some claims in PRIVACY.md are wrong #20

Closed
opened 2026-08-30 20:13:59 +00:00 by uwayss · 2 comments
Owner

We say that the app never touches the network but:

  1. We fetch updates from https://ota.uwayss.com/... with expo-updates, on every cold launch, handing it the user's IP, app version, and platform...
  2. in SettingsScreen.tsx the privacy policy link in the settings links to here like:
Linking.openURL('https://code.uwayss.com/...'),

We should:

  1. allow users to opt out from automatic OTA update checks in the settings
  2. update the privacy page and state that the app hits my ota server on every cold launch for bug fixes and small improvements by default
  3. find a way to render the privacy policy inside the app without needing web access at all. since we don't really update it a lot and when we do, it'll be shipped with ota and be bundled to the version the users are using so we should be fine
We say that the app never touches the network but: 1. We fetch updates from https://ota.uwayss.com/... with expo-updates, *on every cold launch*, handing it the user's IP, app version, and platform... 2. in `SettingsScreen.tsx` the privacy policy link in the settings links to here like: ```typescript Linking.openURL('https://code.uwayss.com/...'), ``` We should: 1. allow users to opt out from automatic OTA update checks in the settings 2. update the privacy page and state that the app hits my ota server on every cold launch for bug fixes and small improvements by default 3. find a way to render the privacy policy inside the app without needing web access at all. since we don't really update it a lot and when we do, it'll be shipped with ota and be bundled to the version the users are using so we should be fine
Author
Owner

@claude open a PR resolving all of these pls and i'll take a look

@claude open a PR resolving all of these pls and i'll take a look
Collaborator

I pushed a branch claude/privacy-ota-fixes (commit 2361367) addressing all three points:

1. Opt-out for automatic OTA checks

  • app.json: set updates.checkAutomatically to "ON_ERROR_RECOVERY", so expo-updates no longer auto-checks on every cold launch on its own.
  • Added a new src/core/services/updateService.ts with checkForOtaUpdate(), which does the check/fetch/reload manually.
  • Added an isAutoUpdateEnabled setting (default true, preserving current behavior) wired into appStore.ts, called from initialize() only when enabled.
  • Added an "Automatic Updates" toggle in Settings (settingsData.ts, SettingsListItem.tsx), translated into all six locales.

2. Updated PRIVACY.md

  • Now states plainly that the app checks ota.uwayss.com on every cold launch by default (sending IP, app version, platform) for bug fixes/small improvements, and that it can be turned off in Settings. Removed the "never touches the network" claim.

3. Privacy policy now renders in-app

  • Added src/screens/PrivacyPolicyScreen.tsx, registered in the Settings stack navigator.
  • Content is bundled as i18n strings (privacyPolicy.* in en.json, mirroring the PRIVACY.md rewrite) — no network request needed. Since it ships with the JS bundle, an OTA update will carry future edits to whatever version users are on, per your point #3.
  • The Settings "Privacy Policy" row now navigates to this screen instead of opening the external CodeHub link.

Verified with tsc --noEmit, expo lint, and prettier --check — all clean (the 4 pre-existing prettier warnings in src/constants/*.ts are unrelated to this change).

Compare/PR link: https://code.uwayss.com/uwayss/muhsin/compare/main...claude/privacy-ota-fixes

One thing worth a second look before merging: I left the legal-text body of the new in-app privacy screen in English only (falling back via i18n.enableFallback) rather than machine-translating it into the other five locales, since inaccurate translations of policy text seemed riskier than an English fallback. Happy to add translations if you'd prefer.

I pushed a branch `claude/privacy-ota-fixes` (commit `2361367`) addressing all three points: **1. Opt-out for automatic OTA checks** - `app.json`: set `updates.checkAutomatically` to `"ON_ERROR_RECOVERY"`, so expo-updates no longer auto-checks on every cold launch on its own. - Added a new `src/core/services/updateService.ts` with `checkForOtaUpdate()`, which does the check/fetch/reload manually. - Added an `isAutoUpdateEnabled` setting (default `true`, preserving current behavior) wired into `appStore.ts`, called from `initialize()` only when enabled. - Added an "Automatic Updates" toggle in Settings (`settingsData.ts`, `SettingsListItem.tsx`), translated into all six locales. **2. Updated `PRIVACY.md`** - Now states plainly that the app checks `ota.uwayss.com` on every cold launch by default (sending IP, app version, platform) for bug fixes/small improvements, and that it can be turned off in Settings. Removed the "never touches the network" claim. **3. Privacy policy now renders in-app** - Added `src/screens/PrivacyPolicyScreen.tsx`, registered in the Settings stack navigator. - Content is bundled as i18n strings (`privacyPolicy.*` in `en.json`, mirroring the `PRIVACY.md` rewrite) — no network request needed. Since it ships with the JS bundle, an OTA update will carry future edits to whatever version users are on, per your point #3. - The Settings "Privacy Policy" row now navigates to this screen instead of opening the external CodeHub link. Verified with `tsc --noEmit`, `expo lint`, and `prettier --check` — all clean (the 4 pre-existing prettier warnings in `src/constants/*.ts` are unrelated to this change). Compare/PR link: https://code.uwayss.com/uwayss/muhsin/compare/main...claude/privacy-ota-fixes One thing worth a second look before merging: I left the legal-text body of the new in-app privacy screen in English only (falling back via `i18n.enableFallback`) rather than machine-translating it into the other five locales, since inaccurate translations of policy text seemed riskier than an English fallback. Happy to add translations if you'd prefer.
Sign in to join this conversation.
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
uwayss/muhsin#20
No description provided.