fix(public): replace residual editorial and submission-prep copy on the four app pages - #103
Conversation
…he four app pages The Drishti and Promptly product pages still carried the editor-facing 'Where to go next' eyebrow (residual from PR #28), and both app privacy pages still carried submission-prep copy as visible hero/body copy: H1s spoke to the launch calendar ('already in place before launch', 'already public ahead of release'), the leads referenced the 'current planned launch scope' and 'final App Store privacy disclosures before release', the aside was labeled 'Current release scope' with 'not publicly released yet', the first card was headed 'At launch', and the 'Important note' told readers both the page and the App Store privacy answers should be updated before the next submission. Rewrite those passages as visitor-facing copy that describes what each page covers and the choices available, without referencing the submission process. Heading levels, links, meta tags, chips, and JSON-LD are unchanged.
…on-prep copy The residual editorial copy on the app product and privacy pages was cleaned up without a regression guard (the earlier footer-copy guard proposal never merged). Add test-public-app-copy-voice.mjs, wired into npm test and npm run ci, which fails if any of the four app pages re-introduces the editorial/submission-prep phrasing (launch-calendar H1s, planned-scope leads, release-scope asides, at-launch cards, 'Where to go next' eyebrows, submission notes) or drops the visitor-facing product identity and public support route.
There was a problem hiding this comment.
nish3451 has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (5)
🚧 Files skipped from review as they are similar to previous changes (4)
Included review availability: 0 reviews are currently available. Your included PR review attempts over the past 7 days set your current allowance at 3 reviews per hour. 📝 WalkthroughWalkthroughThe public Drishti and Promptly copy now uses updated wording. A new Node.js validation script checks page copy and test wiring. The ChangesPublic copy validation
Estimated code review effort: 2 (Simple) | ~15 minutes Merge Risk: 🔵 Low · up to The PR changes public privacy wording to make an absolute claim about payment-card handling. Merge is reasonable with explicit owner confirmation that deployed systems do not receive full card numbers, since an incorrect statement could make the privacy disclosure misleading. Sequence Diagram(s)sequenceDiagram
participant npmScripts
participant copyVoiceScript
participant publicPages
npmScripts->>copyVoiceScript: Run test-public-app-copy-voice.mjs
copyVoiceScript->>publicPages: Read and validate required copy
publicPages-->>copyVoiceScript: Page content
copyVoiceScript-->>npmScripts: Report checks and exit status
Possibly related PRs
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@public/drishti/privacy/index.html`:
- Around line 109-116: Replace the qualifying “does not describe” language in
public/drishti/privacy/index.html:109-116 with direct, product-owner-confirmed
statements covering Drishti’s use of targeted advertising, cross-app tracking,
sign-in, and website payments. Apply the same root change in
public/promptly/privacy/index.html:108-115 by stating Promptly’s actual
targeted-advertising and cross-app-tracking practices and whether it sells
personal information; update both pages’ corresponding privacy card content
without inferring unconfirmed practices.
In `@scripts/test-public-app-copy-voice.mjs`:
- Around line 59-64: Update PAGE_REQUIREMENTS to include the expected
app-specific support route for each Drishti and Promptly page, adding
/drishti/support/ to Drishti entries and /promptly/support/ to Promptly entries
while preserving the existing title and email requirements.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: 56241dfe-55c3-4424-80fb-6cb950764ab2
📒 Files selected for processing (6)
package.jsonpublic/drishti/index.htmlpublic/drishti/privacy/index.htmlpublic/promptly/index.htmlpublic/promptly/privacy/index.htmlscripts/test-public-app-copy-voice.mjs
| <section class="card-grid"> | ||
| <article class="info-card reveal delay-1"> | ||
| <p class="eyebrow">At launch</p> | ||
| <h2>No third-party advertising or cross-app tracking is disclosed here.</h2> | ||
| <p class="eyebrow">Advertising and tracking</p> | ||
| <h2>No third-party advertising or cross-app tracking.</h2> | ||
| <p> | ||
| This page does not currently describe targeted advertising, | ||
| cross-app tracking, a public sign-in system, or website payments | ||
| for Drishti. | ||
| This page does not describe targeted advertising, cross-app | ||
| tracking, a public sign-in system, or website payments for | ||
| Drishti. |
There was a problem hiding this comment.
🔒 Security & Privacy | 🟠 Major | ⚡ Quick win
State the actual privacy practices.
