English
WebHarbor is a local-first iPhone app without advertising or advertising tracking. Version 3.0 adds an optional notification gateway; notification processing applies when you connect a workspace and the service is available. Port also offers a separate, voluntary developer location-sampling workflow described below. Earlier builds may not include these features. Availability depends on deployment and device validation.
Optional notifications in 3.0
After you opt in, notify.lihenry.com processes an encrypted Apple push device token, an installation credential hash, a random notification route identifier, language preference, and site user/group references to send reminders. For a Hezhang workspace, the gateway may also receive an encrypted, bounded summary containing the actor display name, amount and category so the alert can show those details when lock-screen details are enabled. It does not receive your WebKit data-store UUID, website cookies, passwords, memo text, record IDs or counterparties. Hidden-details subscriptions receive generic alert text. Apple delivers the notification through APNs.
In 3.0, connecting GitHub requires separate official GitHub App authorization. The gateway stores encrypted authorization credentials, verified GitHub identity, selected repository references and necessary event/target identifiers. Signed events are filtered for assigned Issues, direct review requests and failed or timed-out Actions. It does not synchronize the whole personal notification center or copy website login cookies. Availability is gated by deployment and verification.
Creating a private push entry sends its display name, HTTPS starting URL and random route to the gateway. Your server or script can send a message title, body and same-origin target URL. This content is encrypted at rest but must be processed to show messages; do not send passwords or secrets. Send credentials are stored in this device's Keychain; the server retains only their verification hashes. Invited websites can connect a restricted subscription after your confirmation, without obtaining your APNs token or global installation credential.
Optional Port region-assisted reminders
Location assistance is off by default and requires separate permission and verified region configuration. It can monitor at most four predefined border regions in the background. As of this update, production regions remain unconfigured pending real-world validation. Region reminders send a region code, enter/exit transition, time, configuration version and event ID, associated with the notification binding, through the gateway to Port. This reminder workflow does not upload raw coordinates or a continuous route. Without the required permission or configuration, Port uses the travel-plan time estimate. You can turn assistance off in Inbox → Notification Sources → Port → account/workspace → Location Assistance.
Port removes online semantic region-event records older than 24 hours during scheduled maintenance, not necessarily at the exact 24-hour boundary. Daily operation normally means cleanup within the next maintenance run; outages can delay it. Backups have the separate retention described below. This is not a promise that every copy disappears within 24 hours.
Port developer foreground location sampling
Only an authenticated Port developer account can use this voluntary workflow. After reading the collection notice and consenting, each explicit capture requests one foreground location fix. Port receives WGS84 latitude and longitude, accuracy, observation and receipt times, travel direction, selected border stage, journey/sample identifiers and the current account association. These points help compare visits across days and prepare region definitions for human review. They are not automatically turned into active geofences, traffic corrections, training labels or notification events, and are not sent to the notification gateway by this workflow.
The collector does not continuously watch location or run background sampling, and does not persist raw coordinates in browser LocalStorage or IndexedDB. You can view, export, replace or delete your own samples. Private responses use no-store. Deleting or replacing a point removes its previous raw coordinates from active records; limited operation audit metadata may remain until cleanup. Online samples and their sampling audit records are eligible for deletion 30 days after the original server receipt time and are removed by scheduled maintenance; retries do not restart that period.
Port maintenance creates a recovery backup before cleanup. Its rotating maintenance backups retain the newest 14 snapshots and up to eight older Sunday snapshots. Backup copies may therefore outlast online records; their expiry depends on successful maintenance and rotation. Separately retained deployment or incident backups are not covered by that automatic rotation and require operational removal. Contact us about removal from retained copies. Collection is for Port functionality, not advertising or cross-app tracking.
Notification retention and removal
3.0 stores necessary encrypted message content and routing/delivery records in a cloud inbox for 30 days from creation and keeps a bounded device cache. Earlier device-only history may be incomplete and is not reconstructed. Clearing notification history or deleting messages hides them from the inbox without clearing website data; deletion markers prevent reappearance during retries, and retained records expire under the retention period. Removing a source can also remove its history. Pairing tickets expire after 180 seconds; GitHub authorization sessions after 15 minutes.
Disconnecting or deleting a workspace disables its local route and queues server revocation if offline. GitHub credentials are removed from the active connector; encrypted credentials may be retained only to retry revocation while GitHub is unavailable. Installation credentials and inactive references may remain for authentication and stale-route protection. Contact us for server-side removal, or revoke the App directly in GitHub settings. Notifications are device-bound; losing the device credential requires reconnecting, not automatic cross-device recovery. Apple accepting a push does not guarantee that iOS displays it. Notification data is not used for advertising, analytics or tracking; message-open state is not sent back to websites by default.
Stored on your device
The app stores workspace metadata (URL, title, UUID, dates and icon filenames) in Application Support. Custom and downloaded icons are stored as local PNG files. Each workspace uses a named WebKit data store that may contain cookies, LocalStorage, IndexedDB and other data created by the website you open.
Network requests
Websites receive the network requests made by their pages and may process cookies, account information and analytics under their own policies. WebHarbor may request a website title and favicon after a successful load. Favicon requests use an isolated session and do not copy your website cookies.
Payments
Permanent Unlock purchases are processed by Apple through StoreKit. WebHarbor does not receive or store your payment details. Purchase entitlement is read from verified Apple transactions and is not written to app metadata, UserDefaults or Keychain.
Deletion
Delete a workspace in the app to remove its metadata, icons and named WebKit data store. Clear Website Data keeps the workspace itself but removes its website data. Removing the app also follows iOS storage rules.
Contact
Questions: henrylidoyle@gmail.com.