[Privacy] PRIVACY.md summary says only data you explicitly send leaves the device #603

Closed
opened 2026-07-22 16:19:50 +00:00 by brenno · 0 comments
Owner

Found in the pre-publication privacy review.

Evidence: docs/PRIVACY.md:14-16 — "The only data that leaves your device is data you explicitly send — by importing from a URL, saving to your own Nextcloud/git server, or turning on the AI assistant."

One hundred and seventy lines further down, docs/PRIVACY.md:183 says the fetch-proxy "is used automatically, without a separate prompt". The table at :161-172 has ten rows, not three. The same file already corrected this once at :197-199, for the table — but not for the summary above it.

Why this matters now: the summary is the paragraph most readers actually read, and it is demonstrably wrong for the one path where the user gets no choice. A reader who finds the correction note at :197 concludes the error was left standing exactly where it counts most. That costs the whole document its credibility — and this document is the strongest selling point the product has.

Proposal: extend the third bullet: "…plus three you do not choose yourself: the CORS fallback on the web build, the CVE mirror if you switch it on, and a YouTube or Vimeo embed. The table below is complete."

Found in the pre-publication privacy review. **Evidence:** `docs/PRIVACY.md:14-16` — "**The only data that leaves your device is data you explicitly send** — by importing from a URL, saving to your own Nextcloud/git server, or turning on the AI assistant." One hundred and seventy lines further down, `docs/PRIVACY.md:183` says the fetch-proxy "is used automatically, **without a separate prompt**". The table at `:161-172` has ten rows, not three. The same file already corrected this once at `:197-199`, for the table — but not for the summary above it. **Why this matters now:** the summary is the paragraph most readers actually read, and it is demonstrably wrong for the one path where the user gets no choice. A reader who finds the correction note at `:197` concludes the error was left standing exactly where it counts most. That costs the whole document its credibility — and this document is the strongest selling point the product has. **Proposal:** extend the third bullet: "…plus three you do not choose yourself: the CORS fallback on the web build, the CVE mirror if you switch it on, and a YouTube or Vimeo embed. The table below is complete."
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
LibreKAT/Ocideck#603
No description provided.