docs(distribution): cite live GitHub Pages privacy URL for store submissions (unblocks Play/IzzyOnDroid)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
engineer
2026-06-02 17:11:39 -07:00
parent fb5c97a8a5
commit dc7cc749c2
15 changed files with 25 additions and 27 deletions

View File

@@ -69,15 +69,13 @@ Goal: bug-free E2E + published on F-Droid & Play + 1k downloads.
commit, then `git tag v0.4.4 && git push origin main --tags`. The `v*` tag fires
`publish-fdroid.yml` and `publish-play-store.yml` automatically.
1. **Publish privacy policy live (blocks Play production).** `https://opencode.vibebrowser.app/privacy`
currently fails to resolve (curl exit 6 / host not found — not deployed). The Play
"App content" answers and the IzzyOnDroid request both cite this exact URL, so it
must serve `distribution/privacy-policy.html` at the path `/privacy`. Steps:
(a) confirm/create DNS for `opencode.vibebrowser.app`; (b) host the file — easiest is
any static host (e.g. add a `privacy.html`/`/privacy` route on the existing
vibebrowser.app deployment, or a Vercel/Netlify/GitHub Pages site for this subdomain);
(c) verify: `curl -sI https://opencode.vibebrowser.app/privacy` returns `200`.
Source file: `distribution/privacy-policy.html` (markdown source mirror:
1. **Privacy policy is live (Play-production blocker cleared).** Canonical privacy URL is
now `https://dzianisv.github.io/opencode-mobile/privacy/` — live & verified (HTTP 200) on
the gh-pages branch, serving `distribution/privacy-policy.html`. This GitHub Pages URL is
the canonical privacy URL cited across all store-submission docs (Play "App content"
answers, IzzyOnDroid request). If the owner later deploys the branded
`opencode.vibebrowser.app/privacy`, it can replace the GitHub Pages URL — this change is
reversible. Source file: `distribution/privacy-policy.html` (markdown mirror:
`distribution/privacy-policy.md`).
2. **Google Play → production (biggest unlock, ~15 min).**

View File

@@ -163,7 +163,7 @@ We welcome bug reports, feature requests, and pull requests. See [CONTRIBUTING.m
OpenCode Mobile does not collect personal data. Optional Sentry crash reporting (opt-in, off by default) sends anonymised crash traces to Sentry. No analytics SDKs are bundled. Credentials are stored exclusively on-device in the OS keystore.
Full privacy policy: [opencode.vibebrowser.app/privacy](https://opencode.vibebrowser.app/privacy)
Full privacy policy: [dzianisv.github.io/opencode-mobile/privacy](https://dzianisv.github.io/opencode-mobile/privacy/)
---

View File

@@ -16,7 +16,7 @@ App facts these answers derive from:
---
## 1. Privacy policy
- URL: `https://opencode.vibebrowser.app/privacy`
- URL: `https://dzianisv.github.io/opencode-mobile/privacy/`
## 2. Data safety
**Does your app collect or share any required user data types?**

View File

@@ -103,7 +103,7 @@ Alternative / supplemental terms to rotate in A/B: `code review`, `AI assistant`
|---|---|
| Support URL | https://agentlabs.cc/opencode |
| Marketing URL | https://github.com/dzianisv/opencode-mobile |
| Privacy Policy URL | https://opencode.vibebrowser.app/privacy |
| Privacy Policy URL | https://dzianisv.github.io/opencode-mobile/privacy/ |
---
@@ -339,7 +339,7 @@ To use: you need opencode running somewhere accessible (local Wi-Fi, Tailscale,
- [ ] App icon 1024×1024 PNG (no alpha, no rounded corners)
- [ ] iPhone screenshots (6.7" minimum; 6.5" strongly recommended)
- [ ] iPad screenshots (12.9" minimum)
- [ ] Privacy policy live at https://opencode.vibebrowser.app/privacy
- [ ] Privacy policy live at https://dzianisv.github.io/opencode-mobile/privacy/
- [ ] App Store Connect API key created (for CI — Key ID, Issuer ID, .p8 file)
- [ ] Apple Distribution certificate + provisioning profile (or use EAS managed signing)
- [ ] Export compliance answered (No to custom encryption)

