Skip to content

Add a privacy page, and keep the map cache out of the app's backup - #71

Merged
octopranav merged 1 commit into
mainfrom
privacy-page
Sep 24, 2026
Merged

octopranav merged 1 commit into
mainfrom
privacy-page

Conversation

@octopranav

Copy link
Copy Markdown
Owner

What changes

Website

  • New page, /privacy. It covers what the site and the Android app send, to whom, and what they keep on the device. Every line is taken from the code:
    • GitHub Pages serves the site.
    • api.country.is, or get.geojs.io as a fallback, receives the IP address at most weekly, for the front page's country. A blocked lookup falls back to the time zone and language, which stay in the browser.
    • OpenFreeMap serves the map tiles.
    • The site's own name index and landmark files are read from this site, so the host sees which part of the index or which area's file.
    • Kept in the browser: three settings, plus the offline caches.
    • The app: location only on request and never sent anywhere; the same two hosts; what is kept on the device and what is backed up. Share and Copy work only when pressed. Read aloud uses the device's speech engine, which may use its provider.
  • The footer links to it.

Android app

  • A "Privacy" link at the end of the panel opens the page in the browser. The store requires an in-app link for apps that read location. The app claims only /play links, so the page is not captured by the app itself. PRIVACY_ADDRESS lives in core, with a test that it stays outside /play.
  • Backup fix. MapLibre keeps its tile cache, files/mbgl-offline.db, in the app's own files. Android's backup takes that folder by default, and the cache may grow to 200 MB. A cloud backup over 25 MB is refused whole, so the saved places the README promises a new phone would have been lost with it. res/xml/data_extraction_rules.xml (Android 12 and later) and res/xml/backup_rules.xml (earlier) now exclude the cache and its SQLite side files.

Checks

  • Site:
    • Type check clean; the build lists /privacy in the sitemap.
    • In the browser, the text reads correctly. Astro's HTML compression had dropped four spaces before inline links and code; they are fixed with {' '}, as the footer does.
    • At 375 px wide in light mode: no sideways scroll and no console errors.
    • The GitHub privacy statement link resolves.
  • App:
    • Core tests pass.
    • On the emulator, the link opened Chrome, at its first-run screen, which was not clicked through.
    • Backup rules: a bmgr backupnow through the local transport, with the backup rule parser's logging on, showed the four excludes. It measured only saved-places.json and preferences.xml: success, about 6 KB, the cache left out. The emulator's backup was switched back off afterwards.
  • The audits, the token and icon checks, and the scan for rival names and dashes all pass.

The store requires an app that reads the device's location to link to a
privacy policy from inside the app. /privacy says what the site and the
Android app send, to whom, and what they keep on the device, from the code:
GitHub Pages serving the site, the weekly country lookup, the tile provider,
the site's own name index and landmark files, and nothing else. The footer
and the end of the app's panel link to it; the app claims only /play links,
so the page opens in the browser.

Writing the storage section found a defect. The map library keeps its tile
cache in the app's own files, where Android's backup looks by default, and
the app lets it grow to 200 MB. A cloud backup over 25 MB is refused whole,
so the saved places the README promised a new phone would have gone with it.
Backup rules for Android 12 and later, and for earlier releases, now leave
the cache out; a backup run through the local transport took the saved
places and the settings, a few kilobytes, and not the cache.
@octopranav
octopranav merged commit 3a4fbdb into main Sep 24, 2026
21 checks passed
@octopranav
octopranav deleted the privacy-page branch September 24, 2026 18:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant