You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Align privacy, notices and release gate; keep downloads out of backups
- PRIVACY.md describes the Japanese dictionary download, the temporary
pronunciation recording and the backup exclusions, and no longer
describes the removed clip downloader.
- THIRD_PARTY_NOTICES.md lists Kuromoji and reproduces the
mecab-ipadic notice.
- Backup and device-transfer rules leave out the downloaded Japanese
dictionary and the F-Droid translation models, which could push a
backup past Android's 25 MB quota.
- The release gate requires all four Android CI jobs by name, and a
test keeps the list equal to the workflow's jobs.
- The PR #87 spec records its phone test and the v1.3.1 release.
Spec: docs/specs/2026-09-30-docs-backup-ci-alignment.md
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CKhgrZwwyTSRbNNCiRGy6s
Copy file name to clipboardExpand all lines: AGENTS.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -30,12 +30,12 @@ Android app (`:app`, package `com.kienhoang.dualsubreplay`) with a separate test
30
30
- Follow explicit owner release intent; otherwise preserve **patch**, including docs/workflow PRs. Recommend alternatives if useful, but do not silently infer minor/major/skip. A docs-only PR uses skip when the owner requests it.
31
31
- Apply and verify the actual GitHub label or standalone exact-version PR-body directive. Prose/specs/checkboxes do not apply labels. Keep at most one release label OR one directive; remove superseded overrides without disturbing unrelated labels. If required metadata cannot be applied, report the missing action and do not call the PR ready to merge.
32
32
- State intent, reason, and expected version (or why skipped/unavailable). Inspect stable tags, releases including draft reservations, and the Gradle baseline before estimating. Bump-derived numbers are estimates until reserved; exact versions must exceed all existing/reserved stable versions. Do not manually change Gradle versions or create release tags in normal PRs.
33
-
- Before calling a PR ready to merge, verify its latest final-head Android CI run: both `verify-build` and `managed-device-tests` must succeed. New commits need fresh checks; report pending/failed/skipped/unavailable checks explicitly.
33
+
- Before calling a PR ready to merge, verify its latest final-head Android CI run: all four jobs (`verify-build`, `managed-device-tests`, `fdroid-build`, `fdroid-device-tests`) must succeed. New commits need fresh checks; report pending/failed/skipped/unavailable checks explicitly.
34
34
- Handoff: owner reviews the preview and green checks, then manually merges; existing automation publishes unless skipped. Green PR CI is not proof of release publication. Verify the release workflow/assets if asked to confirm publication; use existing reservation/retry recovery below.
35
35
36
36
## Releases happen automatically after an approved PR merge
37
37
38
-
- When `hoangkien1703` merges a PR into `main`, `release-on-main.yml` checks the latest Android CI run for the PR's final head and requires both `verify-build` and `managed-device-tests` to succeed. Direct pushes and other mergers do not release.
38
+
- When `hoangkien1703` merges a PR into `main`, `release-on-main.yml` checks the latest Android CI run for the PR's final head and requires all four Android CI jobs (`verify-build`, `managed-device-tests`, `fdroid-build`, `fdroid-device-tests`) to succeed. Direct pushes and other mergers do not release.
39
39
- Default: bump the highest existing/reserved stable patch version and monotonically increase Android `versionCode`. **Do not manually bump Gradle version constants in feature PRs.**
40
40
- Before merge, apply at most one GitHub label (`release:patch`, `release:minor`, `release:major`, `release:skip`) OR a standalone `Release-Version: X.Y.Z` in the PR description. Conflicting instructions fail closed. `release:skip` keeps the rolling preview only.
41
41
- Release versions live in a release-only commit/tag based on the exact merge; only the two Gradle version constants change. `main` keeps development defaults. No bot commits to `main` or branch-protection bypass is needed.
Copy file name to clipboardExpand all lines: PRIVACY.md
+5-3Lines changed: 5 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -8,18 +8,20 @@ DualSub Replay is designed without an application account, analytics SDK, advert
8
8
- The app requests public caption data from YouTube to build the replayable subtitle timeline.
9
9
- Google ML Kit may download the language models you select. Translation then runs on the device.
10
10
- The F-Droid build does not include ML Kit. It downloads Mozilla's Firefox Translations models from Mozilla's servers the first time you translate a language, then translates on the device. Only model files are downloaded; subtitle text is not sent.
11
+
- The first time Japanese subtitles load, the app downloads the Japanese word dictionary (the unchanged 13 MB Kuromoji IPADIC file) from Maven Central (`repo1.maven.org`) or, if that fails, Google's mirror of it (`maven-central.storage-download.googleapis.com`). The request asks only for that file; no subtitle text is sent. The file is checked against a pinned SHA-256 checksum, kept in the app's private storage, and used to split Japanese text into words on the device.
