Skip to content

docs: reconcile demo-service privacy and collection disclosures - #329

Merged
jlipworth merged 3 commits into
mainfrom
codex/fix-325-privacy-disclosures
Sep 29, 2026
Merged

jlipworth merged 3 commits into
mainfrom
codex/fix-325-privacy-disclosures

Conversation

@jlipworth

Copy link
Copy Markdown
Owner

Summary

  • Replace absolute no-developer-backend/media-hosting claims with the actual distinction between ordinary user-selected servers and the optional project-operated review/demo service.
  • Document operational records, server-token handling, limited nightly reset, logs/backups, and unknown service-wide deletion limits without inventing a retention promise.
  • Audit all Apple optional-disclosure criteria for GitHub/diagnostic handoffs; the prominent in-app submitting-account condition is not established.
  • Add sanitized, bounded read-only infrastructure evidence and a proposed data/purpose/linkage mapping for owner review. Uncheck the previously over-certified release privacy gate.

Related to #325, #280 and #92. Does not close #325: database cleanup/expiry, centralized/edge retention, backup coverage, privileged-access review, final candidate manifests and owner-approved App Store Connect answers remain open. #326 required-reason API work is separate.

Evidence boundaries

Live route access logs are disabled; Jellyfin warning logs have a three-file daily/size rotation (three files observed). The daily reset clears catalog progress, not auth/activity/log/backup data. Loki declares 30 days but deletion enforcement was not established. Config-volume backup status is recent; configured copy counts are not maximum-age guarantees. Source-described Velero schedules were absent from the live schedule list. The audit records each limitation rather than treating settings as deletion proof.

No runtime or manifest changes. No service configuration, credentials, resets, playback/transcodes, App Store Connect answers, legal declarations, versions, uploads or releases were changed. No private endpoints, credentials, user rows or raw logs are included.

Validation

  • Canonical hermetic PMSKit suite: 1,707 tests passed (--no-parallel --skip 'Live.*ProbeTests').
  • Strict MkDocs, rendered-site links/anchors and Mermaid: passed.
  • scripts/ci-hygiene.sh: passed, 334 tooling tests.
  • git diff --check: passed.
  • Documentation-only: no simulator boot/build. Required setup attempted but golden .simid was absent; no simulator was created. Own-worktree teardown confirms none to remove.

Approval gates

Before certifying collection answers, the owner must verify actual auth/device/activity expiry and aggregate ages, centralized-log deletion, edge/provider records, backup inventories/downstream copies and access; confirm received support-data purposes/retention; review the mapping against the exact archives/current account state; and authorize any account or manifest edits separately. This PR improves current wording without representing those gates as complete.

@jlipworth

Copy link
Copy Markdown
Owner Author

Validation close-loop: all five reported CI checks reached success (PR docs/hygiene/PMSKit and push hygiene/PMSKit). Local canonical PMSKit tests (1,707), strict docs/links/Mermaid and hygiene tests (334) also passed. This remains a documentation/evidence PR, not closure of the remaining #325 retention, disclosure-exemption or account-owner approval gates.

@jlipworth
jlipworth merged commit 181b943 into main Sep 29, 2026
5 checks passed
@jlipworth
jlipworth deleted the codex/fix-325-privacy-disclosures branch September 29, 2026 15:28
jlipworth added a commit that referenced this pull request Sep 29, 2026
## Summary

Consolidates the still-relevant work from `codex/store-demo-provenance`
(`7f93e1ee`) and `codex/prerelease-disclosure-audit` (`a61eff14`) onto
current main (`181b9431`). No app runtime changes.

- Retain the public open-film/derived-artwork provenance snapshot and
active capture/reviewer plan; distinguish fixture images from final
store images.
- Recheck official Blender license pages and Apple screenshot size
guidance on 2026-09-29. Preserve historical catalog/hash verification
dates and require a fresh deployed-asset check before capture.
- Preserve merged #328/#329 privacy wording and archive-report gates
rather than replaying stale text. Add the explicit #259 deferral and
unchecked exact-candidate export/accessibility gates.
- Keep the original disclosure audit as dated evidence, with a
subsequent-disposition note. Remove current-sounding simulator/worktree
assumptions from the capture plan and add it to the active-plan index.
- Add a manifest consistency regression test; this verifies recorded
metadata, not the remote asset bytes or legal clearance of eventual
compositions.

## Validation

- 10 screenshot tooling tests.
- Strict MkDocs, rendered/source links, Mermaid, repository redaction
and tooling hygiene.
- Hermetic PMSKit tests (live probes excluded).
- Official source-page verification; no new film download or
deployed-server checksum audit.

No simulator, live playback, infrastructure changes, account edits,
uploads, version changes or physical-device acceptance. No final
screenshots produced. No new native build required: docs/spec/test
changes only.

## Remaining scope

Related #92, #259, #280, #325, #326; this PR closes none of them. Final
captures, storefront credits/editorial review, age suitability,
exact-candidate reviewer journeys, signed-archive privacy reports and
owner-approved account answers remain open. The source
branches/worktrees are preserved until this consolidation is reviewed
and merged; this PR does not remove them.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Release privacy: reconcile project-operated review demo and collection disclosures

1 participant