The trust model of Jotbay, in plain words. Each statement here is a statement about the code, and you can read the code.
Jotbay has no server. It sends your notes only to the git repository that you selected. There is no telemetry, there is no analytics, and you make no account with this project.
Jotbay does not read your credentials. It does not keep them, and it does
not send them. The push operation and the pull operation use your git
program and your credential helper. The result is the same as the result of the same
commands in your terminal.
The setup uses gh only for the option
Create one for me. It makes one repository, under the account that
gh uses. The two other setup options do not use gh.
Jotbay reads
api.github.com/repos/<repository>/releases/latest to find a new
version. It sends no data with this request, and it keeps the answer for six hours.
Set JOTBAY_TOOL_REPO to a different address, or prevent the
connection. All other functions continue to operate. The
privacy page lists each connection.
Open a security advisory on the repository. You can also send an email to the address on the GitHub profile of the maintainer. Do not open a public issue for a problem that a person can exploit.
You get an answer in one week. This is a personal project. There is no security team, and there is no bounty.
The most recent release only. The command jotbay upgrade
moves a machine to that release in one step.