View File

@@ -113,7 +113,7 @@ While waiting for Apple's verification call and approval:
- [ ] Create app icon 1024×1024 PNG
- [ ] Capture iPhone screenshots (use iOS Simulator in Xcode on any Mac)
- [ ] Capture iPad screenshots
- [ ] Write/publish privacy policy at https://opencode.vibebrowser.app/privacy
- [ ] Write/publish privacy policy at https://dzianisv.github.io/opencode-mobile/privacy/
- [ ] Set up EAS account at https://expo.dev/ (free tier, log in with Expo account)
- [ ] Add iOS config patches to `app.json` (done in this PR)
- [ ] Run `npx expo prebuild --platform ios` on a Mac to validate the Xcode project

View File

@@ -107,4 +107,4 @@ We will notify the IzzyOnDroid team via this issue when that happens.
Developer: VIBE TECHNOLOGIES, LLC
Email: support@vibebrowser.app
Website: https://agentlabs.cc/opencode
Privacy policy: https://opencode.vibebrowser.app/privacy
Privacy policy: https://dzianisv.github.io/opencode-mobile/privacy/

View File

@@ -17,7 +17,7 @@ IzzyOnDroid is the fastest OSS distribution channel — typical inclusion is
- [ ] APK is signed with `keystores/production-release.jks`
- [ ] SHA-256 fingerprint confirmed: see `distribution/SIGNING-KEY-FINGERPRINTS.md`
- [ ] Sentry opt-in gate is in production (avoids `Tracking` anti-feature escalation)
- [ ] Privacy policy is live at `https://opencode.vibebrowser.app/privacy`
- [ ] Privacy policy is live at `https://dzianisv.github.io/opencode-mobile/privacy/`
- [ ] `app.json` `version` and `android.versionCode` are set correctly in the tagged commit
---

View File

@@ -144,7 +144,7 @@ Issues: github.com/dzianisv/opencode-mobile/issues
**Required.** Must be a public URL.
Suggested path: `https://opencode.vibebrowser.app/privacy`
Suggested path: `https://dzianisv.github.io/opencode-mobile/privacy/`
Privacy policy must cover:
- What data is collected (Sentry crash diagnostics: device model, OS version, stack trace; no user content)
@@ -297,7 +297,7 @@ CI currently publishes to `internal` track. ✅
- [ ] Adaptive icon (real PNG)
- [ ] Feature graphic 1024×500
- [ ] At least 2 phone screenshots
- [ ] Privacy policy live at https://opencode.vibebrowser.app/privacy
- [ ] Privacy policy live at https://dzianisv.github.io/opencode-mobile/privacy/
- [ ] Decide pricing model
- [ ] Run IARC content rating questionnaire (after app created in Play Console)
- [ ] Complete Data safety form (after app created in Play Console)

View File

@@ -253,8 +253,8 @@
If we make material changes to this policy, we will update the effective date at the top
of this page and, where feasible, notify users via an in-app notice. The latest version
is always available at:
<a href="https://opencode.vibebrowser.app/privacy">
vibebrowser.app/opencode-mobile/privacy
<a href="https://dzianisv.github.io/opencode-mobile/privacy/">
dzianisv.github.io/opencode-mobile/privacy
</a>
</p>

View File

@@ -106,7 +106,7 @@ All diagnostic data is transmitted over HTTPS (TLS 1.2+) to Sentry. We do not tr
## 10. Changes to This Policy
If we make material changes to this policy, we will update the effective date and, where feasible, notify users via an in-app notice. The latest version is always available at:
https://opencode.vibebrowser.app/privacy
https://dzianisv.github.io/opencode-mobile/privacy/
---

View File

@@ -42,7 +42,7 @@ Rejected alternatives:
1. **Google Play identity verification** — upload governor ID (Dzianis Vashchuk). Unlocks: API access, Create app, AAB upload, CI publish.
2. **Apple Developer Program enrollment** — $99/year, D-U-N-S 142059652 ready. iOS agent will produce runbook.
3. **App icon + adaptive icon + feature graphic** — current `assets/*.json` are placeholders. Need real PNGs before either Play or App Store publish.
4. **Privacy policy URL** — must be live at https://opencode.vibebrowser.app/privacy before Play publish. Template in `play-listing.md`.
4. **Privacy policy URL** — live & verified at https://dzianisv.github.io/opencode-mobile/privacy/ (this GitHub Pages URL is the canonical privacy URL used for store submissions; if the owner later deploys the branded `opencode.vibebrowser.app/privacy`, it can replace it — reversible). Template in `play-listing.md`.
### Soft blockers (we can fix without user)

