diff --git a/android/play-store/release-checklist.md b/android/play-store/release-checklist.md index 9fc8429..d2b75db 100644 --- a/android/play-store/release-checklist.md +++ b/android/play-store/release-checklist.md @@ -50,7 +50,8 @@ - [ ] Privacy policy URL. - [ ] Ads declaration: no ads. -- [ ] App access instructions tested from a clean install. +- [ ] Both App access accounts and both sides of the reviewer instructions + tested from a clean Play-delivered install. - [ ] Target audience/adult-only positioning confirmed. - [ ] Content rating questionnaire completed truthfully. - [ ] Data Safety worksheet reconciled with the final dependency report. diff --git a/android/play-store/review-access.md b/android/play-store/review-access.md index 53f339e..1a5e895 100644 --- a/android/play-store/review-access.md +++ b/android/play-store/review-access.md @@ -11,34 +11,37 @@ real requester or sharing real personal/medical information. reporting, and Account deletion pages are available without a reviewer account. Request, activity, category-proposal, profile, notification, and moderation LiveViews require authentication. -2. For authenticated functionality, use the dedicated production reviewer - account prepared immediately before submission. -3. Expand **Use a password instead**, then enter the dedicated reviewer email - and password supplied in Play Console. Do not use an email link or Google - sign-in for review: the supplied password must remain reusable, always - available, and independent of a developer mailbox or one-time code. +2. For authenticated functionality, use the two dedicated production review + accounts prepared immediately before submission. The requester/organizer + account exposes one side of the flows; the helper/participant account exposes + the other. +3. Expand **Use a password instead**, then enter one of the dedicated emails and + passwords supplied in Play Console. Do not use an email link or Google sign-in + for review: both supplied passwords must remain reusable, always available, + and independent of a developer mailbox or one-time code. 4. Use only the pre-created synthetic requests and activity. Their titles must start with `Play review`. -5. A second synthetic account must already be assigned as the counterpart so the - reviewer can inspect chat, optional tracking controls, handover, withdrawal, - reviews, blocking, reporting, support, privacy, and account deletion. +5. Sign out and use the helper/participant credentials when checking acceptance, + participant state, the counterpart chat view, optional tracking, handover, + withdrawal, reviews, blocking, and reporting. ## Submission-time values Do not store credentials here or in Git. Put them only in Play Console’s app access field: -- Reviewer email: create at release time. -- Reviewer password: create at release time and store only in Play Console and - the operator-controlled password manager. +- Requester/organizer reviewer email and password: create at release time. +- Helper/participant reviewer email and password: create at release time. +- Store both credential pairs only in Play Console and the operator-controlled + password manager. - Stable synthetic request URL: create at release time. - Stable synthetic activity URL: create at release time. - Support contact: `contact@whoneedhelp.com`. ## Copy for Play Console App access -Use the following English instructions only after replacing both bracketed -values with the dedicated production reviewer credentials and after testing the +Use the following English instructions only after replacing all four bracketed +values with the two dedicated production credential pairs and after testing the exact text from a clean Play-delivered installation. Never commit the completed version. @@ -47,14 +50,19 @@ This app has public pages and authenticated product flows. 1. Open the app and tap Log in. 2. Expand "Use a password instead". -3. Enter the reusable reviewer credentials below. -4. After signing in, open Requests to inspect the pre-created synthetic help - request and its private chat, location controls, handover and reporting. -5. Open Activities to inspect the pre-created synthetic cinema activity and - participation controls. +3. First enter the requester/organizer credentials below. +4. Open Requests and Activities to inspect the pre-created synthetic records, + requester/organizer controls, chat, location controls and reporting. +5. Sign out, return to Log in, expand "Use a password instead", and enter the + helper/participant credentials. +6. Open the same synthetic records to inspect the counterpart views, private + chat, acceptance/participation, tracking, handover, withdrawal, reviews, + blocking and reporting. -Reviewer email: [ENTER IN PLAY CONSOLE ONLY] -Reviewer password: [ENTER IN PLAY CONSOLE ONLY] +Requester/organizer email: [ENTER IN PLAY CONSOLE ONLY] +Requester/organizer password: [ENTER IN PLAY CONSOLE ONLY] +Helper/participant email: [ENTER IN PLAY CONSOLE ONLY] +Helper/participant password: [ENTER IN PLAY CONSOLE ONLY] All records whose titles start with "Play review" are synthetic. No purchase, payment, medicine, travel or real-world meeting is required. The credentials @@ -73,12 +81,12 @@ test, localhost or expiring sign-in URL. - Test the exact instructions in a clean Android install from the Play track. - Confirm they do not depend on a developer browser session, VPN, localhost, expiring fixture, or test/staging domain. -- Confirm the reviewer account is not a moderator or administrator. +- Confirm neither review account has any staff role. - Confirm all data is synthetic and no real user can be messaged or located. -- Confirm the password works from a clean Play-delivered install without a +- Confirm both passwords work from a clean Play-delivered install without a second factor, one-time code, developer browser session, or location gate. - Confirm the final Play Console instructions are in English and every route - they mention is reachable by the reviewer account. + they mention is reachable from the appropriate review account. After both dedicated accounts have registered, confirmed their email, and set their fixed passwords through the production UI, first run the read-only diff --git a/docs/google-play-pre-upload-audit-2026-08-03.md b/docs/google-play-pre-upload-audit-2026-08-03.md index 07212b3..601e76b 100644 --- a/docs/google-play-pre-upload-audit-2026-08-03.md +++ b/docs/google-play-pre-upload-audit-2026-08-03.md @@ -44,13 +44,13 @@ require Play Console. It contains no account credentials or signing keys. ## Required before Play review -- Create a dedicated non-staff production reviewer account with a fixed, - reusable password. Put its credentials only in Play Console App access and - the operator-controlled password manager. -- Register and confirm two dedicated non-staff accounts with fixed passwords, - then create their stable synthetic `Play review` request and activity using - `scripts/prepare-play-review.sh`. Verify every reviewer instruction from a - clean installation. +- Register and confirm two dedicated non-staff production review accounts with + fixed, reusable passwords: one requester/organizer and one + helper/participant. Put both credential pairs only in Play Console App access + and the operator-controlled password manager. +- Create their stable synthetic `Play review` request and activity using + `scripts/prepare-play-review.sh`. Verify both roles and every reviewer + instruction from a clean Play-delivered installation. - Complete App content: App access, Ads, Content rating, Target audience, News-app declaration, Data Safety, background-location declaration if Play presents it, and the account-deletion URL.