aboutsummaryrefslogtreecommitdiffstats
path: root/docs
diff options
context:
space:
mode:
authorChristophe Besson <cbesson@gmail.com>2026-10-10 14:21:46 +0200
committerChristophe Besson <cbesson@gmail.com>2026-10-10 14:21:46 +0200
commit2f2a9a6542d2194e50ffba6f382e4fdffd481838 (patch)
tree5437330f9e8b963f8af0904f3c5d80d1afc6dc3b /docs
parent914d2f0af848fb80d70d517901f44420a4e47764 (diff)
downloadmeshbay-2f2a9a6542d2194e50ffba6f382e4fdffd481838.tar.gz
feat(android): one backup destination, a group the account owns alone
Chosen once at the top of Android Sync for every kind; photos and contacts go into <folder>/<account>-photos and -contacts. Owner and sole member are checked at set-up and before every run. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'docs')
-rw-r--r--docs/MESHBAY_DESIGN.md46
-rw-r--r--docs/USERGUIDE.md67
2 files changed, 60 insertions, 53 deletions
diff --git a/docs/MESHBAY_DESIGN.md b/docs/MESHBAY_DESIGN.md
index 052570a..8293493 100644
--- a/docs/MESHBAY_DESIGN.md
+++ b/docs/MESHBAY_DESIGN.md
@@ -3326,7 +3326,7 @@ are two albums.
### 9.12 Photo backup (Android)
The Android application sends the photos taken on the phone to **one folder of
-one group**, chosen by the member, once a day. It is a client feature over the
+a group the member owns and is the only member of**, once a day. It is a client feature over the
upload path that exists: a backed-up photo is a `file_upload` into a writable
root under a slot the node granted, with every rule of §6.4, and its owner is
recorded as for any upload. **No message, no node state and no hub state was
@@ -3345,9 +3345,24 @@ object — absent, not refusing (§11.3).
**Where it lives.** Its controls are on a page of their own, **Android Sync**,
under a **Phone** heading of the side menu (`android-sync-page.js`), shown only
-where `platform.photoSync` exists. Settings holds what the account prefers on
-every client; this page holds what one phone sends, and is where whatever else
-the phone sends will go.
+where `platform.phoneSync` exists. Settings holds what the account prefers on
+every client; this page holds what one phone sends: photos, contacts (§9.13),
+and the kinds to come (messages, calendar, files).
+
+**One destination for every kind.** The top of the page chooses it once: a
+group and one of its writable folders (`Destination.kt`, `sync-destination.js`).
+Each kind goes into its own folder under it, `<folder>/<account>-photos`,
+`<folder>/<account>-contacts`, made if missing. Only a group **the account owns
+and is the only member of, with nobody invited**, is offered, because what a
+group's folder holds every member can read, and none of this is the group's.
+The hub's member list is asked again **at every run, before anything is
+read**: a group that has gained a member, an invitation or another owner stops
+every backup (`not_private`, a lasting refusal said once) rather than being
+read from then on. Moving the destination is a fresh start for every kind:
+each is told, forgets what it sent (its ledger belongs to the old place) and
+runs at once; what was sent stays where it is. The page says so before it
+happens, and says too when the group's Photos tab does not show
+`<folder>/<account>-photos`, since photos there are kept but shown nowhere.
**When.** A run is due 24 hours after the last run that *finished*; an
interrupted one is retried at the next chance, at most every fifteen minutes.
@@ -3364,19 +3379,15 @@ node's partial upload resumes it (§8.5).
like a member sending by hand and gives it back, so a family's daily backups
never occupy the node's upload pool ahead of a person.
-**Where.** The member chooses the group (one per phone) and a folder among
-those that are writable, available and shown by the group's Photos tab — a
-folder outside those would take the photos and show them nowhere. Inside it,
-each photo goes under `YYYY/YYYY-MM` from when it was taken, because an album is a
+**Where.** Under `<folder>/<account>-photos` of the destination, each photo
+goes under `YYYY/YYYY-MM` from when it was taken, because an album is a
directory (§9.9) and one folder of twenty thousand is a slow album. Albums on
the phone are chosen too; the camera alone is the default, because screenshots
and saved images are where photos nobody meant to share live. **By default the
photos already on the phone are sent, newest first**, then each new one; "from
-now on" is an option. A confirmation is drawn **when the destination or the
+now on" is an option. A confirmation is drawn **when the backup starts or its
starting point changes, never per run and never for a change of albums alone**:
-it names the group, its owner, its member count, the folder, the count and size
-about to go, and says that members can download them and that what they
-downloaded cannot be taken back.
+it names the folder and the count and size about to go.
**Additive by construction.** The backup never deletes, renames or replaces
anything on the node: `photo-sync.js` reaches no such operation
@@ -3419,15 +3430,8 @@ path, additive, once a day, the page doing the sending and the phone handing
bytes over by token (`/phonesync/<token>`, `phonesync/` in the Android
package, `phone-sync.js` on the page). Messages follow the same design.