“Does not describe” only limits the page or policy text. It does not state whether the app uses targeted advertising, cross-app tracking, or sells personal information. Use direct statements of the actual practices after confirming them with the product and privacy owners.
public/drishti/privacy/index.html#L109-L116: state whether Drishti uses targeted advertising, cross-app tracking, sign-in, and payments.public/promptly/privacy/index.html#L108-L115: state whether Promptly uses targeted advertising or cross-app tracking, and whether it sells personal information.
📍 Affects 2 files
public/drishti/privacy/index.html#L109-L116(this comment)public/promptly/privacy/index.html#L108-L115
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@public/drishti/privacy/index.html` around lines 109 - 116, Replace the
qualifying “does not describe” language in
public/drishti/privacy/index.html:109-116 with direct, product-owner-confirmed
statements covering Drishti’s use of targeted advertising, cross-app tracking,
sign-in, and website payments. Apply the same root change in
public/promptly/privacy/index.html:108-115 by stating Promptly’s actual
targeted-advertising and cross-app-tracking practices and whether it sells
personal information; update both pages’ corresponding privacy card content
without inferring unconfirmed practices.
| const PAGE_REQUIREMENTS = { | ||
| "public/drishti/index.html": ["Drishti", "support@tinystudio.in"], | ||
| "public/drishti/privacy/index.html": ["Drishti", "support@tinystudio.in"], | ||
| "public/promptly/index.html": ["Promptly", "support@tinystudio.in"], | ||
| "public/promptly/privacy/index.html": ["Promptly", "support@tinystudio.in"] | ||
| } |
There was a problem hiding this comment.
🎯 Functional Correctness | 🟠 Major | ⚡ Quick win
Validate the app-specific support routes.
PAGE_REQUIREMENTS checks support@tinystudio.in, but it does not check /drishti/support/ or /promptly/support/. An edit can remove an app support route and still pass this test. Add the expected app-specific support route for each product page.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@scripts/test-public-app-copy-voice.mjs` around lines 59 - 64, Update
PAGE_REQUIREMENTS to include the expected app-specific support route for each
Drishti and Promptly page, adding /drishti/support/ to Drishti entries and
/promptly/support/ to Promptly entries while preserving the existing title and
email requirements.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3f32219106
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| "public/drishti/index.html": ["Drishti", "support@tinystudio.in"], | ||
| "public/drishti/privacy/index.html": ["Drishti", "support@tinystudio.in"], | ||
| "public/promptly/index.html": ["Promptly", "support@tinystudio.in"], | ||
| "public/promptly/privacy/index.html": ["Promptly", "support@tinystudio.in"] |
There was a problem hiding this comment.
Check the actual support routes
These requirements only look for the support email address, although the guard is intended to preserve each app's public support path. If /drishti/support/ or /promptly/support/ is removed from a page, the unchanged email in its footer still makes both npm test and npm run ci pass; require the corresponding app-specific support URL instead.
Useful? React with 👍 / 👎.
| "already", | ||
| "launch", | ||
| "planned", |
There was a problem hiding this comment.
Match full editorial phrases instead of common words
Because the test applies html.includes to each entry, ordinary visitor-facing copy containing words such as “already,” “launch,” or “planned” will fail the blocking npm test and npm run ci chains even when none of the old editorial phrasing has returned—for example, an “Already have early access?” support prompt. Match the complete legacy phrases or otherwise scope these checks so valid product copy does not break CI.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
nish3451 has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f27567faa6
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| may support hosting, storage, authentication or OTP delivery, | ||
| notifications, calendar connectivity, support, and payment-proof | ||
| handling. Promptly should not receive full payment-card numbers. | ||
| handling. Promptly does not receive full payment-card numbers. |
There was a problem hiding this comment.
Update the effective date for the revised privacy claims
This changes an intended safeguard (should not receive) into a categorical statement about current data handling, while the page still says the policy became effective on March 14, 2026; the Drishti page likewise gains new current-state claims without changing its date. When this August revision is published, users cannot tell when these materially different disclosures took effect, so update the displayed effective date (or add a revision date) on both privacy pages.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
nish3451 has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 94628be60a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| const APP_PAGES = [ | ||
| "public/drishti/index.html", | ||
| "public/drishti/privacy/index.html", | ||
| "public/promptly/index.html", | ||
| "public/promptly/privacy/index.html" |
There was a problem hiding this comment.
