Add a privacy page, and keep the map cache out of the app's backup - #71
Merged
Merged
Conversation
The store requires an app that reads the device's location to link to a privacy policy from inside the app. /privacy says what the site and the Android app send, to whom, and what they keep on the device, from the code: GitHub Pages serving the site, the weekly country lookup, the tile provider, the site's own name index and landmark files, and nothing else. The footer and the end of the app's panel link to it; the app claims only /play links, so the page opens in the browser. Writing the storage section found a defect. The map library keeps its tile cache in the app's own files, where Android's backup looks by default, and the app lets it grow to 200 MB. A cloud backup over 25 MB is refused whole, so the saved places the README promised a new phone would have gone with it. Backup rules for Android 12 and later, and for earlier releases, now leave the cache out; a backup run through the local transport took the saved places and the settings, a few kilobytes, and not the cache.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What changes
Website
/privacy. It covers what the site and the Android app send, to whom, and what they keep on the device. Every line is taken from the code:api.country.is, orget.geojs.ioas a fallback, receives the IP address at most weekly, for the front page's country. A blocked lookup falls back to the time zone and language, which stay in the browser.Android app
/playlinks, so the page is not captured by the app itself.PRIVACY_ADDRESSlives in core, with a test that it stays outside/play.files/mbgl-offline.db, in the app's own files. Android's backup takes that folder by default, and the cache may grow to 200 MB. A cloud backup over 25 MB is refused whole, so the saved places the README promises a new phone would have been lost with it.res/xml/data_extraction_rules.xml(Android 12 and later) andres/xml/backup_rules.xml(earlier) now exclude the cache and its SQLite side files.Checks
/privacyin the sitemap.{' '}, as the footer does.bmgr backupnowthrough the local transport, with the backup rule parser's logging on, showed the four excludes. It measured onlysaved-places.jsonandpreferences.xml: success, about 6 KB, the cache left out. The emulator's backup was switched back off afterwards.