diff --git a/.github/images/fdroid.png b/.github/images/fdroid.png new file mode 100644 index 0000000..9500c4a Binary files /dev/null and b/.github/images/fdroid.png differ diff --git a/.github/images/playstore.png b/.github/images/playstore.png new file mode 100644 index 0000000..131f3ac Binary files /dev/null and b/.github/images/playstore.png differ diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index a9eb4a7..a21cdb1 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -40,6 +40,11 @@ jobs: gpg -d --passphrase "${{ secrets.RELEASE_KEYSTORE_PASSWORD }}" --batch keystore.asc > app/keystore.properties gpg -d --passphrase "${{ secrets.RELEASE_KEYSTORE_PASSWORD }}" --batch key.asc > app/key.jks + - name: Generate Dynamic Release Notes + run: | + mkdir -p tmp/whatsnew + echo "Various improvements for you to experience..." > tmp/whatsnew/whatsnew-en-US + - name: create and checkout branch if: github.event_name == 'pull_request' env: @@ -99,5 +104,6 @@ jobs: serviceAccountJsonPlainText: ${{ secrets.SERVICE_ACCOUNT_JSON }} packageName: net.helcel.fidelity releaseFiles: app/build/outputs/bundle/signedRelease/app-signedRelease.aab - tracks: 'internal' # ${{ startsWith(github.ref, 'refs/tags/') && 'production' || 'beta' }} + tracks: ${{ startsWith(github.ref, 'refs/tags/') && 'production' || 'alpha' }} status: completed + whatsNewDirectory: tmp/whatsnew diff --git a/PRIVACY.md b/PRIVACY.md new file mode 100644 index 0000000..c2d169c --- /dev/null +++ b/PRIVACY.md @@ -0,0 +1,77 @@ +# Privacy Policy for Keepass Fidelity + +**App:** Keepass Fidelity (`net.helcel.fidelity`) +**Developer:** Helcel +**Effective date:** 19 September 2026 + +## What we collect + +Nothing. We operate no servers and receive no data from the app. Keepass +Fidelity has no internet access, no account, and contains no analytics, +advertising, or tracking libraries. + +## Your data + +Your loyalty cards (names and barcodes) are stored in the +KeePass database you choose, not in a separate store controlled by us: + +- **Standalone mode:** the app opens a `.kdbx` file you select, using the + bundled KeePassDX engine. The file stays where you put it, encrypted by + KeePass with your password or key file. +- **Keepass2Android plugin mode:** entries are read and created through the + Keepass2Android app installed on your device. That app holds the database and + its own privacy policy applies to it. + +Your database password is used only to unlock your database on the device. It is +never stored anywhere by us and never leaves your device. + +If your database file is kept in a folder synchronised by another app or cloud +service, that service handles the file under its own privacy policy. + +## On-device cache + +For quick access, the app keeps a recently-used history and may cache entry data +in its private storage. You can mark individual entries to be excluded from +caching, and the cache can be cleared from the app or by clearing the app's data +in Android Settings. + +## Permissions + +- `CAMERA` — scanning a barcode to create an entry. Camera frames are processed + on the device and are not stored or transmitted. +- `READ_MEDIA_VISUAL_USER_SELECTED` — reading a barcode from an image you + explicitly select. Only the images you pick are accessed, and only while + importing. + +## Retention and deletion + +Cached data and history remain until you clear them or uninstall the app. +Uninstalling does not delete your KeePass database, which is your own file: +delete it yourself, or remove entries through the app or any KeePass client. + +## Children + +Keepass Fidelity is suitable for all ages and collects no data from any user, +including children. + +## Security + +Your cards are protected by KeePass encryption, which depends on the strength of +the password or key file you choose. On-device cache and history are held in the +app's private storage, protected by the Android sandbox. + +## Open source + +Keepass Fidelity is released into the public domain under the Unlicense. The +full source is available at https://github.com/helcel-net/keepass-fidelity, so +these statements can be independently verified. + +## Changes + +Any change affecting privacy will be published in this document before or with +the release that introduces it. + +## Contact + +Email: net.helcel+privacy@google.com +Issues: https://github.com/helcel-net/keepass-fidelity/issues \ No newline at end of file diff --git a/README.md b/README.md index 341d0d2..49020c8 100644 --- a/README.md +++ b/README.md @@ -43,13 +43,23 @@
+Note: + - Fdroid: requested, see https://gitlab.com/fdroid/rfp/-/work_items/4411 + - PlayStore: alpha test restriction by Google. To access, join https://groups.google.com/g/helcel-android-test + ## ⚙️ Permissions - `CAMERA`: necessary for importing barcodes from camera @@ -68,6 +78,13 @@ Keepass-Fidelity is a user-driven project. We welcome any contribution, big or s Thanks to all contributors, the developers of our dependencies, and our users. +## Signinig key + +``` +net.helcel.fidelity +D1:96:54:FE:1D:79:16:76:47:D7:A6:12:0E:F6:AB:7D:56:9D:45:AD:FD:41:EF:D6:FA:80:9D:26:52:73:F6 +``` + ## 📝 License ``` diff --git a/app/build.gradle b/app/build.gradle index baf3ca4..c862cb1 100644 --- a/app/build.gradle +++ b/app/build.gradle @@ -145,7 +145,7 @@ dependencies { //Submodule //noinspection NewerVersionAvailable - implementation 'joda-time:joda-time:2.14.3' + implementation 'joda-time:joda-time:2.14.4' implementation 'org.joda:joda-convert:3.0.1' testImplementation 'junit:junit:4.13.2' diff --git a/build.gradle b/build.gradle index 2db08f6..8795110 100644 --- a/build.gradle +++ b/build.gradle @@ -8,7 +8,7 @@ buildscript { plugins { id 'com.android.application' version '9.4.1' apply false - id 'com.android.library' version '9.3.2' apply false + id 'com.android.library' version '9.4.1' apply false id 'org.jetbrains.kotlin.android' version '2.3.21' apply false id 'com.autonomousapps.dependency-analysis' version '3.13.0' apply true } \ No newline at end of file