Part of #11.
## Context
Server side of bug reporting. Lives in **separate infrastructure** (not the Android app
repo). Receives reports from #33.
## Scope
- [ ] Cloudflare Worker HTTPS endpoint accepting a report payload, with size/rate limiting
and basic abuse protection.
- [ ] Best-effort PII anonymization/redaction pass (email addresses, tokens, names, IPs)
before storage.
- [ ] Store each report in a Cloudflare R2 bucket **encrypted at rest**; document the
encryption scheme and key custody.
- [ ] Lifecycle so unreviewed reports are picked up by the weekly job (#35).
- [ ] Document the data flow + privacy posture (referenced by F-Droid #16 and the README #20).
## Acceptance criteria
- A POST from the app is accepted, scrubbed, and stored encrypted in R2.
- Stored objects are not readable without the documented key.
## Open questions
- Encryption scheme (Worker-side envelope encryption vs. R2 SSE) and who holds the keys.
- Where the Worker source lives; secrets stored in Cloudflare, never in the app.
## Dependencies
Consumes #33; feeds #35.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Part of #11.
Context
Server side of bug reporting. Lives in separate infrastructure (not the Android app
repo). Receives reports from #33.
Scope
and basic abuse protection.
before storage.
encryption scheme and key custody.
Acceptance criteria
Open questions
Dependencies
Consumes #33; feeds #35.