-**Only a group the person is alone in.** What a group's folder holds every
-member can read, and an address book is not the group's. The set-up offers
-only groups whose member list is this account and nobody invited, and every
-run asks the hub again before reading anything: somebody who joins later stops
-the backup (`not_private`, a lasting refusal said once) rather than reading
-every copy from then on. Any writable folder of that group is offered, not
-only the ones the Photos tab shows.
-
-**Where.** `<folder>/<account>-contacts/`, made if missing. Each copy is a new
+**Where.** `<folder>/<account>-contacts/` of the destination every kind shares
+(§9.12), checked at every run the same way. Each copy is a new
file named for when it was taken (`contacts-2026-10-10-0900.vcf`), never a
replacement: restoring is importing the newest one, and an older one is there
if a phone sync went wrong.
diff --git a/docs/USERGUIDE.md b/docs/USERGUIDE.md
index d8e793f..4c5c61e 100644
--- a/docs/USERGUIDE.md
+++ b/docs/USERGUIDE.md
@@ -382,55 +382,58 @@ coordinates are still inside the photo itself, as your phone wrote them, so
anyone who downloads the original file has them. Strip them before sharing if
that matters to you.
-### Backing up your phone's photos
+### Backing up your phone
-On the Android application, **Phone → Android Sync** in the side menu holds
-**Photo backup**, which sends the photos taken on your phone to a folder of one
-of your groups, once a day.
+On the Android application, **Phone → Android Sync** in the side menu backs up
+your phone's photos and contacts to a group.
-- **Set up** asks for access to your photos, then for a group, a folder and the
- albums to send. Only folders you may add to and that the group's Photos tab
- shows are offered. The camera is ticked; screenshots and other albums are
- yours to add.
+**Where backups go** is chosen once, at the top of the page, for every kind:
+
+- **Only a group you own and are the only member of** can receive them: your
+ photos and your address book are not the group's. If you have none, create a
+ group just for yourself first. If somebody joins it or is invited later,
+ every backup stops and tells you.
+- You choose any folder of that group you may add to. Each kind of backup gets
+ a folder named after you inside it: `Backups/alice-photos`,
+ `Backups/alice-contacts`. The page tells you if the group's Photos tab does
+ not show the photos folder; add it in the group settings to see them there.
+- Choosing another group or folder later starts every backup again in the new
+ place. What was already sent stays where it is.
+
+#### Photos
+
+- **Set up** asks for access to your photos, then for the albums to send. The
+ camera is ticked; screenshots and other albums are yours to add.
- By default **the photos already on the phone are sent too**, newest first,
then each new one. Choose "Only photos taken from now on" to skip the ones
- already there.
-- Before anything is sent you are told where the photos go, how many members
- the group has and how much will be sent. **Everyone in that group will be
- able to see and download them.** You can delete what you sent afterwards,
- but not the copies others have already downloaded — so pick the group with
- care. Changing the group or the folder later asks again.
+ already there. Before the first send you are told how many photos and how
+ much that is.
- It runs **on Wi-Fi only** (more exactly, on a connection that is not charged
- by the amount), once a day, while the application is open — with the screen
+ by the amount), once a day, while the application is open, with the screen
off too. If the application was not opened all day, it runs the next time it
is. **Back up now** runs at once; on mobile data it tells you how much it is
about to send and asks first.
-- Photos go into folders by year, then year and month (`2026/2026-10`). **A photo you delete
- from the phone stays in the group**, and one deleted from the group is not
- sent again, unless the application is reinstalled. A photo you edit on the phone is sent again beside the original,
- with `-edited-` and the date in its name.
+- Photos go into folders by year, then year and month (`2026/2026-10`). **A
+ photo you delete from the phone stays in the group**, and one deleted from
+ the group is not sent again, unless the application is reinstalled. A photo
+ you edit on the phone is sent again beside the original, with `-edited-` and
+ the date in its name.
- **Where a photo was taken is removed** from the copy that is sent.
-- If the backup cannot go on — the node's disk is full, the folder no longer
- accepts files, you left the group — it stops, says why once in a
- notification and on the Android Sync page, and tries again the next day.
-### Backing up your phone's contacts
+#### Contacts
-**Contacts backup**, on the same **Android Sync** page, sends a copy of your
-phone's contacts to a group, once a day when they have changed.
-
-- **Only a group you are the only member of** can receive it: your address
- book is not something to share. If you have none, create a group just for
- yourself first. If somebody joins that group later, the backup stops and
- tells you.
-- You choose any folder of that group you may add to; the copies go into a
- folder named after you inside it, such as `Backups/alice-contacts`.
+- **Turn on** asks for access to your contacts, then sends a copy once a day
+ when they have changed.
- Each copy is a `.vcf` file with the date in its name
(`contacts-2026-10-10-0900.vcf`). Any phone can import it. Older copies are
kept, nothing is ever replaced.
- It runs on any connection, since a copy is small. **Back up now** sends one
at once if your contacts changed since the last copy.
+If a backup cannot go on (the node's disk is full, the folder no longer accepts
+files, somebody else joined the group), it stops, says why once in a
+notification and on the Android Sync page, and tries again the next day.
+
### Search
The magnifying glass in the sidebar searches **across every group you are in**