Skip to content

docs: disclose Tencent COS direct upload in privacy policy - #2

Merged
veil-chow-fyaic merged 1 commit into
mainfrom
docs/privacy-cos-disclosure
Aug 20, 2026
Merged

docs: disclose Tencent COS direct upload in privacy policy#2
veil-chow-fyaic merged 1 commit into
mainfrom
docs/privacy-cos-disclosure

Conversation

@veil-chow-fyaic

Copy link
Copy Markdown
Contributor

Why

The 0.0.67 HOLD review (P1-8) found the public privacy policy did not disclose the Tencent COS direct-upload path, temporary credentials, or the server-proxy fallback. The corrective source (private paid main, PRIVACY-01 fix) already carries this disclosure; this PR syncs the public document.

Changes

  • New Direct cloud upload section in PRIVACY.md: recipient (Tencent Cloud COS, third-party processor), data class (explicitly referenced images/attachments + optional Pro theme style snapshot; note text never uses this path), credential lifetime (~30-minute single-object upload-only STS credential, never persisted by the plugin), retention/deletion, and the DocFerry server API-proxy fallback.
  • Publish Share table row and the README privacy pointer reference the direct-upload path.
  • The Tencent COS upload SDK is named in the local-storage section.
  • Hidden dotfile / traversal asset references are documented as excluded from publishing.

No code changes. Mirrors the wording of the reviewed private-repo privacy copy.

Note: GitHub reports 7 high-severity Dependabot alerts on the default branch — flagged for the release hardening track (not introduced by this PR).

…fallback

- Add a Direct cloud upload section: recipient (Tencent Cloud COS),
  data class (referenced attachments and optional Pro theme snapshot;
  never note text), ~30-minute single-object STS credential lifetime,
  in-memory-only use, retention/deletion, and the DocFerry server
  API-proxy fallback
- Publish Share table row and README privacy pointer reference the
  direct-upload path
- Document that hidden dotfile and traversal asset references are
  excluded from publishing
@veil-chow-fyaic
veil-chow-fyaic merged commit 44b3ea0 into main Aug 20, 2026
1 check passed
@veil-chow-fyaic
veil-chow-fyaic deleted the docs/privacy-cos-disclosure branch August 20, 2026 03:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant