Docs: clarify ntfy privacy — default server is public ntfy.sh
CI / Gateway plugin tests (push) Successful in 8m58s
CI / Kotlin tests (android host + desktop) (push) Failing after 13m32s

The docs claimed ntfy keeps push metadata on your own infrastructure,
but the default NTFY_SERVER_URL is the public https://ntfy.sh cloud
service. Make explicit that push metadata (topic, notification title)
passes through ntfy.sh unless you self-host ntfy.
This commit is contained in:
ARIA committed 2026-08-27 09:23:44 +02:00
1 parent fb980d12b4
commit b065d1783b
4 files changed
+32 -19

No files matched your search

+10 -6
View File
@@ -7,9 +7,11 @@ Iris pairs with your running `hermes gateway` over a private, token-authenticate
## Features ## Features
- **Native Hermes-Gateway integration** — your hermes → gateway → Iris app - **Native Hermes-Gateway integration** — your hermes → gateway → Iris app
- **Absolute Privacy!** — everything stays on your own infrastructure - **Absolute Privacy!** — chat stays on your own infrastructure
(push: ntfy by default; FCM is opt-in and routes push metadata via Google — (push: ntfy by default, **but the default ntfy server is the public
see [Push notifications](#push-notifications)) `ntfy.sh`** — self-host ntfy to keep push metadata on your own machine;
FCM is opt-in and routes push metadata via Google — see
[Push notifications](#push-notifications))
- **100 MB file uploads by default** — configurable on the gateway via - **100 MB file uploads by default** — configurable on the gateway via
`max_upload_bytes` (see [Media](docs/07-media.md) §7.7); all limits are set `max_upload_bytes` (see [Media](docs/07-media.md) §7.7); all limits are set
on the gateway side (hermes), not in the app on the gateway side (hermes), not in the app
@@ -48,9 +50,11 @@ hermes-agent ──> hermes gateway ──(HTTP :8791)──> Iris app (Android
Push wakes a backgrounded/offline device; on reconnect the app syncs the Push wakes a backgrounded/offline device; on reconnect the app syncs the
outbox, so nothing is lost. outbox, so nothing is lost.
- **ntfy (default)** — push metadata stays on your own infrastructure - **ntfy (default)** — the backend for truly private communication.
(self-hosted ntfy recommended). This is the backend for truly private ⚠️ **By default it uses the public `https://ntfy.sh` cloud service** — push
communication. metadata (topic, notification title) passes through ntfy.sh's servers.
Set `NTFY_SERVER_URL` to a **self-hosted ntfy** to keep push metadata on
your own infrastructure (recommended; public ntfy.sh SSE is also flaky).
- **FCM (opt-in, `IRIS_PUSH_BACKEND=fcm`)** — standard/reliable, but FCM push - **FCM (opt-in, `IRIS_PUSH_BACKEND=fcm`)** — standard/reliable, but FCM push
metadata (notification title, device token) is routed through **Google's metadata (notification title, device token) is routed through **Google's
servers**. If you want truly private communication, use ntfy instead. servers**. If you want truly private communication, use ntfy instead.
+5 -2
View File
@@ -3,8 +3,11 @@
The gateway can't reach a sleeping phone directly. Push goes through a cloud The gateway can't reach a sleeping phone directly. Push goes through a cloud
relay. **Decision: ntfy default, FCM optional** (`IRIS_PUSH_BACKEND`). relay. **Decision: ntfy default, FCM optional** (`IRIS_PUSH_BACKEND`).
Privacy: FCM push metadata (notification title, device token) is routed Privacy: FCM push metadata (notification title, device token) is routed
through Google's servers — for truly private communication use ntfy through Google's servers. ntfy is the private option — **but note the default
(self-hosted), which keeps everything on your own infrastructure. `NTFY_SERVER_URL` is the public `https://ntfy.sh` cloud service**, so push
metadata passes through ntfy.sh's servers unless you self-host ntfy (set
`NTFY_SERVER_URL`); only a self-hosted ntfy keeps everything on your own
infrastructure.
