Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .beads/interactions.jsonl
Original file line number Diff line number Diff line change
Expand Up @@ -83,3 +83,4 @@
{"id":"int-4a5d788f","kind":"field_change","created_at":"2026-06-01T22:37:26.718366Z","actor":"Jacob Cole","issue_id":"OpenChat-ap3","extra":{"field":"status","new_value":"closed","old_value":"in_progress","reason":"Decision shipped 2026-06-01 in docs/decisions/2026-06-01-expo-contacts.md: DEFER expo-contacts integration. Blocked by phone-sign-in decision (xf4 also deferred today). Without phone-keyed users, contacts match rate is 5-10% — not worth the 40-60% iOS permission decline rate. Re-open when xf4 ships phone sign-in OR we get ≥3 user requests for contact-discovery."}}
{"id":"int-54d5fe80","kind":"field_change","created_at":"2026-06-01T22:38:00.242989Z","actor":"Jacob Cole","issue_id":"OpenChat-3kr.2","extra":{"field":"status","new_value":"in_progress","old_value":"open"}}
{"id":"int-ee89998e","kind":"field_change","created_at":"2026-06-01T22:40:15.033587Z","actor":"Jacob Cole","issue_id":"OpenChat-3kr.2","extra":{"field":"status","new_value":"closed","old_value":"in_progress","reason":"Shipped 2026-06-01: NVCComposerModal + 💙 button in ChatScreen composer. Fields: Observation (required), Feeling (required), Need, Request. Assembled message uses unicode bullet prefixes for visual structure. Stuffs draft into composer text on submit so user gets one revision pass before send (self-empathy moment per ticket stretch goal). Bot-side @nvc coaching deferred to OpenChat-3kr.3."}}
{"id":"int-10eb2708","kind":"field_change","created_at":"2026-07-12T00:32:05.202115Z","actor":"tmad4000","issue_id":"OpenChat-ig3","extra":{"field":"status","new_value":"closed","old_value":"in_progress","reason":"Completed launch-readiness audit and safe documentation/legal updates. Added docs/app-store-launch-readiness.md, refreshed privacy policy and App Store privacy labels, linked from testers guide, wrote required report, and filed OpenChat-epd for remaining human/App Store Connect blockers."}}
145 changes: 74 additions & 71 deletions .beads/issues.jsonl

Large diffs are not rendered by default.

34 changes: 26 additions & 8 deletions apps/server/src/legal/privacy.md
Original file line number Diff line number Diff line change
@@ -1,43 +1,61 @@
# Privacy Policy

**Last updated: June 1, 2026**
**Last updated: July 12, 2026**

This Privacy Policy describes how OpenChat (operated by chat.globalbr.ai) collects, uses, and handles your information when you use our service.

## Information We Collect

**Account information.** When you sign up, we collect your email address and display name. If you sign in with Google or Apple, we receive your profile information from that provider.

**Messages.** We store the messages you send and receive so conversations persist across sessions. Message content is stored on our servers.
**Messages and attachments.** We store the messages you send and receive so conversations persist across sessions. Message content, reactions, image attachments, voice messages, voice-message transcripts, link previews, and related conversation metadata are stored on our servers.

**Usage data.** We collect basic presence information (online/offline status) and the timestamp of your last activity.
**Profile and app activity.** We collect profile details you provide, such as display name, avatar, status message, onboarding state, blocked users, report submissions, feedback submissions, and the timestamp of your last activity.

**Push notification tokens.** If you enable push notifications on a mobile device, we store a device token to deliver notifications.

**Diagnostics.** The app may send diagnostic logs, error details, stack traces, user agent details, request metadata, and crash/error context to help us debug and operate the service.

## How We Use Your Information

- To operate the chat service and deliver your messages.
- To send push notifications when you receive new messages.
- To show your presence status to people you have conversations with.
- To provide user safety features such as reporting, blocking, and moderation review.
- To provide AI features you choose to use, including AI assistant replies, message rewriting, semantic search, and voice-message transcription.
- To debug, secure, and improve service reliability.
- To respond to support requests sent to support@chat.globalbr.ai.

