@@ -42,6 +42,10 @@ branch names, credentials, signing material, or other secrets.
4242- Compose interaction tests may run in ` app/src/test ` using Robolectric with a pinned SDK and
4343 plain test Application. Inject platform operations; do not load Go JNI or real Keystore in
4444 those tests. They run through the existing Fastlane Android checks without an emulator.
45+ - Exercise real screens and ConfigStore with a test-only Keystore provider. Before asserting
46+ service commands or their absence, drain ordered configuration writes and check both completion
47+ and failure state; ` pending == 0 ` alone does not prove success. Recorded service intents do not
48+ establish VPN lifecycle/JNI coverage. See ` docs/reviews/test-quality.md ` for coverage gaps.
4549- Keep device-only tests out of required GitHub CI unless the project later adopts a dependable
4650 device farm or controlled self-hosted runner. Do not reintroduce a software-emulated Android
4751 fallback.
@@ -79,6 +83,20 @@ branch names, credentials, signing material, or other secrets.
7983 transfer operations across configuration changes; never put credentials or export payloads into
8084 Android saved-state bundles, and reject a lost export before opening the output stream.
8185
86+ ## Privacy and documentation
87+
88+ - ` PRIVACY.md ` is the public privacy policy. Keep it consistent with actual app behavior and store
89+ metadata; put detailed diagnostic endpoint inventories and encryption implementation details in
90+ README instead of duplicating them in the policy.
91+ - Support emails, including sender addresses, messages and attachments, are retained until the
92+ reported problem is fixed, then deleted. This is the developer's operational practice, not an
93+ app-enforced retention timer. Uninstalling the app does not remove email or exported/shared copies.
94+ - Keep the privacy-policy link at the bottom of Settings, targeting the public policy on ` main ` ,
95+ with localized labels and an error message when no browser can open it.
96+ - Update current documentation while preserving historical changelogs. Review reports are dated
97+ snapshots, not proof of current coverage or external store compliance; see
98+ ` docs/reviews/privacy-policy.md ` for privacy follow-ups.
99+
82100## Architecture landmarks
83101
84102- ` ProxyVpnService ` extends Android's standard ` android.net.VpnService ` . It owns VPN lifecycle,
0 commit comments