## 8.1 When push fires ## 8.1 When push fires
+6 -3
View File
@@ -201,9 +201,12 @@ app is closed. Nothing is lost either way — on reconnect the app syncs its
outbox. outbox.
- **ntfy (default)** — the phone generates its own topic automatically; the - **ntfy (default)** — the phone generates its own topic automatically; the
gateway publishes to it. Set `NTFY_SERVER_URL` to a **self-hosted ntfy** gateway publishes to it. ⚠️ **The default server is the public
for reliability (the public `ntfy.sh` SSE endpoint is flaky). Push metadata `https://ntfy.sh` cloud service** — push metadata (topic, notification
stays on your own infrastructure — this is the private option. title) passes through ntfy.sh's servers. Set `NTFY_SERVER_URL` to a
**self-hosted ntfy** to keep push metadata on your own infrastructure —
that is the private option (and also more reliable: the public `ntfy.sh`
SSE endpoint is flaky).
- **FCM (opt-in, `IRIS_PUSH_BACKEND=fcm`)** — standard and reliable, but push - **FCM (opt-in, `IRIS_PUSH_BACKEND=fcm`)** — standard and reliable, but push
metadata (notification title, device token) is routed through **Google's metadata (notification title, device token) is routed through **Google's
servers**. Needs a Firebase project + `google-services.json` in the app servers**. Needs a Firebase project + `google-services.json` in the app
+11 -8
View File
@@ -16,8 +16,9 @@ threads, media, search — Telegram-quality, on your own infrastructure.
**Absolute Privacy!** — everything stays on your own infrastructure: **Absolute Privacy!** — everything stays on your own infrastructure:
- Your gateway, your machine, your data. No cloud middleman for chat. - Your gateway, your machine, your data. No cloud middleman for chat.
- **Push notifications:** ntfy by default — push metadata stays on your own - **Push notifications:** ntfy by default. Note: out of the box it uses the
(self-hosted) ntfy server. public ntfy.sh service; self-host ntfy (one env var) to keep push metadata
on your own server.
- **FCM is opt-in** (`IRIS_PUSH_BACKEND=fcm`): standard and reliable, but FCM - **FCM is opt-in** (`IRIS_PUSH_BACKEND=fcm`): standard and reliable, but FCM
push metadata (notification title, device token) is routed through push metadata (notification title, device token) is routed through
**Google's servers**. If you want truly private communication, use ntfy **Google's servers**. If you want truly private communication, use ntfy
@@ -32,10 +33,12 @@ Runs on Android and desktop (Linux, macOS, Windows) from one shared codebase.
## Privacy note (for the "Data safety" section / FAQ) ## Privacy note (for the "Data safety" section / FAQ)
Iris talks directly to your own hermes gateway over a private, token-authenticated Iris talks directly to your own hermes gateway over a private, token-authenticated
connection. By default, push notifications use ntfy, which you can self-host so connection. By default, push notifications use ntfy — out of the box via the
that push metadata never leaves your infrastructure. If you explicitly enable public ntfy.sh service (push metadata such as the topic and notification title
FCM, push metadata (notification title, device token) is sent via Google's FCM passes through ntfy.sh's servers); self-host ntfy (one env var) so that push
servers; chat content itself is not sent to Google — FCM only carries a short metadata never leaves your infrastructure. If you explicitly enable FCM, push
preview, and full content is fetched from your gateway over the authenticated metadata (notification title, device token) is sent via Google's FCM servers;
chat content itself is not sent to Google — FCM only carries a short preview,
and full content is fetched from your gateway over the authenticated
connection. For truly private communication, use the default ntfy backend connection. For truly private communication, use the default ntfy backend
(self-hosted). with a self-hosted ntfy server.