Skip to content

feat: revise the terms and privacy policy for the mobile apps and put v2.1 in effect - #16

Closed
Yamaguchi wants to merge 1 commit into
chaintope:mainfrom
Yamaguchi:feat/revise_legal_docs_for_mobile_apps
Closed

Yamaguchi wants to merge 1 commit into
chaintope:mainfrom
Yamaguchi:feat/revise_legal_docs_for_mobile_apps

Conversation

@Yamaguchi

Copy link
Copy Markdown
Contributor

Summary

Publishes version 2.1 of the terms of service and the privacy policy, and puts it
in effect. Both documents now cover the iOS and Android apps as well as the Chrome
extension.

The iOS app is being submitted to the App Store (chaintope/tapylet-for-mobile#21).
App Review requires the privacy policy handed to Apple to apply to the app being
reviewed (guideline 5.1.1), and both documents defined "the Service" as the Chrome
extension alone.

Why 2.1, and why the switch is immediate

Version 2.0 was written and announced — legal.json has carried
upcoming: { version: "2.0", effectiveFrom: "2026-09-01" } — but it was never put
in effect, so the version users have agreed to is still 1.0. Editing 2.0 in place
is not an option: users have already been shown its change list. 2.1 is a new
version that supersedes it.

The switch is made in one step rather than announced first. Users are moving from
1.0, which is a major bump, so everyone is asked to agree (acknowledge) again from
their next launch, and the re-consent screen carries the change list. That screen
is the notice section 7 of the terms undertakes to give.

Because the diff users experience is from 1.0, the change list in legal.json
carries the items announced for 2.0 alongside the new ones.

What changed in the documents

Both define "the Service" as the Chrome extension, the iOS app and the Android
app, and state that they apply to all three.

Terms of service:

  • Section 2 said the network was fixed per distribution. It is not: both the
    extension and the mobile app switch at runtime, defaulting to mainnet.
  • Section 1 no longer treats installing or using the service as agreement to the
    terms. Consent is taken on the welcome screen, with a checkbox per document and
    the version recorded, so the deemed-agreement clause was carrying nothing and
    said less than what actually happens.

Privacy policy:

  • Where data is stored is written per platform: browser local storage
    (chrome.storage.local) for the extension; app-private storage on mobile, with
    the wallet data in the iOS Keychain, or encrypted under a key held in the
    Android Keystore.
  • New section 2.5 covers the camera: the mobile apps read address QR codes, the
    frames are processed on the device, and no image is stored or sent.
  • The request that checks the minimum supported version is listed among the
    external communications, and so is the App Store / Google Play page that opens
    for an update.
  • Deleting the app does not necessarily clear the iOS Keychain; the text now says
    so rather than promising that everything is removed.
  • On iOS the wallet data is excluded from iCloud and device-transfer backups
    (WHEN_UNLOCKED_THIS_DEVICE_ONLY, which is an iOS-only option). On Android the
    encrypted blob can be carried by a device backup — android:allowBackup is
    true — but the Keystore key never leaves the device, so a restored copy cannot
    be decrypted elsewhere. The text says this rather than claiming both platforms
    are excluded from backup.

Changes to the files

File Change
docs/terms/v2.1.html New. Based on v2.0
docs/privacy/v2.1.html New. Based on v2.0
docs/legal.json Version in effect is 2.1 for both documents; upcoming dropped; change lists rewritten as the diff from 1.0
docs/terms.html, docs/privacy.html The version-less URL now points at v2.1
docs/index.html Subtitle covers all three platforms
src/extension/legal.ts BUNDLED_LEGAL_DOCS raised to 2.1

v1.0 and v2.0 are left where they are. They are linked from nowhere but stay
readable to anyone who knows the URL.

Effect on users

Every existing user of the extension meets the re-consent screen on their next
launch, and cannot reach the wallet until they respond. This is what a major
revision does.

tapylet-for-mobile needs no release: main links to the version-less URLs, so the
redirect carries its users to v2.1. It does not record which version was agreed to,
so its existing testers are not asked again.

tapylet-for-web is unaffected. It neither reads this manifest nor links here — it
serves its own copies of the documents and holds them at 1.0 in src/shared/legal.ts
(see Notes).

How to verify

pnpm test   # 124 tests, including test/legalDocs.test.ts against the published files

After deploying:

curl -s https://chaintope.github.io/tapylet/privacy.html | grep -o 'privacy/v[0-9.]*\.html'
# => privacy/v2.1.html
curl -s https://chaintope.github.io/tapylet/legal.json | grep -o '"version": "[0-9.]*"'
# => "version": "2.1" twice

Then open the extension and confirm the re-consent screen lists the changes and
links to v2.1.

Related

  • chaintope/tapylet-for-mobile#21

Notes

  • The privacy policy describes the minimum-supported-version request. The file it
    reads (docs/app/min-version.json) is already on main, but the request itself
    is made by tapylet-for-mobile's forced-upgrade feature, which is not yet merged.
    That should land before the App Store build.
  • tapylet-for-web keeps its own copies of the documents under
    src/client/public/{terms,privacy}/v1.0.html and does not read this manifest, so
    it stays on 1.0 until it is changed on its own. Whether it should be brought onto
    these documents at all is open: it stores keys server-side behind a passkey, which
    is a different arrangement from the extension and the mobile apps.
  • The documents are Japanese only. The change lists in legal.json carry English.

@Yamaguchi

Copy link
Copy Markdown
Contributor Author

モバイルアプリとChrome拡張の利用規約、プライバシーポリシーは別にするため、このPRはクローズ

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant