diff --git a/android/play-store/review-access.md b/android/play-store/review-access.md index 1a5e895..ec82dcd 100644 --- a/android/play-store/review-access.md +++ b/android/play-store/review-access.md @@ -36,7 +36,10 @@ access field: password manager. - Stable synthetic request URL: create at release time. - Stable synthetic activity URL: create at release time. -- Support contact: `contact@whoneedhelp.com`. +- Public support contact: choose at submission time only after the address has + passed a real inbound-delivery test. `contact@whoneedhelp.com` is currently + verified only as an outbound Brevo sender; DNS inspection found no MX record + proving that replies or new inbound messages reach an operator. ## Copy for Play Console App access @@ -69,7 +72,7 @@ payment, medicine, travel or real-world meeting is required. The credentials are reusable, do not require a one-time code or developer mailbox, and work independently of reviewer location. -Support: contact@whoneedhelp.com +Support: [ENTER A TESTED, MONITORED INBOUND ADDRESS IN PLAY CONSOLE ONLY] ``` After `scripts/prepare-play-review.sh ... --confirm` succeeds, append the exact diff --git a/docs/operations.md b/docs/operations.md index 956d787..6bd2db1 100644 --- a/docs/operations.md +++ b/docs/operations.md @@ -1120,13 +1120,17 @@ The endpoint returns `401` without the exact token, disables response caching, and does not put the credential in a URL. The reporter exports cumulative HTTP request and duration, router exception, database query and duration, WebSocket connection, Oban job, aggregate single-email delivery outcome, VM memory, and -scheduler run-queue metrics. Email metrics distinguish only `ok` and `error` -adapter results and count raised delivery exceptions separately. Cumulative -durations are integer microseconds because the selected reporter's sum -accumulator is integer-based; divide by `1_000_000` in PromQL when seconds are -required. Definitions intentionally have no request path, user, request, -recipient, message, or event-name labels that could create unbounded -cardinality or expose private data. +scheduler run-queue metrics. Email metrics retain the adapter-level `ok`/`error` +counter and exception counter, and also expose the application's fixed +allow-listed delivery purpose together with `ok`, `error`, or `exception`. +Purpose labels are code-defined values such as `auth_login`, +`support_confirmation`, or `content_removal_update`; recipients, subjects, +references, and message bodies are never labels. Cumulative durations are +integer microseconds because the selected reporter's sum accumulator is +integer-based; divide by `1_000_000` in PromQL when seconds are required. +Definitions intentionally have no request path, user, request, recipient, +message, or event-name labels that could create unbounded cardinality or expose +private data. The locked `telemetry_metrics_prometheus_core` reporter aggregates distribution samples only when a scrape occurs. Each application VM therefore diff --git a/docs/public-launch-checklist.md b/docs/public-launch-checklist.md index 7b34923..d7317bb 100644 --- a/docs/public-launch-checklist.md +++ b/docs/public-launch-checklist.md @@ -175,6 +175,11 @@ as forward-only rather than receiving an invented database rollback. approval, and reporting. - [ ] Support, privacy/data, account-deletion, general content-removal, and TAKE IT DOWN submissions reach the correct production operator queues. + A 2026-08-09 run-scoped check proved one authenticated support case and + one authenticated general content-removal notice, then removed only those + exact records. Privacy/data, account deletion, anonymous verification, + and TAKE IT DOWN still require an exact production smoke before this + combined item can be checked. - [ ] Database, application, worker, email, push, backup, and edge monitoring are visible to the responsible operator.