Discover new app pages before checking copy
When another app product or privacy page is added, this hard-coded array never discovers it, so that page can contain every forbidden editorial fragment while both npm test and npm run ci still pass—the opposite of the stated guard on lines 21–23. Enumerate eligible app pages from public/, or add an assertion that every app product/privacy page is represented here.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
nish3451 has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
There was a problem hiding this comment.
nish3451 has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
There was a problem hiding this comment.
nish3451 has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 69bce84ea8
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| for (const page of APP_PAGES) { | ||
| const html = read(page) | ||
| for (const fragment of EDITORIAL_FRAGMENTS) { | ||
| ok(!html.includes(fragment), `${page} avoids "${fragment}"`) |
There was a problem hiding this comment.
Compare editorial fragments case-insensitively
Because String.prototype.includes is case-sensitive, capitalizing a listed lowercase fragment lets the prohibited copy pass the blocking guard. For example, reintroducing “Already public ahead of release” or an “At Launch” heading passes both npm test and npm run ci, despite being the exact editorial voice this test is intended to reject; normalize both the page text and fragments to a common case before comparing them.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
Your trial has ended. Reactivate Greptile to resume code reviews.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 0d85016937
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| const html = read(page) | ||
| for (const fragment of EDITORIAL_FRAGMENTS) { | ||
| ok(!html.includes(fragment), `${page} avoids "${fragment}"`) |
There was a problem hiding this comment.
Normalize rendered text before checking fragments
Because this applies includes directly to raw HTML, a prohibited visitor-facing phrase passes whenever normal markup changes its source representation—for example, App Store, Current release\n scope, or text split by an inline element all render as the banned phrase but are not matched. Extract or normalize rendered text, including entities and whitespace, before performing these checks so harmless HTML formatting cannot bypass the CI guard.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
Your trial has ended. Reactivate Greptile to resume code reviews.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 13a651e6dc
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| for (const page of APP_PAGES) { | ||
| const html = read(page) | ||
| for (const fragment of PAGE_REQUIREMENTS[page]) { | ||
| ok(html.includes(fragment), `${page} names ${fragment}`) |
There was a problem hiding this comment.
Scope product identity checks to the app content
Because this searches the entire HTML document, the shared metadata and footer already contain each expected app name; even deleting all Drishti- or Promptly-specific visitor-facing content from <main> would leave this check passing. Check the relevant heading or normalized main content instead so the advertised product-identity guard detects an over-aggressive rewrite.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
Your trial has ended. Reactivate Greptile to resume code reviews.
…lve package.json ci/test conflict (keep main's full chain, add test-public-app-copy-voice guard)
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
There was a problem hiding this comment.
Your trial has ended. Reactivate Greptile to resume code reviews.
There was a problem hiding this comment.
Your trial has ended. Reactivate Greptile to resume code reviews.
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Only conflict was the advertising/tracking paragraph on drishti/privacy, where PR #186 landed alternative wording on main. Took main wording; this branch remaining value is the two product-page rewrites and the test-public-app-copy-voice.mjs guard, which passes against main copy (62 checks, 0 failures).
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
There was a problem hiding this comment.
Your trial has ended. Reactivate Greptile to resume code reviews.
package.json conflict only after the latest main merges: take main ci/test chains and re-insert this PR own check. Guard re-run against current main.
PR #123 replaced the literal support@tinystudio.in in the public HTML with support@tinystudio.in so Cloudflare Email Address Obfuscation cannot rewrite it into a [email protected] placeholder, and its live check now asserts the plaintext form is absent. This guard still required the plaintext form, so the two contradicted each other. Updated to match the landed encoding.
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
There was a problem hiding this comment.
Your trial has ended. Reactivate Greptile to resume code reviews.
There was a problem hiding this comment.
Your trial has ended. Reactivate Greptile to resume code reviews.
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Automated conflict resolution during the PR backlog sweep: kept main's side of every shared block, re-applied this branch's unique additions on top (package scripts re-inserted into main's chains; live-check sections relabelled to the next free letter). Repo check chain re-run green before push.
There was a problem hiding this comment.
Your trial has ended. Reactivate Greptile to resume code reviews.
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
What
The four public app pages still carried internal editorial and submission-prep notes as visible copy on main:
Rewrite all of those passages as visitor-facing copy describing what each page covers and the choices available, without referencing the submission process. Heading levels, links, meta tags, chips, and JSON-LD are unchanged.
Guard
Add
scripts/test-public-app-copy-voice.mjs, wired intonpm testandnpm run ci, which fails if any of the four app pages re-introduces the editorial/submission-prep phrasing or drops the visitor-facing product identity and public support route.Verification
npm run cipasses end to end (exit 0).git diff --checkclean.Summary by CodeRabbit
Content Updates
Quality Improvements