docs: refresh README for onboarding/app-password/rich-compose/opt-in features #48

Merged
JMR-dev merged 2 commits from docs-readme-refresh into main 2026-07-01 16:16:51 +00:00
JMR-dev commented 2026-07-01 05:38:53 +00:00 (Migrated from github.com)

Summary

Refreshes README.md to describe the app's post-batch shipped state. Closes #20 and folds in the README reconciliation from #31. Docs-only — no code, build files, or schemas touched.

Changes

  • Status blurb + feature list rewritten to reflect shipped state: first-run onboarding, rich-text compose (HTML editor + formatting toolbar, multipart/alternative, per-account signatures), full-history backfill with an optional device-only retention cap, opt-in biometric app lock, mailto:/default-mail-app, and opt-in local debug reporting.
  • Gmail is no longer an OAuth vendor. Removed the entire "Gmail account setup (OAuth client)" section and the "no stored passwords for Gmail" claim (Gmail OAuth path was removed in #40). Fixed the status/feature lines that called Gmail an OAuth vendor.
  • New "Accounts and onboarding" section documenting the three account types consistent with the onboarding flow: Outlook/Hotmail (OAuth 2.0 via Microsoft/AppAuth), Gmail/Yahoo/iCloud (preconfigured IMAP/SMTP with an app password, links to vendor app-password pages, Gmail 2-Step-Verification prerequisite), and Other (manual IMAP/SMTP).
  • Kept the Outlook / Microsoft OAuth setup section (still accurate). Internal anchor link to it verified.
  • New "Privacy and data flow" section: honest, opt-in framing for SQLCipher cache encryption + app-lock key binding, local user-initiated debug reporting (no hosted crash pipeline — server-side ingest from #11/#34/#35 is not shipped), and opt-in Android Backup that excludes the DB key/credentials/cache (references the optional Google Backup F-Droid anti-feature).
  • Light fix to the Architecture note (sync/auth layers are now shipped, not "later increments").

Reflects (not-yet-merged) feature PRs

This documents the state after PRs #40–#47. This doc PR should merge LAST, after #40–#47, so the README matches what actually shipped.

Notes

  • Still framed as "in development" — no overclaiming; the debug pipeline is described as local capture + user-initiated submit to a configurable/optional endpoint, not a live server.
  • Proofread: no remaining "Gmail OAuth"/"no stored passwords for Gmail" text; the #outlook--microsoft-account-setup-oauth-client anchor resolves; account-types match the onboarding flow. Unit tests / lint N/A for a README-only change.

🤖 Generated with Claude Code

## Summary Refreshes `README.md` to describe the app's **post-batch shipped state**. Closes #20 and folds in the README reconciliation from #31. Docs-only — no code, build files, or schemas touched. ## Changes - **Status blurb + feature list** rewritten to reflect shipped state: first-run onboarding, rich-text compose (HTML editor + formatting toolbar, `multipart/alternative`, per-account signatures), full-history backfill with an optional device-only retention cap, opt-in biometric app lock, `mailto:`/default-mail-app, and opt-in local debug reporting. - **Gmail is no longer an OAuth vendor.** Removed the entire "Gmail account setup (OAuth client)" section and the "no stored passwords for Gmail" claim (Gmail OAuth path was removed in #40). Fixed the status/feature lines that called Gmail an OAuth vendor. - **New "Accounts and onboarding" section** documenting the three account types consistent with the onboarding flow: Outlook/Hotmail (OAuth 2.0 via Microsoft/AppAuth), Gmail/Yahoo/iCloud (preconfigured IMAP/SMTP with an **app password**, links to vendor app-password pages, Gmail 2-Step-Verification prerequisite), and Other (manual IMAP/SMTP). - **Kept** the Outlook / Microsoft OAuth setup section (still accurate). Internal anchor link to it verified. - **New "Privacy and data flow" section**: honest, opt-in framing for SQLCipher cache encryption + app-lock key binding, **local** user-initiated debug reporting (no hosted crash pipeline — server-side ingest from #11/#34/#35 is **not** shipped), and opt-in Android Backup that excludes the DB key/credentials/cache (references the optional Google Backup F-Droid anti-feature). - Light fix to the Architecture note (sync/auth layers are now shipped, not "later increments"). ## Reflects (not-yet-merged) feature PRs This documents the state after PRs **#40–#47**. **This doc PR should merge LAST, after #40–#47**, so the README matches what actually shipped. ## Notes - Still framed as **"in development"** — no overclaiming; the debug pipeline is described as local capture + user-initiated submit to a configurable/optional endpoint, not a live server. - Proofread: no remaining "Gmail OAuth"/"no stored passwords for Gmail" text; the `#outlook--microsoft-account-setup-oauth-client` anchor resolves; account-types match the onboarding flow. Unit tests / lint N/A for a README-only change. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
Sign in to join this conversation.