Docs: clarify ntfy privacy — default server is public ntfy.sh
The docs claimed ntfy keeps push metadata on your own infrastructure, but the default NTFY_SERVER_URL is the public https://ntfy.sh cloud service. Make explicit that push metadata (topic, notification title) passes through ntfy.sh unless you self-host ntfy.
This commit is contained in:
1 parent
fb980d12b4
commit
b065d1783b
4 files changed
+32
-19
No files matched your search
@@ -7,9 +7,11 @@ Iris pairs with your running `hermes gateway` over a private, token-authenticate
|
|||||||
## Features
|
## Features
|
||||||
|
|
||||||
- **Native Hermes-Gateway integration** — your hermes → gateway → Iris app
|
- **Native Hermes-Gateway integration** — your hermes → gateway → Iris app
|
||||||
- **Absolute Privacy!** — everything stays on your own infrastructure
|
- **Absolute Privacy!** — chat stays on your own infrastructure
|
||||||
(push: ntfy by default; FCM is opt-in and routes push metadata via Google —
|
(push: ntfy by default, **but the default ntfy server is the public
|
||||||
see [Push notifications](#push-notifications))
|
`ntfy.sh`** — self-host ntfy to keep push metadata on your own machine;
|
||||||
|
FCM is opt-in and routes push metadata via Google — see
|
||||||
|
[Push notifications](#push-notifications))
|
||||||
- **100 MB file uploads by default** — configurable on the gateway via
|
- **100 MB file uploads by default** — configurable on the gateway via
|
||||||
`max_upload_bytes` (see [Media](docs/07-media.md) §7.7); all limits are set
|
`max_upload_bytes` (see [Media](docs/07-media.md) §7.7); all limits are set
|
||||||
on the gateway side (hermes), not in the app
|
on the gateway side (hermes), not in the app
|
||||||
@@ -48,9 +50,11 @@ hermes-agent ──> hermes gateway ──(HTTP :8791)──> Iris app (Android
|
|||||||
Push wakes a backgrounded/offline device; on reconnect the app syncs the
|
Push wakes a backgrounded/offline device; on reconnect the app syncs the
|
||||||
outbox, so nothing is lost.
|
outbox, so nothing is lost.
|
||||||
|
|
||||||
- **ntfy (default)** — push metadata stays on your own infrastructure
|
- **ntfy (default)** — the backend for truly private communication.
|
||||||
(self-hosted ntfy recommended). This is the backend for truly private
|
⚠️ **By default it uses the public `https://ntfy.sh` cloud service** — push
|
||||||
communication.
|
metadata (topic, notification title) passes through ntfy.sh's servers.
|
||||||
|
Set `NTFY_SERVER_URL` to a **self-hosted ntfy** to keep push metadata on
|
||||||
|
your own infrastructure (recommended; public ntfy.sh SSE is also flaky).
|
||||||
- **FCM (opt-in, `IRIS_PUSH_BACKEND=fcm`)** — standard/reliable, but FCM push
|
- **FCM (opt-in, `IRIS_PUSH_BACKEND=fcm`)** — standard/reliable, but FCM push
|
||||||
metadata (notification title, device token) is routed through **Google's
|
metadata (notification title, device token) is routed through **Google's
|
||||||
servers**. If you want truly private communication, use ntfy instead.
|
servers**. If you want truly private communication, use ntfy instead.
|
||||||
|
|||||||
+5
-2
@@ -3,8 +3,11 @@
|
|||||||
The gateway can't reach a sleeping phone directly. Push goes through a cloud
|
The gateway can't reach a sleeping phone directly. Push goes through a cloud
|
||||||
relay. **Decision: ntfy default, FCM optional** (`IRIS_PUSH_BACKEND`).
|
relay. **Decision: ntfy default, FCM optional** (`IRIS_PUSH_BACKEND`).
|
||||||
Privacy: FCM push metadata (notification title, device token) is routed
|
Privacy: FCM push metadata (notification title, device token) is routed
|
||||||
through Google's servers — for truly private communication use ntfy
|
through Google's servers. ntfy is the private option — **but note the default
|
||||||
(self-hosted), which keeps everything on your own infrastructure.
|
`NTFY_SERVER_URL` is the public `https://ntfy.sh` cloud service**, so push
|
||||||
|
metadata passes through ntfy.sh's servers unless you self-host ntfy (set
|
||||||
|
`NTFY_SERVER_URL`); only a self-hosted ntfy keeps everything on your own
|
||||||
|
infrastructure.
