Skip to content

feat: v1.1 private research, local media and automatic email activity - #11

Merged
user-github-me merged 5 commits into
mainfrom
feat/v1.1-private-tools
Oct 3, 2026
Merged

user-github-me merged 5 commits into
mainfrom
feat/v1.1-private-tools

Conversation

@user-github-me

@user-github-me user-github-me commented Oct 3, 2026 •

Copy link
Copy Markdown
Owner

What changed

LocalPulse v1.1.0 now offers private research, local media and optional email read activity through discoverable controls. Enabling tracking once during onboarding connects the public service and reserves the first image; supported Gmail/Outlook drafts get independent images, a per-draft toggle and local estimated-read badges. Tracking never reads or sends email subjects, recipients, bodies or private names. Private keys and decrypted results stay local; encrypted queued events are deleted only after local saving and signed acknowledgement, without expiry.

  • Save/search/reopen research collections locally, import/export validated JSON and require fresh cloud consent for reopened sources.
  • Open verified quotations in actual source context with extracted PDF page numbers.
  • Review duplicate tabs, confirm closing, save/restore local sessions and optionally group by domain in Chromium.
  • Recognize images/scanned PDFs with bundled Tesseract and transcribe chosen English audio with bundled Whisper/ONNX. Model data downloads only after enable; files stay local. Review/export text or add it to the workspace.
  • Send an explicit typed query to Wikipedia or a user-chosen SearXNG endpoint and fetch only selected public sources.
  • Add private tracking names, separate opt-in generic notifications, scheduled collection and a synthetic encrypted diagnostic with cleanup.
  • Display the configured shortcut for each OS, including unassigned bindings.
  • Fix production startup before optional alarm APIs exist; add a separate production-manifest regression. Fix media dialog readiness across effect cleanup.

The production manifest adds optional alarms/notifications and Chromium tabGroups permissions; tabs/site access remain optional. Bundled runtime code/WASM comes from locked npm dependencies, and model data revisions are pinned. Native ONNX/dependency postinstalls are disabled for browser builds. AI provider consent and never-send protections still apply to each source; explicitly enabled tracking and typed web research have separate network disclosures.

How I tested it

  • Types, lint, format and frozen-lockfile installation passed. GitHub CI at the final commit also passed both build/unit and browser jobs: https://github.com/user-github-me/localpulse-ai/actions/runs/37098954189.
  • 264 unit tests and 7 native tracking-service tests passed.
  • 68 Chromium browser tests passed with real media enabled, including production startup, light/dark accessibility, privacy/consent, imports, writing, study/follow-ups and synthetic Gmail/Outlook flows.
  • Real OCR recognized an image and two-page PDF; OCR and Whisper reopened with model download hosts blocked. Files were not uploaded.
  • A separate real WebLLM GPU test produced a 1,017-character local article summary.
  • Live Vercel/Upstash synthetic read encrypted/decrypted/acknowledged; queue empty afterward.
  • Production Chrome/Firefox ZIPs and reviewer source ZIP built. Firefox validation: 0 errors, 17 static warnings in bundled code.
  • CRX signed with the existing private key; signature/public ID/version verified and every packaged file matched the Chrome ZIP. No key in packages.
  • UI text is in en.yml, permission/network justifications and public service disclosures updated.

Complete test report · Release notes · Store preparation

Authenticated mail layouts, every live cloud provider, actual Windows/Linux and a real Firefox profile were not exercised. Image requests can be proxies/preloads/scanners, so counts are estimates. Free hosting and bounded queues can miss activity. Firefox static warnings and model/browser limits are recorded in the report. No store publication, production-branch push, merge or automatic issue closure is performed by this PR.

Optional tracking controls with synthetic data

Closes #2
Closes #3
Closes #4
Closes #5
Closes #6
Closes #7
Closes #8
Closes #9
Closes #10
Closes #12
Closes #13
Closes #14
Closes #15

@vercel

vercel Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
localpulse-email-tracker Ready Ready Preview Oct 3, 2026 5:10am UTC

This branch was successfully deployed

1 active deployment
Preview — b0ad6674 Deployed Oct 3, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment