Repository navigation
fix(privacy): policy, delete page and Play Data Safety match the code; no query strings in logs; container log rotation - #738
Merged
Conversation
…ngs from access log - policy: upload -> OpenAI (title, author, opening text) + Open Library; mobile guest on open + cleanup rule; models; unlinked AI records keep text; mobile Sentry; Expo updates; Edge TTS; MCP connectors; caches 30d, logs 14d, backups ~90d. Dated 2026-10-06 - delete page: what outlives deletion, how long - nginx: textstack_noquery log_format (combined minus ?query, referer too), all server blocks - runbook Data Safety re-derived; Sentry section no longer "dormant" - golden fixtures, sections.ts, CHANGELOG + archive Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TBqXDqcbLYbPwGKnTsWYLz
…inds; STATUS enrichment route - docker-compose: x-logging anchor (json-file 10m x 5) on every service - retentionBody2 + delete page: nginx 14d, app logs size-capped - archive: container logs + nginx error_log known limit - STATUS: upload enrichment is OpenAI (bookmeta.agent), Ollama only fallback Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TBqXDqcbLYbPwGKnTsWYLz
…nest about nginx error log - mobile: beforeSendTransaction = scrubTransaction (spans, trace ctx, request lose ?query); tests - backend: ScrubTransaction drops Request.QueryString, strips url + span descriptions; tests - collectBody5/retentionBody2: error log can hold full request line of rejected/failed requests; both logs 14d - archive note Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TBqXDqcbLYbPwGKnTsWYLz
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TBqXDqcbLYbPwGKnTsWYLz
mrviduus
force-pushed
the
fix/privacy-policy-matches-code
branch
from
October 6, 2026 16:17
1dc371e to
63057b1
Compare
mrviduus
enabled auto-merge (squash)
October 6, 2026 16:17
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Before Play production (~2026-10-16). Every policy statement checked against code (research with file:line evidence).
packages/shared/src/i18n/en.jsonprivacy.*, 5 new keys inlegal/sections.ts): upload enrichment sends title, author and opening text to OpenAI; mobile creates a guest account on our server; models in use; AI records not linked to the account but keep text; mobile Sentry + Expo; Open Library; Microsoft Edge TTS (no agreement); caches 30 days; web server logs 14 days without query strings; app logs rotated by size; encrypted off-site backups ~3 months; MCP connectors are the reader's choice. Updated 6 October 2026.log_format textstack_noquery— request line and Referer without query strings (/api/tts?text=…, search).nginx -tOK; verified no query text logged.Review follow-up (1dc371e): Sentry transactions now drop query strings: mobile
beforeSendTransaction(fetch spans carried?q=/?text=), and the backendScrubTransactionnow dropsRequest.QueryStringand strips the query from span descriptions. The policy now says the nginx error log can hold the full request line of rejected or failed requests, and that both nginx logs are kept 14 days.Deploy note: adding
logging:to every service indocker-compose.ymlchanges each container's config. This deploy therefore recreates every container, Postgres included. Expect a brief outage, once.Tests: shared 599, web 1035, mobile 685, backend SentryScrubber 20; golden fixtures updated.
🤖 Generated with Claude Code
https://claude.ai/code/session_01TBqXDqcbLYbPwGKnTsWYLz