Skip to content

fix(privacy): policy, delete page and Play Data Safety match the code; no query strings in logs; container log rotation - #738

Merged
mrviduus merged 4 commits into
mainfrom
fix/privacy-policy-matches-code
Oct 6, 2026
Merged

mrviduus merged 4 commits into
mainfrom
fix/privacy-policy-matches-code

Conversation

@mrviduus

@mrviduus mrviduus commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner

Before Play production (~2026-10-16). Every policy statement checked against code (research with file:line evidence).

  • Policy (packages/shared/src/i18n/en.json privacy.*, 5 new keys in legal/sections.ts): upload enrichment sends title, author and opening text to OpenAI; mobile creates a guest account on our server; models in use; AI records not linked to the account but keep text; mobile Sentry + Expo; Open Library; Microsoft Edge TTS (no agreement); caches 30 days; web server logs 14 days without query strings; app logs rotated by size; encrypted off-site backups ~3 months; MCP connectors are the reader's choice. Updated 6 October 2026.
  • Delete-account page: what outlives deletion and for how long.
  • nginx: log_format textstack_noquery — request line and Referer without query strings (/api/tts?text=…, search). nginx -t OK; verified no query text logged.
  • docker-compose: json-file rotation (10 MB × 5) on all services.
  • Runbook: Data Safety table replaced (owner's defaults: OpenAI disclosed, no Analytics purpose on app interactions, Sentry/Expo service providers, Edge TTS + Open Library shared, Apple iOS-only).
  • STATUS AI row: enrichment runs on OpenAI.

Review follow-up (1dc371e): Sentry transactions now drop query strings: mobile beforeSendTransaction (fetch spans carried ?q= / ?text=), and the backend ScrubTransaction now drops Request.QueryString and strips the query from span descriptions. The policy now says the nginx error log can hold the full request line of rejected or failed requests, and that both nginx logs are kept 14 days.

Deploy note: adding logging: to every service in docker-compose.yml changes each container's config. This deploy therefore recreates every container, Postgres included. Expect a brief outage, once.

Tests: shared 599, web 1035, mobile 685, backend SentryScrubber 20; golden fixtures updated.

🤖 Generated with Claude Code

https://claude.ai/code/session_01TBqXDqcbLYbPwGKnTsWYLz

mrviduus and others added 4 commits October 6, 2026 12:16
…ngs from access log

- policy: upload -> OpenAI (title, author, opening text) + Open Library; mobile guest on open + cleanup rule; models; unlinked AI records keep text; mobile Sentry; Expo updates; Edge TTS; MCP connectors; caches 30d, logs 14d, backups ~90d. Dated 2026-10-06
- delete page: what outlives deletion, how long
- nginx: textstack_noquery log_format (combined minus ?query, referer too), all server blocks
- runbook Data Safety re-derived; Sentry section no longer "dormant"
- golden fixtures, sections.ts, CHANGELOG + archive

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TBqXDqcbLYbPwGKnTsWYLz
…inds; STATUS enrichment route

- docker-compose: x-logging anchor (json-file 10m x 5) on every service
- retentionBody2 + delete page: nginx 14d, app logs size-capped
- archive: container logs + nginx error_log known limit
- STATUS: upload enrichment is OpenAI (bookmeta.agent), Ollama only fallback

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TBqXDqcbLYbPwGKnTsWYLz
…nest about nginx error log

- mobile: beforeSendTransaction = scrubTransaction (spans, trace ctx, request lose ?query); tests
- backend: ScrubTransaction drops Request.QueryString, strips url + span descriptions; tests
- collectBody5/retentionBody2: error log can hold full request line of rejected/failed requests; both logs 14d
- archive note

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TBqXDqcbLYbPwGKnTsWYLz
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TBqXDqcbLYbPwGKnTsWYLz
@mrviduus
mrviduus force-pushed the fix/privacy-policy-matches-code branch from 1dc371e to 63057b1 Compare October 6, 2026 16:17
@mrviduus
mrviduus enabled auto-merge (squash) October 6, 2026 16:17
@mrviduus
mrviduus merged commit eabbb4b into main Oct 6, 2026
10 of 11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant