diff --git a/README.md b/README.md index 21e1200..a9babc5 100644 --- a/README.md +++ b/README.md @@ -7,9 +7,11 @@ Iris pairs with your running `hermes gateway` over a private, token-authenticate ## Features - **Native Hermes-Gateway integration** — your hermes → gateway → Iris app -- **Absolute Privacy!** — everything stays on your own infrastructure - (push: ntfy by default; FCM is opt-in and routes push metadata via Google — - see [Push notifications](#push-notifications)) +- **Absolute Privacy!** — chat stays on your own infrastructure + (push: ntfy by default, **but the default ntfy server is the public + `ntfy.sh`** — self-host ntfy to keep push metadata on your own machine; + FCM is opt-in and routes push metadata via Google — see + [Push notifications](#push-notifications)) - **100 MB file uploads by default** — configurable on the gateway via `max_upload_bytes` (see [Media](docs/07-media.md) §7.7); all limits are set on the gateway side (hermes), not in the app @@ -48,9 +50,11 @@ hermes-agent ──> hermes gateway ──(HTTP :8791)──> Iris app (Android Push wakes a backgrounded/offline device; on reconnect the app syncs the outbox, so nothing is lost. -- **ntfy (default)** — push metadata stays on your own infrastructure - (self-hosted ntfy recommended). This is the backend for truly private - communication. +- **ntfy (default)** — the backend for truly private communication. + ⚠️ **By default it uses the public `https://ntfy.sh` cloud service** — push + metadata (topic, notification title) passes through ntfy.sh's servers. + Set `NTFY_SERVER_URL` to a **self-hosted ntfy** to keep push metadata on + your own infrastructure (recommended; public ntfy.sh SSE is also flaky). - **FCM (opt-in, `IRIS_PUSH_BACKEND=fcm`)** — standard/reliable, but FCM push metadata (notification title, device token) is routed through **Google's servers**. If you want truly private communication, use ntfy instead. diff --git a/docs/08-push.md b/docs/08-push.md index c4e9969..5a8e7cb 100644 --- a/docs/08-push.md +++ b/docs/08-push.md @@ -3,8 +3,11 @@ The gateway can't reach a sleeping phone directly. Push goes through a cloud relay. **Decision: ntfy default, FCM optional** (`IRIS_PUSH_BACKEND`). Privacy: FCM push metadata (notification title, device token) is routed -through Google's servers — for truly private communication use ntfy -(self-hosted), which keeps everything on your own infrastructure. +through Google's servers. ntfy is the private option — **but note the default +`NTFY_SERVER_URL` is the public `https://ntfy.sh` cloud service**, so push +metadata passes through ntfy.sh's servers unless you self-host ntfy (set +`NTFY_SERVER_URL`); only a self-hosted ntfy keeps everything on your own +infrastructure. ## 8.1 When push fires diff --git a/docs/install.md b/docs/install.md index 51b409c..2eba00f 100644 --- a/docs/install.md +++ b/docs/install.md @@ -201,9 +201,12 @@ app is closed. Nothing is lost either way — on reconnect the app syncs its outbox. - **ntfy (default)** — the phone generates its own topic automatically; the - gateway publishes to it. Set `NTFY_SERVER_URL` to a **self-hosted ntfy** - for reliability (the public `ntfy.sh` SSE endpoint is flaky). Push metadata - stays on your own infrastructure — this is the private option. + gateway publishes to it. ⚠️ **The default server is the public + `https://ntfy.sh` cloud service** — push metadata (topic, notification + title) passes through ntfy.sh's servers. Set `NTFY_SERVER_URL` to a + **self-hosted ntfy** to keep push metadata on your own infrastructure — + that is the private option (and also more reliable: the public `ntfy.sh` + SSE endpoint is flaky). - **FCM (opt-in, `IRIS_PUSH_BACKEND=fcm`)** — standard and reliable, but push metadata (notification title, device token) is routed through **Google's servers**. Needs a Firebase project + `google-services.json` in the app diff --git a/docs/playstore-listing.md b/docs/playstore-listing.md index 430eee0..1902768 100644 --- a/docs/playstore-listing.md +++ b/docs/playstore-listing.md @@ -16,8 +16,9 @@ threads, media, search — Telegram-quality, on your own infrastructure. **Absolute Privacy!** — everything stays on your own infrastructure: - Your gateway, your machine, your data. No cloud middleman for chat. -- **Push notifications:** ntfy by default — push metadata stays on your own - (self-hosted) ntfy server. +- **Push notifications:** ntfy by default. Note: out of the box it uses the + public ntfy.sh service; self-host ntfy (one env var) to keep push metadata + on your own server. - **FCM is opt-in** (`IRIS_PUSH_BACKEND=fcm`): standard and reliable, but FCM push metadata (notification title, device token) is routed through **Google's servers**. If you want truly private communication, use ntfy @@ -32,10 +33,12 @@ Runs on Android and desktop (Linux, macOS, Windows) from one shared codebase. ## Privacy note (for the "Data safety" section / FAQ) Iris talks directly to your own hermes gateway over a private, token-authenticated -connection. By default, push notifications use ntfy, which you can self-host so -that push metadata never leaves your infrastructure. If you explicitly enable -FCM, push metadata (notification title, device token) is sent via Google's FCM -servers; chat content itself is not sent to Google — FCM only carries a short -preview, and full content is fetched from your gateway over the authenticated +connection. By default, push notifications use ntfy — out of the box via the +public ntfy.sh service (push metadata such as the topic and notification title +passes through ntfy.sh's servers); self-host ntfy (one env var) so that push +metadata never leaves your infrastructure. If you explicitly enable FCM, push +metadata (notification title, device token) is sent via Google's FCM servers; +chat content itself is not sent to Google — FCM only carries a short preview, +and full content is fetched from your gateway over the authenticated connection. For truly private communication, use the default ntfy backend -(self-hosted). +with a self-hosted ntfy server.