Novolis Docs
novolis-governance / installer-data-lifecycle.md

Installer, data, and Android lifecycle policy

dotnetgovernancenovolis

Applies to every product host in novolis-apps. Authoritative per-app values live in build/apps.json.

Windows (windows-inno)

Required Inno citizenship (enforced by Novolis.Avalonia.Packaging.Inno + apps validators):

RuleRequirement
ElevationPrivilegesRequired=lowest — no admin override path
Install root{localappdata}\Programs\Novolis\<App> — never Program Files
IdentityStable AppId per product across versions and repository moves
UpgradesStable AppId plus UsePreviousAppDir=yes (documented exceptions only)
ProcessesCloseApplications=yes with a filter covering every payload executable
ShortcutsPer-user Start Menu; desktop shortcut opt-in and unchecked by default
Machine scopeNo HKLM, services, scheduled tasks, machine-wide env, or privileged shell extensions
File associationsPer-user only, declared in the manifest, repaired/removed cleanly
UninstallRemoves installer payload and shortcuts; preserves documents, workspaces, saves, settings, and credentials

Payload, user data, cache, crash logs, and credentials must use separate roots. Uninstall must not recursively delete %LOCALAPPDATA%\Novolis.

Data roots (Windows)

KindLocation
Installed binaries%LOCALAPPDATA%\Programs\Novolis\<App>
Persistent app data%LOCALAPPDATA%\Novolis\<app-key>\
Cache / logs%LOCALAPPDATA%\Novolis\<app-key>\cache (and sibling folders)
CredentialsProduct-scoped Windows Credential Manager namespace
User documentsUser-selected paths only — apps do not silently copy whole repositories into app data

Local debugging follows the same data rules even when a platform is not in ship.

Android (android-apk)

RuleRequirement
DocumentsSystem picker / SAF for user-selected files; no broad shared-storage permissions
App stateApp-private FilesDir / cache for tokens, temp files, generated artifacts
NetworkDeclare INTERNET only for implemented features; usesCleartextTraffic=false
BackupDefault allowBackup=false for credential/token/offline-viewer apps
IdentityStable applicationId + persistent signing key when available (adhoc keys are for sideload testing; new key = new app)
VersioningMonotonic versionCode derived from release metadata (NovolisAndroidVersionCode)

Permission allowlists, network policy, and signing secret keys are declared per app in build/apps.json. Validators fail on undeclared permissions and backup/cleartext violations.

Privacy inventory

Every shipped app maintains a short privacy/data inventory (permissions, network destinations, storage roots, backup, deletion). Template: novolis-apps/docs/privacy-template.md.

Verification

pwsh -File d:\novolis\novolis-apps\scripts\verify-installer-policy.ps1
pwsh -File d:\novolis\novolis-apps\scripts\smoke-installer-script.ps1
pwsh -File d:\novolis\novolis-apps\scripts\verify-android-policy.ps1