Applies the gen2 desktop-PTT review summary
(`gen2/chanora-desktop-ptt-review-summary-v0.9.2.md`) to our doc set
with the owner rulings PTT-OPEN-001 through PTT-OPEN-006 resolved as
accepted decisions DEC-023 through DEC-028:
* DEC-023 Windows Global PTT P0 / MVP
* DEC-024 macOS Global PTT P0 / MVP with permission UX
* DEC-025 Linux officially-tested env: GNOME on Wayland only
* DEC-026 Mouse side buttons supported (Win + macOS; Linux portal)
* DEC-027 PTT diagnostics: capability + availability only, no
raw key codes ever
* DEC-028 Missed-key-up watchdog: P0
Requirements (SysRS / SRS) and architecture (SysDes / SAD / SDD)
gain the desktop-PTT ID set the gen2 summary describes:
SysRS-296..302 -> SysDes-142..148
-> SRS-195..203
-> SAD-071..079
-> SDD-081..092
ID totals advance from 295 / 141 / 194 / 70 / 80 to 302 / 148 / 203
/ 79 / 92. The strict layered sourcing rule (`SRS -> SysDes` only,
`SAD -> SRS` only, `SDD -> SAD` only) is preserved; the
`tools/validate_docs.py` validator reports zero undefined refs and
zero direct-layer-rule violations.
New document:
* `docs/architecture/desktop-ptt-architecture.md` — capability
ladder (L0Focused, L1GlobalShortcut, L2GlobalHoldToTalk,
L3GlobalWithMouseButtons, L4DeviceAware reserved), Windows /
macOS / Linux strategies, privacy rule, audio-gate rule,
missed-key-up watchdog, release-readiness evidence requirement,
traceability summary.
Doc addenda (Baseline Candidate 0.9.3):
* `privacy/privacy-policy.md` — no raw key history, capability-
dependent Global PTT, UI reflects actual runtime capability
* `security/threat-model.md` — THREAT-PTT-001..006
* `security/diagnostic-redaction-audit-report.md` —
REDACT-PTT-001..006 banned field list enforced by `PttSanitizer`
* `release/platform-release-policy.md` — per-platform evidence
fields, no over-claim on untested Linux compositors
* `release/release-readiness-go-nogo-record.md` — RR-PTT-001..008
release-readiness items
* `verification/swe4-unit-verification-plan.md` —
SWE4-UV-035..039
* `verification/swe5-software-integration-verification-plan.md` —
SWE5-IV-015
* `verification/swe6-software-verification-plan.md` — SWE6-SV-017
* `verification/sys4-system-integration-verification-plan.md` —
SYS4-SIV-016
* `governance/traceability-matrix.md` — full PTT trace rows +
verification map
* `governance/decision-impact-assessment.md` — DEC-023..028
impact matrix
* `governance/product-decision-register.md` v0.9.9 entry
recording DEC-023..028 in the decision table and the status
table at §7
* `governance/document-index.md` — adds
`desktop-ptt-architecture.md` to the controlled set
* `architecture/proof-of-concept-plan.md` —
PoC-PTT-001..005 platform items
* `references/external-references.md` — Windows Raw Input,
macOS event-tap, Linux GlobalShortcuts portal references
* Both validation reports
(`baseline-candidate-validation-report.md`,
`repo-format-validation-report.md`) bumped to v0.9.3 with the
new ID totals (302 / 148 / 203 / 79 / 92).
README §"Desktop Push-to-Talk" added between Architecture Overview
and Repository Layout: capability levels, per-platform strategy,
privacy posture, missed-key-up watchdog.
Tooling:
* `tools/validate_docs.py` copied from the gen2 zip into the
repo tree (was previously available only inside the zip).
Reports zero undefined refs, zero direct-layer-rule violations,
English-only CJK check passes. The 35 "old package-style
filename" hits are pre-existing and identical to the gen2
baseline (they live in `path-migration-map.md` and config-ID
headers of governance docs and are intentional per the path
migration policy).
* `.gitignore` adds `/gen2/` so the externally-provided review
package does not enter the repo.
No code changes in this commit; B (the implementation split into
`transmit_active` / `capture_active`, `PttCapabilityLevel`
reporting, `PttSanitizer` diagnostics rule, and the UI capability
badge) follows in a separate commit.
5.5 KiB
Priv Privacy Policy V0.9.2.2.1
Document type: Privacy / Public Policy Draft
Version: 0.9.2
Status: Baseline Candidate / Legal Review Required
Language: English
Product: Chanora
Repo path: docs/privacy/privacy-policy.md ---
1. Important Notice
This is a draft privacy policy template for review. It must be reviewed by a qualified legal/privacy reviewer before public release or store submission.