## Third-Party AI
## Third-Party Processors

We do not sell personal information and we do not use your information to track you across other companies' apps or websites. We use service providers to operate OpenChat:

Some conversations include an AI assistant powered by Anthropic's Claude model. When you send a message in a conversation that includes the AI bot, your message content is sent to Anthropic's API to generate a reply. Anthropic's use of that data is governed by [Anthropic's Privacy Policy](https://www.anthropic.com/privacy). Conversations containing an AI participant are marked in the app so you always know when AI is present.
- **Anthropic.** Some conversations include an AI assistant powered by Anthropic's Claude model. When you send a message in a conversation that includes the AI bot, or use the message-rewrite tools, relevant message text is sent to Anthropic to generate a reply or rewrite. Anthropic's use of that data is governed by [Anthropic's Privacy Policy](https://www.anthropic.com/privacy). Conversations containing an AI participant are marked in the app so you always know when AI is present.
- **OpenAI.** OpenChat may send message text to OpenAI to generate embeddings for semantic search, and voice-message audio to OpenAI Whisper to produce transcripts. These features are used for app functionality, not advertising or model training by OpenChat.
- **Expo.** If you enable push notifications, Expo receives push tokens and notification payloads needed to deliver notifications.
- **Apple and Google.** If you sign in with Apple or Google, those providers process authentication information and provide OpenChat with account identifiers such as email, name, and provider-specific IDs.
- **AWS/S3-compatible storage and Neo4j Aura.** OpenChat uses hosted infrastructure to store and process app data, including account data, messages, attachments, and conversation metadata.
- **World Issue Tracker and Slack/webhook tooling.** If you submit feedback or a safety report, the submitted text and relevant report metadata may be routed to team review tools so we can respond.

## Data Retention

We retain your account data and messages for as long as your account is active. You can delete your account at any time (see below), which removes all your personal information and redacts the content of your messages from shared conversations.
We retain your account data, messages, attachments, and related conversation metadata for as long as your account is active or as needed to operate the service. You can delete your account at any time (see below), which removes your profile, push tokens, sessions, and credentials, and redacts the content of messages you authored from shared conversations. Some operational logs, backups, reports, and security records may remain for a limited period where needed for reliability, safety, abuse prevention, or legal compliance.

## Your Rights

**Delete your account.** In the app, go to Settings → Delete My Account. This permanently deletes your account, push tokens, and all message content you authored. Conversation structure (other participants' messages) is preserved, but your messages are replaced with "Message deleted."

**Data requests.** To request a copy of your data or ask questions about privacy, email support@chat.globalbr.ai.
**Data export and requests.** You can export account and conversation data from the app. To request a copy of your data or ask questions about privacy, email support@chat.globalbr.ai.

**Reports and blocking.** You can report messages or users in the app and block users you do not want to hear from. Reports are reviewed by the OpenChat team.

## Data Security

We use industry-standard transport encryption (TLS/HTTPS) for all data in transit. Your data is stored in a database accessible only to the application server.
We use industry-standard transport encryption (TLS/HTTPS) for data in transit. Your data is stored in databases and object storage accessible only to the application server and authorized operators.

## International Transfers

OpenChat is operated from the United States and uses infrastructure that may process or store data in the United States, including AWS Lightsail in US East and Neo4j Aura. If you use OpenChat from outside the United States, your information may be transferred to and processed in the United States.

## Children

Expand Down
86 changes: 86 additions & 0 deletions docs/app-store-launch-readiness.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,86 @@
# OpenChat App Store Launch Readiness

Last audited: 2026-07-12 for `apps/mobile/app.config.js` v0.1.23 and bundle id `com.jacobcole.openchat`.

This checklist is for the first public Apple App Store submission. It is separate from TestFlight release operations in `docs/testers.md`.

