Repository navigation
Conversation
Contributor
Author
|
モバイルアプリとChrome拡張の利用規約、プライバシーポリシーは別にするため、このPRはクローズ |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Publishes version 2.1 of the terms of service and the privacy policy, and puts it
in effect. Both documents now cover the iOS and Android apps as well as the Chrome
extension.
The iOS app is being submitted to the App Store (chaintope/tapylet-for-mobile#21).
App Review requires the privacy policy handed to Apple to apply to the app being
reviewed (guideline 5.1.1), and both documents defined "the Service" as the Chrome
extension alone.
Why 2.1, and why the switch is immediate
Version 2.0 was written and announced —
legal.jsonhas carriedupcoming: { version: "2.0", effectiveFrom: "2026-09-01" }— but it was never putin effect, so the version users have agreed to is still 1.0. Editing 2.0 in place
is not an option: users have already been shown its change list. 2.1 is a new
version that supersedes it.
The switch is made in one step rather than announced first. Users are moving from
1.0, which is a major bump, so everyone is asked to agree (acknowledge) again from
their next launch, and the re-consent screen carries the change list. That screen
is the notice section 7 of the terms undertakes to give.
Because the diff users experience is from 1.0, the change list in
legal.jsoncarries the items announced for 2.0 alongside the new ones.
What changed in the documents
Both define "the Service" as the Chrome extension, the iOS app and the Android
app, and state that they apply to all three.
Terms of service:
extension and the mobile app switch at runtime, defaulting to mainnet.
terms. Consent is taken on the welcome screen, with a checkbox per document and
the version recorded, so the deemed-agreement clause was carrying nothing and
said less than what actually happens.
Privacy policy:
(
chrome.storage.local) for the extension; app-private storage on mobile, withthe wallet data in the iOS Keychain, or encrypted under a key held in the
Android Keystore.
frames are processed on the device, and no image is stored or sent.
external communications, and so is the App Store / Google Play page that opens
for an update.
so rather than promising that everything is removed.
(
WHEN_UNLOCKED_THIS_DEVICE_ONLY, which is an iOS-only option). On Android theencrypted blob can be carried by a device backup —
android:allowBackupistrue— but the Keystore key never leaves the device, so a restored copy cannotbe decrypted elsewhere. The text says this rather than claiming both platforms
are excluded from backup.
Changes to the files
docs/terms/v2.1.htmldocs/privacy/v2.1.htmldocs/legal.jsonupcomingdropped; change lists rewritten as the diff from 1.0docs/terms.html,docs/privacy.htmldocs/index.htmlsrc/extension/legal.tsBUNDLED_LEGAL_DOCSraised to 2.1v1.0 and v2.0 are left where they are. They are linked from nowhere but stay
readable to anyone who knows the URL.
Effect on users
Every existing user of the extension meets the re-consent screen on their next
launch, and cannot reach the wallet until they respond. This is what a major
revision does.
tapylet-for-mobile needs no release:
mainlinks to the version-less URLs, so theredirect carries its users to v2.1. It does not record which version was agreed to,
so its existing testers are not asked again.
tapylet-for-web is unaffected. It neither reads this manifest nor links here — it
serves its own copies of the documents and holds them at 1.0 in
src/shared/legal.ts(see Notes).
How to verify
After deploying:
Then open the extension and confirm the re-consent screen lists the changes and
links to v2.1.
Related
Notes
reads (
docs/app/min-version.json) is already onmain, but the request itselfis made by tapylet-for-mobile's forced-upgrade feature, which is not yet merged.
That should land before the App Store build.
src/client/public/{terms,privacy}/v1.0.htmland does not read this manifest, soit stays on 1.0 until it is changed on its own. Whether it should be brought onto
these documents at all is open: it stores keys server-side behind a passkey, which
is a different arrangement from the extension and the mobile apps.
legal.jsoncarry English.