The docs claimed ntfy keeps push metadata on your own infrastructure, but the default NTFY_SERVER_URL is the public https://ntfy.sh cloud service. Make explicit that push metadata (topic, notification title) passes through ntfy.sh unless you self-host ntfy.
45 lines
2.1 KiB
Markdown
45 lines
2.1 KiB
Markdown
# Play Store Listing
|
|
|
|
Copy-paste text for the Play Console (and the F-Droid / sideload pages).
|
|
Keep this file in sync with the README whenever the privacy story changes.
|
|
|
|
## Short description (≤ 80 chars)
|
|
|
|
Private chat for your personal AI agent — Android & desktop.
|
|
|
|
## Full description
|
|
|
|
Iris is a native chat app for your personal AI agent (hermes-agent):
|
|
streaming replies, visible reasoning, structured tool activity, channels,
|
|
threads, media, search — Telegram-quality, on your own infrastructure.
|
|
|
|
**Absolute Privacy!** — everything stays on your own infrastructure:
|
|
|
|
- Your gateway, your machine, your data. No cloud middleman for chat.
|
|
- **Push notifications:** ntfy by default. Note: out of the box it uses the
|
|
public ntfy.sh service; self-host ntfy (one env var) to keep push metadata
|
|
on your own server.
|
|
- **FCM is opt-in** (`IRIS_PUSH_BACKEND=fcm`): standard and reliable, but FCM
|
|
push metadata (notification title, device token) is routed through
|
|
**Google's servers**. If you want truly private communication, use ntfy
|
|
(self-hosted) instead — it is the default.
|
|
|
|
100 MB file uploads by default (configurable on your gateway). No
|
|
4,096-character message limit like Telegram. Full markdown + HTML artifact
|
|
preview. All settings live in the app.
|
|
|
|
Runs on Android and desktop (Linux, macOS, Windows) from one shared codebase.
|
|
|
|
## Privacy note (for the "Data safety" section / FAQ)
|
|
|
|
Iris talks directly to your own hermes gateway over a private, token-authenticated
|
|
connection. By default, push notifications use ntfy — out of the box via the
|
|
public ntfy.sh service (push metadata such as the topic and notification title
|
|
passes through ntfy.sh's servers); self-host ntfy (one env var) so that push
|
|
metadata never leaves your infrastructure. If you explicitly enable FCM, push
|
|
metadata (notification title, device token) is sent via Google's FCM servers;
|
|
chat content itself is not sent to Google — FCM only carries a short preview,
|
|
and full content is fetched from your gateway over the authenticated
|
|
connection. For truly private communication, use the default ntfy backend
|
|
with a self-hosted ntfy server.
|