## Ready In Code

- Sign in with Apple is present on iOS and backed by `POST /api/auth/apple/idtoken-exchange`.
- Google sign-in and email/password sign-in are available from the login screen.
- Account deletion is available from Settings and backed by `DELETE /api/auth/me`.
- Data export is available for account and conversation data.
- User-generated content controls are present: report message, report user, block user, unblock from Settings, and server-side report storage/webhook notification.
- AI disclosure is present for conversations containing bot users.
- Legal links are exposed from Settings and served at `https://chat.globalbr.ai/legal/privacy` and `https://chat.globalbr.ai/legal/terms`.
- Native permissions are explained in `app.config.js`: camera for QR scanning, photo library for image sharing, microphone for voice messages, remote notification background mode for push.
- TestFlight/native release scripts and EAS submit configuration exist in `apps/mobile/scripts/local-build.sh` and `apps/mobile/eas.json`.

## Human/App Store Connect Blockers

- Create and verify the reviewer account `openchat-reviewer@globalbr.ai` in production.
- Seed reviewer-visible demo data. The current `apps/server/src/seed-test-data.ts` only targets Alice/Bob test accounts, so reviewer data must be created manually or the script must be extended before submission.
- Store the reviewer password in 1Password and paste it only into App Store Connect Review Notes at submission time.
- Confirm `support@chat.globalbr.ai` is monitored.
- Prepare App Store screenshots for required iPhone sizes. No screenshot set was found in the repo during this audit.
- Fill App Store Connect metadata: app description, keywords, support URL, marketing URL if desired, copyright, age rating, category, review notes, privacy labels, and version release notes.
- Confirm the production backend at `https://chat.globalbr.ai` is live, healthy, and using production env vars for Google, Apple, Anthropic/OpenAI features, push, reports, and feedback.
- Obtain explicit approval before submitting for App Review.

## Recommended Review Notes

Paste only after the reviewer account exists and has demo data:

```text
OpenChat is a messaging app with optional AI assistant features.

Demo account:
Email: openchat-reviewer@globalbr.ai
Password: <paste from 1Password at submission time>

Sign in with the email/password form on the login screen. Sign in with Apple is also available on iOS and Google sign-in is available as a third-party login option.

Demo coverage:
- Direct and group chats with seeded messages
- Image attachments and voice messages
- Report/block flows from message actions and user profiles
- Account deletion in Settings -> Legal & Account -> Delete my account
- Privacy Policy and Terms links in Settings
- AI assistant disclosure appears in conversations that include a bot user

Backend services are live at https://chat.globalbr.ai. The app requires network access for sign-in, messaging, push registration, attachments, and AI features.
```

## Submission Commands

Do not run these until screenshots, reviewer credentials, App Store Connect metadata, and final approval are complete.

Web/server/RN-web deploy:

```bash
cd /Users/jacobcole/.treehouse/OpenChat-a02908/1/OpenChat
bash infra/deploy.sh
```

Native iOS build, TestFlight submit, and tester publication:

```bash
cd /Users/jacobcole/.treehouse/OpenChat-a02908/1/OpenChat/apps/mobile
TMPDIR="$HOME/.ocbuild-tmp" bash scripts/local-build.sh
```

Local build constraints:

- Do not run `scripts/local-build.sh` under tmux.
- Use Node 22.
- Expect the script to bump the app version, commit, push, build locally, submit to App Store Connect, and publish to the configured TestFlight testers.

## App Review Readiness Verdict

OpenChat is not ready for App Review submission until the human/App Store Connect blockers above are cleared. The minimum blocker list is:

1. Reviewer account exists, credentials are available in App Store Connect Review Notes, and demo data is seeded.
2. App Store screenshots and metadata are complete.
3. Privacy labels are entered in App Store Connect from `docs/app-store-privacy-labels.md`.
4. Production backend and legal URLs are verified live.
5. Explicit approval is given to submit for App Review.
Loading