11
12
- The app stores the last Browse URL, target language, subtitle text size, and landscape split ratio in local Android preferences.
12
13
- Saved words, meanings, subtitle context, video IDs, timestamp ranges, and review schedules are stored in a local SQLite database. They are not sent to an application server. Android's normal app backup may include this database and preferences.
13
14
- Progress stores, per day and language, how long videos played in the app and how many videos were watched, in a separate local SQLite database, plus your daily goal in local preferences. Video IDs and titles are not stored for Progress, and nothing is sent to an application server. Android's normal app backup may include this database.
14
-
- Optional offline clip downloads send video requests to YouTube and its media hosts using the bundled yt-dlp downloader. Downloads do not copy cookies from the browsing WebView. Clip files are stored privately and excluded from Android backups. Restored cards may require their clips to be downloaded again.
15
-
- Pronunciation sends the selected word and language to the device's preferred Android text-to-speech engine and, if needed, other installed speech engines. It prefers installed offline voices but may try a supported online voice when local speech fails or is unavailable. Online voices process the word according to the speech engine provider's settings and privacy policy.
15
+
- Saved words replay their moment in the same embedded YouTube page. The app no longer downloads video clips; the offline clip downloader of earlier versions has been removed.
16
+
- Pronunciation sends the selected word and language to the device's preferred Android text-to-speech engine and, if needed, other installed speech engines. It prefers installed offline voices but may try a supported online voice when local speech fails or is unavailable. Online voices process the word according to the speech engine provider's settings and privacy policy. The spoken word is recorded to a temporary file in the app's cache so it can replay instantly. It is deleted when you select or pronounce another word or close the app, and any file left behind is removed the next time a word is spoken.
17
+
- The Japanese dictionary and the F-Droid build's translation models are excluded from Android backups and device transfers, because they can be downloaded again. Saved words, Progress, and preferences stay in backups.
16
18
- If you use the experimental Google/YouTube sign-in flow, authentication occurs inside YouTube's embedded web experience and WebView cookies persist locally. Google may reject embedded-WebView sign-in.
17
19
18
20
## What the project does not do
19
21
20
22
- It does not require an API key or DualSub Replay account.
21
23
- It does not send subtitle text or translation requests to a server operated by this project.
22
-
- It does not download media automatically during browsing; users explicitly request offline vocabulary clips.
24
+
- It does not download video or audio from YouTube.
23
25
- It does not intentionally collect analytics, advertising identifiers, or crash telemetry.
24
26
25
27
Deleting the app clears its local app data under Android's normal uninstall behavior. You can also clear the app's storage from Android Settings.
Copy file name to clipboardExpand all lines: README.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -181,7 +181,7 @@ Pull requests use the committed wrapper to run formatting and complexity checks,
181
181
182
182
### Automatic official releases
183
183
184
-
When **hoangkien1703 merges a PR into `main`**, the **Release merged PR** workflow checks that the latest Android CI run for the PR's final commit succeeded, including both `verify-build`and `managed-device-tests`. It then builds the preview and a production-signed official APK. Direct pushes and merges by other accounts do not publish releases.
184
+
When **hoangkien1703 merges a PR into `main`**, the **Release merged PR** workflow checks that the latest Android CI run for the PR's final commit succeeded, including all four jobs: `verify-build`, `managed-device-tests`, `fdroid-build`and `fdroid-device-tests`. It then builds the preview and a production-signed official APK. Direct pushes and merges by other accounts do not publish releases.
185
185
186
186
By default, each eligible merge increments the highest existing or reserved stable patch version: `1.0.4 → 1.0.5` (and `1.0.9 → 1.0.10`). It also increments Android's internal `versionCode` above all prior stable releases and reservations. Preview tags do not affect official version selection. **Do not manually bump the Gradle constants in feature PRs.**
Copy file name to clipboardExpand all lines: THIRD_PARTY_NOTICES.md
+70Lines changed: 70 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -19,6 +19,7 @@ Current releases bundle only:
19
19
- Google ML Kit Translate: Google APIs Terms of Service / Apache-2.0.
20
20
- Square OkHttp: Apache-2.0.
21
21
- Kotlin / Coroutines: Apache-2.0.
22
+
- Kuromoji 0.9.0 (`com.atilika.kuromoji:kuromoji-ipadic`, code only): Apache-2.0, copyright 2010-2015 Atilika Inc. and contributors. Its license and notice files are kept in the APK under `META-INF/`.
22
23
23
24
The F-Droid build (`-Pdistribution=fdroid`) leaves out Google ML Kit Translate and contains only free software. Instead it bundles a native translation engine built from the git submodules in `app/src/fdroid/cpp`:
24
25
- Bergamot translator and Marian (mozilla/translations `inference/`): MPL-2.0 and MIT.
