docs: say what actually shipped, and what 1.0.0 actually is

The branch's documents describe a world where the vendored provider reached
users. It never did, and several claims follow from that mistake.

`ROADMAP.md`:
- Phase 5's "**Breaking:** the authority and both custom permissions no longer
  exist — anyone who pointed DAVx5 at that authority loses it, and the release
  notes have to say so" is wrong in the way that *removes* work: they were
  added and deleted inside this unreleased cycle, so nobody could have pointed
  anything at them. The release notes must not warn about losing something that
  never shipped. The per-locale release-notes item went with it.
- "Run the instrumented suite on a device … none has ever executed" was stale:
  52 tests, 0 failures, Pixel 10 / API 36, 13 Aug. What is genuinely open is a
  re-run against the tip, since the 4 Sep commits reworked the store and added
  instrumented cases that have never run. Both now say so, with the ARM64 aapt
  exit-code trap noted where someone will hit it.
- The device-verification item described upgrading from a v0.3.2 APK with
  seeded data, which cannot be the real path. Replaced with the four cases that
  matter, including the one that only exists on a device that side-loaded a dev
  build of this branch.
- M6's Glance item claimed "deps present in build.gradle.kts" — not any more.
  Translations and the language picker shipped in 0.4.0 and are marked done.

`OWN-STORE.md` gets a correction banner over "Migrating existing users" saying
the premise is wrong, and a section for the copy that replaces it.
`STORAGE-AND-SYNC.md`'s banner said the vendored-provider decision was "made,
shipped, and then costed properly" — built, not shipped.

`PRIVACY.md` had the opposite problem: it describes CalDAV sync, Nextcloud
Login Flow v2, RFC 6764 discovery and a Keystore-held password, none of which
exist in 1.0.0 — the app holds no `INTERNET` permission at all. The permissions
section listed six it does not declare. Since it is a legal document users are
sent to from Settings → About, section 4 is now marked as describing a planned
feature, section 9 lists exactly what the manifest declares (and says what is
*not* there), and the backup and crash-report sections no longer assume network
access or sync bookkeeping. Kept forward-looking rather than cut, so it does
not have to change underneath anyone when sync lands. **Worth a read before
merging** — it is the one change here with legal weight.

`fastlane/.../full_description.txt` still opened with "It works directly on an
existing tasks provider (OpenTasks / tasks.org) … no own account, no own sync"
as the app's premise. That is the F-Droid listing for a release whose headline
is that it needs nothing installed. Rewritten, with the feature list and the
no-internet-permission point that is now literally true.

`README.md` and `ExportWriter`'s "ships in eleven locales" (it is three) follow.
This commit is contained in:
2026-09-21 13:38:23 +02:00
parent b49a8af83d
commit 3150781376
7 changed files with 176 additions and 41 deletions
+36 -17
View File
@@ -1,7 +1,7 @@
---
title: Privacy Policy — Agendula
description: What Agendula does with your data. No servers, no account, no analytics — your tasks stay on your device unless you add a CalDAV server yourself.
updated: 2026-09-15
updated: 2026-09-21
---
<!--
@@ -21,7 +21,7 @@ updated: 2026-09-15
render on the published page.
-->
**Last updated:** 9 September 2026
**Last updated:** 21 September 2026
Applies to the Android app **Agendula** (package `de.jeanlucmakiola.agendula`),
all versions and all distribution channels.
@@ -32,6 +32,14 @@ your device. They leave it in exactly one case: if you set up a CalDAV account
yourself, they are synchronised with **the server you entered** — and with
nothing and no one else. Nothing is ever sent to the developer.
> **As of version 1.0.0, CalDAV sync is not in the app yet.** It is designed and
> described here so that this policy does not have to change underneath you when
> it arrives, but the released app has **no network access of its own at all** —
> it does not hold Android's `INTERNET` permission, so section 4 cannot happen on
> this version. Until it ships, your tasks leave the device only if *you* export
> them, or if a separate sync app you installed yourself syncs a task provider you
> pointed Agendula at (section 3).
## 1. Controller
IT-Dienstleister | Jean-Luc Makiola
@@ -64,6 +72,9 @@ All of this is verifiable in the
## 4. CalDAV sync — the only case where your tasks leave the device
*Not available in version 1.0.0 — see the note in "In short". This section
describes how it will behave, and is published in advance deliberately.*
Sync is optional and off until you add an account. If you add one, everything
below happens between your device and **the server you nominated**, and nowhere
else.
@@ -144,16 +155,21 @@ stored locally on your device and are removed when you uninstall the app.
If Android Auto Backup is enabled on your device, your tasks and settings may
be backed up to your own Google account, under Google's terms — the developer
has no access to it. Two things are deliberately excluded from that backup:
your stored CalDAV password, and Agendula's per-device sync bookkeeping. After
restoring onto a new device you therefore sign in to your server again.
has no access to it. What travels is Agendula's own task database and your
settings, and nothing else: the backup rules name those explicitly, which makes
everything not named — including the archived copy the app keeps of an older
version's database — excluded by default.
Once CalDAV sync ships, two further things will be kept out of that backup by
design: the stored password, and the per-device sync bookkeeping. Restoring onto
a new device will therefore mean signing in to your server again.
## 7. Crash reports
If Agendula crashes, it offers to report the problem. Nothing is sent
automatically, even though the app has network access. The report is copied to
your clipboard and your browser is opened with the project's issue tracker, the
text pre-filled. **You see the full content, you decide whether to submit it,
automatically — and on this version the app could not send it if it wanted to,
having no network permission. The report is copied to your clipboard and your
browser is opened with the project's issue tracker, the text pre-filled. **You see the full content, you decide whether to submit it,
and you can edit or discard it.**
Such a report contains:
@@ -183,11 +199,10 @@ process — it only opens the address.
## 9. Permissions and why they exist
- `INTERNET`, `ACCESS_NETWORK_STATE` — CalDAV sync with the server you
configure, and checking whether a connection exists before trying. Without a
CalDAV account, no connection is made.
- `READ_SYNC_SETTINGS`, `WRITE_SYNC_SETTINGS` — register the sync account with
Android's sync framework so it can be scheduled.
This is the complete list the released app declares — you can check it against
the app's entry in F-Droid, or against `app/src/main/AndroidManifest.xml` in the
source:
- `POST_NOTIFICATIONS` — show reminders.
- `USE_EXACT_ALARM`, `SCHEDULE_EXACT_ALARM` — deliver reminders at the exact
due time.
@@ -195,10 +210,14 @@ process — it only opens the address.
- `org.dmfs.permission.READ_TASKS` / `WRITE_TASKS` and
`org.tasks.permission.READ_TASKS` / `WRITE_TASKS` — optional, requested only
if you choose the external-provider storage mode, and only for the provider
you selected (OpenTasks or tasks.org).
- `WAKE_LOCK`, `FOREGROUND_SERVICE` — required by the Android system component
used for scheduled background work (WorkManager); on older Android versions
it needs them to run an expedited sync.
you selected (OpenTasks or tasks.org). All four are declared in the manifest
because a manifest is static, but none is requested until you pick that mode.
Note what is **not** there: Agendula declares no `INTERNET` permission, so the
released app cannot make a network connection of any kind. When CalDAV sync
ships it will need `INTERNET` and `ACCESS_NETWORK_STATE`, and the sync-framework
permissions to schedule itself; this section will be updated in the same release
that adds them, never before.
Agendula publishes no content provider of its own and declares no permissions
that other apps could request.