Bring README in line with the post-batch shipped state (issue #20, folding in
#31's README reconciliation):
- Rewrite the status blurb and feature list to cover the onboarding flow, rich
compose (HTML + multipart/alternative + signatures), full-history backfill
with a device-only retention cap, opt-in app lock, mailto/default-app, and
opt-in local debug reporting.
- Remove the Gmail OAuth setup section and the "no stored passwords for Gmail"
claim; Gmail/Yahoo/iCloud are now app-password IMAP/SMTP vendors.
- Add an "Accounts and onboarding" section (Outlook OAuth; Gmail/Yahoo/iCloud
app password with vendor app-password pages + Gmail 2SV note; Other IMAP/SMTP)
and keep the Outlook OAuth setup section.
- Add a "Privacy and data flow" note: opt-in cache encryption, local
user-initiated debug reporting (no hosted pipeline), and opt-in Android Backup.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>