@@ -27,6 +28,75 @@ The F-Droid build (`-Pdistribution=fdroid`) leaves out Google ML Kit Translate a
27
28
28
29
It downloads Mozilla's Firefox Translations models, which are distributed under MPL-2.0.
29
30
31
+
## Japanese dictionary (downloaded on first use)
32
+
33
+
The IPADIC dictionary that Kuromoji uses is not bundled in the APK. The first time Japanese subtitles load, the app downloads the same `kuromoji-ipadic-0.9.0.jar` from Maven Central, checks its size and SHA-256, and stores it in the app's private storage (see [PRIVACY.md](PRIVACY.md)). The jar contains data from `mecab-ipadic-2.7.0-20070801` ([source archive](http://atilika.com/releases/mecab-ipadic/mecab-ipadic-2.7.0-20070801.tar.gz)), distributed under this notice:
34
+
35
+
Nara Institute of Science and Technology (NAIST),
36
+
the copyright holders, disclaims all warranties with regard to this
37
+
software, including all implied warranties of merchantability and
38
+
fitness, in no event shall NAIST be liable for
39
+
any special, indirect or consequential damages or any damages
40
+
whatsoever resulting from loss of use, data or profits, whether in an
41
+
action of contract, negligence or other tortuous action, arising out
42
+
of or in connection with the use or performance of this software.
43
+
44
+
A large portion of the dictionary entries
45
+
originate from ICOT Free Software. The following conditions for ICOT
46
+
Free Software applies to the current dictionary as well.
47
+
48
+
Each User may also freely distribute the Program, whether in its
49
+
original form or modified, to any third party or parties, PROVIDED
50
+
that the provisions of Section 3 ("NO WARRANTY") will ALWAYS appear
51
+
on, or be attached to, the Program, which is distributed substantially
52
+
in the same form as set out herein and that such intended
53
+
distribution, if actually made, will neither violate or otherwise
54
+
contravene any of the laws and regulations of the countries having
55
+
jurisdiction over the User or the intended distribution itself.
56
+
57
+
NO WARRANTY
58
+
59
+
The program was produced on an experimental basis in the course of the
60
+
research and development conducted during the project and is provided
61
+
to users as so produced on an experimental basis. Accordingly, the
62
+
program is provided without any warranty whatsoever, whether express,
63
+
implied, statutory or otherwise. The term "warranty" used herein
64
+
includes, but is not limited to, any warranty of the quality,
65
+
performance, merchantability and fitness for a particular purpose of
66
+
the program and the nonexistence of any infringement or violation of
67
+
any right of any third party.
68
+
69
+
Each user of the program will agree and understand, and be deemed to
70
+
have agreed and understood, that there is no warranty whatsoever for
71
+
the program and, accordingly, the entire risk arising from or
72
+
otherwise connected with the program is assumed by the user.
73
+
74
+
Therefore, neither ICOT, the copyright holder, or any other
75
+
organization that participated in or was otherwise related to the
76
+
development of the program and their respective officials, directors,
77
+
officers and other employees shall be held liable for any and all
78
+
damages, including, without limitation, general, special, incidental
79
+
and consequential damages, arising out of or otherwise in connection
80
+
with the use or inability to use the program or any product, material
81
+
or result produced or otherwise obtained by using the program,
82
+
regardless of whether they have been advised of, or otherwise had
83
+
knowledge of, the possibility of such damages at any time during the
84
+
project or thereafter. Each user will be deemed to have agreed to the
85
+
foregoing by his or her commencement of use of the program. The term
86
+
"use" as used herein includes, but is not limited to, the use,
87
+
modification, copying and distribution of the program and the
88
+
production of secondary products from the program.
89
+
90
+
In the case where the program, whether in its original form or
91
+
modified, was distributed or delivered to or received by a user from
92
+
any person, organization or entity other than ICOT, unless it makes or
93
+
grants independently of ICOT any specific warranty to the user in
94
+
writing, such person, organization or entity, will also be exempted
95
+
from and not be held liable to the user for any such damages as noted
96
+
above as far as the program is concerned.
97
+
98
+
The F-Droid build downloads the same dictionary.
99
+
30
100
## Obtain and build this application's source
31
101
32
102
The complete application source and build scripts are available without charge at https://github.com/hoangkien1703/dual-sub-replay. For a PR preview, select the PR's exact commit; for a tagged release, select that tag. GitHub provides downloadable source archives for both commits and tags. Keep these source links beside redistributed APKs and retain upstream notices and access to the corresponding dependency sources.
0 commit comments