2. Overview
Chanora is a client application for connecting to compatible voice communication servers. Chanora is designed to operate primarily on the user's device.
3. Data Processed by the App
Depending on how the user configures and uses the app, Chanora may process:
- server address and port;
- server password if provided by the user;
- user nickname;
- identity information needed for server connection;
- channel names and server-provided names;
- chat messages displayed in the app;
- audio input and output during voice sessions;
- local application settings;
- audio device settings;
- diagnostic information generated by the app.
4. Local Storage
Chanora may store local settings, bookmarks, recent server information, audio preferences, and related configuration on the user's device.
Sensitive secrets such as server passwords or identity secrets are intended to be stored using platform secure storage mechanisms where supported.
5. Diagnostics
Chanora may allow the user to generate diagnostic bundles for troubleshooting.
Diagnostic export is intended to be user-initiated. Diagnostic bundles should be redacted to avoid including passwords, identity secrets, and other sensitive information.
Chanora should not automatically upload diagnostic bundles unless a future version explicitly introduces an opt-in upload feature and updates this policy.
6. Audio and Microphone
Chanora uses microphone access to provide voice communication features. Audio is processed for voice communication and may include echo cancellation, automatic gain control, noise suppression, and high-pass filtering.
Chanora should not record or persist voice audio unless a future feature explicitly states otherwise and receives user consent where required.
7. Permissions
Chanora may request permissions required for voice communication, notifications, audio routing, local storage access, or platform-specific behavior.
Permission requirements vary by platform.
8. Data Sharing
This draft policy assumes:
- Chanora does not sell user data.
- Chanora does not automatically upload diagnostics.
- Chanora does not include automatic telemetry unless later approved and documented.
- User-initiated sharing of diagnostic bundles is controlled by the user.
These assumptions must be confirmed before public release.
9. Third-Party Servers
When the user connects to a compatible external server, the server may receive connection information, nickname, voice data, text messages, or other information necessary for communication. The operation of external servers is outside Chanora's control.
10. Third-Party Dependencies
Chanora may use third-party software dependencies. The dependency and license list should be published or made available where required by applicable licenses.
11. Children's Privacy
TBD by legal/privacy reviewer.
12. Regional Requirements
TBD by legal/privacy reviewer. Public release may require region-specific privacy disclosures.
13. Contact
TBD.
14. Change History
| Version | Date | Description |
|---|---|---|
| 0.9.0 | 2026-05-14 | Initial privacy policy draft template; legal review required before public release. |
Baseline Candidate 0.9.1 Update
| Version | Date | Description |
|---|---|---|
| 0.9.1 | 2026-05-14 | Updated baseline after product decision closure: Apple App Store SDK gate uses Xcode 26+ and iOS 26 / iPadOS 26 SDK+ since 2026-04-28, platform baselines and decision traceability propagated across the document set. |
Baseline Candidate 0.9.2 Update
| Version | Date | Description |
|---|---|---|
| 0.9.2 | 2026-05-14 | Corrected Apple App Store Connect upload gate to 2026-04-28 and checked full-package naming, references, and coverage. |
Desktop Push-to-Talk Privacy Addendum (Baseline Candidate 0.9.3)
Per SysRS-302 / SRS-202 / DEC-027, the Chanora desktop PTT subsystem operates under the following privacy rule:
- Chanora shall not log, persist, or transmit raw keyboard key codes, scan codes, virtual-key values, keysyms, or key-press timing sequences.
- The user-initiated diagnostic export shall include only the detected PTT capability level (
L0Focused,L1GlobalShortcut,L2GlobalHoldToTalk,L3GlobalWithMouseButtons, or the reservedL4DeviceAware), the active backend identifier (a fixed string per implementation, for example"raw-input","event-tap","gnome-wayland-portal","focused"), and the bound input class ("keyboard","mouse-side-button"). - The bound key value itself is never included in any diagnostic, even when the user invokes the export explicitly.
- Whether Global PTT is available depends on the operating system, the user-granted permission set, the display server, and the available input backend. Where Global PTT cannot be honoured, Chanora falls back to Focused PTT and reports the fallback honestly through the UI capability badge.
| Version | Date | Description |
|---|---|---|
| 0.9.3 | 2026-05-15 | Added desktop Push-to-Talk privacy addendum: raw key history is not recorded or exported; Global PTT is capability-dependent and the UI reflects actual runtime capability. |