253,8 @@
If we make material changes to this policy, we will update the effective date at the top
of this page and, where feasible, notify users via an in-app notice. The latest version
is always available at:
-
- vibebrowser.app/opencode-mobile/privacy
+
+ dzianisv.github.io/opencode-mobile/privacy
diff --git a/distribution/privacy-policy.md b/distribution/privacy-policy.md
index d61e61c..c3c2383 100644
--- a/distribution/privacy-policy.md
+++ b/distribution/privacy-policy.md
@@ -106,7 +106,7 @@ All diagnostic data is transmitted over HTTPS (TLS 1.2+) to Sentry. We do not tr
## 10. Changes to This Policy
If we make material changes to this policy, we will update the effective date and, where feasible, notify users via an in-app notice. The latest version is always available at:
-https://opencode.vibebrowser.app/privacy
+https://dzianisv.github.io/opencode-mobile/privacy/
---
diff --git a/distribution/strategy.md b/distribution/strategy.md
index 5e3dc51..717cfeb 100644
--- a/distribution/strategy.md
+++ b/distribution/strategy.md
@@ -42,7 +42,7 @@ Rejected alternatives:
1. **Google Play identity verification** — upload governor ID (Dzianis Vashchuk). Unlocks: API access, Create app, AAB upload, CI publish.
2. **Apple Developer Program enrollment** — $99/year, D-U-N-S 142059652 ready. iOS agent will produce runbook.
3. **App icon + adaptive icon + feature graphic** — current `assets/*.json` are placeholders. Need real PNGs before either Play or App Store publish.
-4. **Privacy policy URL** — must be live at https://opencode.vibebrowser.app/privacy before Play publish. Template in `play-listing.md`.
+4. **Privacy policy URL** — live & verified at https://dzianisv.github.io/opencode-mobile/privacy/ (this GitHub Pages URL is the canonical privacy URL used for store submissions; if the owner later deploys the branded `opencode.vibebrowser.app/privacy`, it can replace it — reversible). Template in `play-listing.md`.
### Soft blockers (we can fix without user)
diff --git a/docs/applestore.md b/docs/applestore.md
index a2ccd2a..bdc378f 100644
--- a/docs/applestore.md
+++ b/docs/applestore.md
@@ -81,7 +81,7 @@ Because the answer is "No", no ERN (Encryption Registration Number) is required
| 4 | App icon — 1024×1024 PNG, opaque (no alpha) | ✅ Done | `assets/icon-appstore.png` (flattened from Android-produced `assets/icon.png`) |
| 5 | iPhone screenshots 6.7" (1290×2796) + 6.5" (1242×2688) | ✅ Done | `distribution/app-store-graphics/iphone-67/{01,02,03}.png` + `iphone-65/` — 3 mockup screens: connection, chat, diff |
| 6 | iPad screenshots 12.9" (2048×2732) | ✅ Done | `distribution/app-store-graphics/ipad-129/{01,02}.png` — 2 mockup screens |
-| 7 | Privacy policy — live at https://opencode.vibebrowser.app/privacy | 🟡 partial | Content handled by Android agent (`distribution/privacy-policy.{md,html}`). iOS-specific ATT / nutrition label addendum written in `distribution/app-store-listing.md`. User must deploy to vibebrowser.app. |
+| 7 | Privacy policy — live at https://dzianisv.github.io/opencode-mobile/privacy/ | ✅ done | Live & verified (HTTP 200) on gh-pages. Content handled by Android agent (`distribution/privacy-policy.{md,html}`). iOS-specific ATT / nutrition label addendum written in `distribution/app-store-listing.md`. |
| 8 | Privacy nutrition label (App Tracking + Data Collection) | ✅ Done | Updated in `distribution/app-store-listing.md` — ATT explicitly noted (not used), Sentry opt-in status documented |
| 9 | Export compliance | ✅ Done | `ITSAppUsesNonExemptEncryption: false` added to `app.json`. Answers + rationale in this doc (see Export Compliance section above) and `distribution/app-store-listing.md`. |
| 10 | ATS justification in App Review notes | ✅ Done | Full justification text in `distribution/app-store-listing.md` under "App Review Notes — ATS Justification" |
diff --git a/docs/opencode-site-deploy.md b/docs/opencode-site-deploy.md
index 05ba252..833c31a 100644
--- a/docs/opencode-site-deploy.md
+++ b/docs/opencode-site-deploy.md
@@ -56,5 +56,5 @@ When the privacy policy changes, re-deploy the site to pick up the new version.
## Verification command
```bash
-curl -sI https://opencode.vibebrowser.app/privacy | head -3
+curl -sI https://dzianisv.github.io/opencode-mobile/privacy/ | head -3
```
diff --git a/docs/playstore.md b/docs/playstore.md
index 9c66203..403b59d 100644
--- a/docs/playstore.md
+++ b/docs/playstore.md
@@ -64,7 +64,7 @@ For full company facts (D-U-N-S, address, governor, etc.) see `~/.agents/skills/
| 3 | Adaptive icon — 432×432 foreground PNG | Agent | ✅ done — `assets/adaptive-icon.png` (432×432, transparent bg) |
| 4 | Feature graphic — 1024×500 PNG | Agent | ✅ done — `distribution/play-graphics/feature-graphic.png` |
| 5 | At least 2 phone screenshots (1080×1920 or similar) | Agent | ✅ done — `distribution/play-graphics/phone-{01,02,03}.png` (1080×2400 each; 3 screens: connection, chat, diff viewer) |
-| 6 | Privacy policy — live at https://opencode.vibebrowser.app/privacy | Agent | ✅ done — `distribution/privacy-policy.html` (deployed to opencode.vibebrowser.app/privacy), `distribution/privacy-policy.md` (source) |
+| 6 | Privacy policy — live at https://dzianisv.github.io/opencode-mobile/privacy/ | Agent | ✅ done — live & verified (HTTP 200) on gh-pages; `distribution/privacy-policy.html` (source), `distribution/privacy-policy.md` (markdown mirror) |
| 7 | Data safety form answers (drafted in `distribution/play-listing.md`) | User (in Console after app created) | ✅ verified — no analytics/ad SDKs found; crash logs updated to "Optional (opt-in, default OFF)" per new consent gate |
| 8 | Content rating questionnaire (IARC, drafted) | User (in Console after app created) | ✅ verified — no violence/sexual/gambling/UGC; "interact with other users" = No (user talks to own AI agent) |
| 9 | App access — reviewer instructions for self-hosted opencode (drafted) | User | ✅ verified — instructions accurate; `npm install -g opencode-ai && opencode serve` flow confirmed in `play-listing.md` |
diff --git a/docs/privacy/index.html b/docs/privacy/index.html
index 76cf148..3be371a 100644
--- a/docs/privacy/index.html
+++ b/docs/privacy/index.html
@@ -253,8 +253,8 @@
If we make material changes to this policy, we will update the effective date at the top
of this page and, where feasible, notify users via an in-app notice. The latest version
is always available at:
-
- vibebrowser.app/opencode-mobile/privacy
+
+ dzianisv.github.io/opencode-mobile/privacy