View File

@@ -81,7 +81,7 @@ Because the answer is "No", no ERN (Encryption Registration Number) is required
| 4 | App icon — 1024×1024 PNG, opaque (no alpha) | ✅ Done | `assets/icon-appstore.png` (flattened from Android-produced `assets/icon.png`) |
| 5 | iPhone screenshots 6.7" (1290×2796) + 6.5" (1242×2688) | ✅ Done | `distribution/app-store-graphics/iphone-67/{01,02,03}.png` + `iphone-65/` — 3 mockup screens: connection, chat, diff |
| 6 | iPad screenshots 12.9" (2048×2732) | ✅ Done | `distribution/app-store-graphics/ipad-129/{01,02}.png` — 2 mockup screens |
| 7 | Privacy policy — live at https://opencode.vibebrowser.app/privacy | 🟡 partial | Content handled by Android agent (`distribution/privacy-policy.{md,html}`). iOS-specific ATT / nutrition label addendum written in `distribution/app-store-listing.md`. User must deploy to vibebrowser.app. |
| 7 | Privacy policy — live at https://dzianisv.github.io/opencode-mobile/privacy/ | ✅ done | Live & verified (HTTP 200) on gh-pages. Content handled by Android agent (`distribution/privacy-policy.{md,html}`). iOS-specific ATT / nutrition label addendum written in `distribution/app-store-listing.md`. |
| 8 | Privacy nutrition label (App Tracking + Data Collection) | ✅ Done | Updated in `distribution/app-store-listing.md` — ATT explicitly noted (not used), Sentry opt-in status documented |
| 9 | Export compliance | ✅ Done | `ITSAppUsesNonExemptEncryption: false` added to `app.json`. Answers + rationale in this doc (see Export Compliance section above) and `distribution/app-store-listing.md`. |
| 10 | ATS justification in App Review notes | ✅ Done | Full justification text in `distribution/app-store-listing.md` under "App Review Notes — ATS Justification" |

View File

@@ -56,5 +56,5 @@ When the privacy policy changes, re-deploy the site to pick up the new version.
## Verification command
```bash
curl -sI https://opencode.vibebrowser.app/privacy | head -3
curl -sI https://dzianisv.github.io/opencode-mobile/privacy/ | head -3
```

View File

@@ -64,7 +64,7 @@ For full company facts (D-U-N-S, address, governor, etc.) see `~/.agents/skills/
| 3 | Adaptive icon — 432×432 foreground PNG | Agent | ✅ done — `assets/adaptive-icon.png` (432×432, transparent bg) |
| 4 | Feature graphic — 1024×500 PNG | Agent | ✅ done — `distribution/play-graphics/feature-graphic.png` |
| 5 | At least 2 phone screenshots (1080×1920 or similar) | Agent | ✅ done — `distribution/play-graphics/phone-{01,02,03}.png` (1080×2400 each; 3 screens: connection, chat, diff viewer) |
| 6 | Privacy policy — live at https://opencode.vibebrowser.app/privacy | Agent | ✅ done — `distribution/privacy-policy.html` (deployed to opencode.vibebrowser.app/privacy), `distribution/privacy-policy.md` (source) |
| 6 | Privacy policy — live at https://dzianisv.github.io/opencode-mobile/privacy/ | Agent | ✅ done — live & verified (HTTP 200) on gh-pages; `distribution/privacy-policy.html` (source), `distribution/privacy-policy.md` (markdown mirror) |
| 7 | Data safety form answers (drafted in `distribution/play-listing.md`) | User (in Console after app created) | ✅ verified — no analytics/ad SDKs found; crash logs updated to "Optional (opt-in, default OFF)" per new consent gate |
| 8 | Content rating questionnaire (IARC, drafted) | User (in Console after app created) | ✅ verified — no violence/sexual/gambling/UGC; "interact with other users" = No (user talks to own AI agent) |
| 9 | App access — reviewer instructions for self-hosted opencode (drafted) | User | ✅ verified — instructions accurate; `npm install -g opencode-ai && opencode serve` flow confirmed in `play-listing.md` |

View File

@@ -253,8 +253,8 @@
If we make material changes to this policy, we will update the effective date at the top
of this page and, where feasible, notify users via an in-app notice. The latest version
is always available at:
<a href="https://opencode.vibebrowser.app/privacy">
vibebrowser.app/opencode-mobile/privacy
<a href="https://dzianisv.github.io/opencode-mobile/privacy/">
dzianisv.github.io/opencode-mobile/privacy
</a>
</p>