|
||||||
|
|
||||||
## 8.1 When push fires
|
## 8.1 When push fires
|
||||||
|
|
||||||
|
|||||||
+6
-3
@@ -201,9 +201,12 @@ app is closed. Nothing is lost either way — on reconnect the app syncs its
|
|||||||
outbox.
|
outbox.
|
||||||
|
|
||||||
- **ntfy (default)** — the phone generates its own topic automatically; the
|
- **ntfy (default)** — the phone generates its own topic automatically; the
|
||||||
gateway publishes to it. Set `NTFY_SERVER_URL` to a **self-hosted ntfy**
|
gateway publishes to it. ⚠️ **The default server is the public
|
||||||
for reliability (the public `ntfy.sh` SSE endpoint is flaky). Push metadata
|
`https://ntfy.sh` cloud service** — push metadata (topic, notification
|
||||||
stays on your own infrastructure — this is the private option.
|
title) passes through ntfy.sh's servers. Set `NTFY_SERVER_URL` to a
|
||||||
|
**self-hosted ntfy** to keep push metadata on your own infrastructure —
|
||||||
|
that is the private option (and also more reliable: the public `ntfy.sh`
|
||||||
|
SSE endpoint is flaky).
|
||||||
- **FCM (opt-in, `IRIS_PUSH_BACKEND=fcm`)** — standard and reliable, but push
|
- **FCM (opt-in, `IRIS_PUSH_BACKEND=fcm`)** — standard and reliable, but push
|
||||||
metadata (notification title, device token) is routed through **Google's
|
metadata (notification title, device token) is routed through **Google's
|
||||||
servers**. Needs a Firebase project + `google-services.json` in the app
|
servers**. Needs a Firebase project + `google-services.json` in the app
|
||||||
|
|||||||
@@ -16,8 +16,9 @@ threads, media, search — Telegram-quality, on your own infrastructure.
|
|||||||
**Absolute Privacy!** — everything stays on your own infrastructure:
|
**Absolute Privacy!** — everything stays on your own infrastructure:
|
||||||
|
|
||||||
- Your gateway, your machine, your data. No cloud middleman for chat.
|
- Your gateway, your machine, your data. No cloud middleman for chat.
|
||||||
- **Push notifications:** ntfy by default — push metadata stays on your own
|
- **Push notifications:** ntfy by default. Note: out of the box it uses the
|
||||||
(self-hosted) ntfy server.
|
public ntfy.sh service; self-host ntfy (one env var) to keep push metadata
|
||||||
|
on your own server.
|
||||||
- **FCM is opt-in** (`IRIS_PUSH_BACKEND=fcm`): standard and reliable, but FCM
|
- **FCM is opt-in** (`IRIS_PUSH_BACKEND=fcm`): standard and reliable, but FCM
|
||||||
push metadata (notification title, device token) is routed through
|
push metadata (notification title, device token) is routed through
|
||||||
**Google's servers**. If you want truly private communication, use ntfy
|
**Google's servers**. If you want truly private communication, use ntfy
|
||||||
@@ -32,10 +33,12 @@ Runs on Android and desktop (Linux, macOS, Windows) from one shared codebase.
|
|||||||
## Privacy note (for the "Data safety" section / FAQ)
|
## Privacy note (for the "Data safety" section / FAQ)
|
||||||
|
|
||||||
Iris talks directly to your own hermes gateway over a private, token-authenticated
|
Iris talks directly to your own hermes gateway over a private, token-authenticated
|
||||||
connection. By default, push notifications use ntfy, which you can self-host so
|
connection. By default, push notifications use ntfy — out of the box via the
|
||||||
that push metadata never leaves your infrastructure. If you explicitly enable
|
public ntfy.sh service (push metadata such as the topic and notification title
|
||||||
FCM, push metadata (notification title, device token) is sent via Google's FCM
|
passes through ntfy.sh's servers); self-host ntfy (one env var) so that push
|
||||||
servers; chat content itself is not sent to Google — FCM only carries a short
|
metadata never leaves your infrastructure. If you explicitly enable FCM, push
|
||||||
preview, and full content is fetched from your gateway over the authenticated
|
metadata (notification title, device token) is sent via Google's FCM servers;
|
||||||
|
chat content itself is not sent to Google — FCM only carries a short preview,
|
||||||
|
and full content is fetched from your gateway over the authenticated
|
||||||
connection. For truly private communication, use the default ntfy backend
|
connection. For truly private communication, use the default ntfy backend
|
||||||
(self-hosted).
|
with a self-hosted ntfy server.
|
||||||
Reference in new issue
Block a user