Prepare Google Play release materials
This commit is contained in:
parent
c863b47ed1
commit
3f67df1733
72
android/play-store/closed-test.md
Normal file
72
android/play-store/closed-test.md
Normal file
|
|
@ -0,0 +1,72 @@
|
||||||
|
# Google Play closed-test runbook
|
||||||
|
|
||||||
|
The developer account is a new personal account. Google currently requires at
|
||||||
|
least 12 testers to remain opted in to the closed test for 14 continuous days
|
||||||
|
before production access can be requested.
|
||||||
|
|
||||||
|
## Before inviting testers
|
||||||
|
|
||||||
|
1. Complete Play developer identity and contact verification.
|
||||||
|
2. Create the Play app with package `org.whoneedhelp.mobile`.
|
||||||
|
3. Enable Play App Signing.
|
||||||
|
4. Add the Play App Signing SHA-256 fingerprint to production App Links and
|
||||||
|
Google/Firebase configuration, then verify the production association files.
|
||||||
|
5. Upload the source-bound production AAB.
|
||||||
|
6. Complete the store listing, App content, privacy, Data Safety, content rating,
|
||||||
|
ads, target-audience, and access declarations.
|
||||||
|
7. Start with an internal test on the owner’s device, then promote the verified
|
||||||
|
build to the closed track.
|
||||||
|
|
||||||
|
## Tester cohort
|
||||||
|
|
||||||
|
- Recruit at least 12 real people with Google or Google Workspace accounts.
|
||||||
|
- Keep at least 14 opted in so that one accidental opt-out does not reset the
|
||||||
|
minimum cohort; this is an operational buffer, not a Google requirement.
|
||||||
|
- Do not publish tester email addresses in the repository.
|
||||||
|
- Give every tester the Play opt-in link and state clearly that they must remain
|
||||||
|
opted in for at least 14 continuous days.
|
||||||
|
- Record opt-in date, device/Android version, completed scenarios, and feedback
|
||||||
|
in a private operational sheet.
|
||||||
|
|
||||||
|
## Required scenarios for each cohort
|
||||||
|
|
||||||
|
- Install and open from the Play closed-test listing.
|
||||||
|
- Register or sign in with Google/email.
|
||||||
|
- Review privacy and location controls.
|
||||||
|
- Create or browse a request without exposing an exact public address.
|
||||||
|
- Accept/withdraw from a safe test request using two separate accounts.
|
||||||
|
- Send and receive private messages and push notifications.
|
||||||
|
- Start and stop live location on a clearly labelled synthetic test assignment.
|
||||||
|
- Request to join and withdraw from an activity.
|
||||||
|
- Block/report a synthetic account and locate support/account deletion.
|
||||||
|
- Confirm that rotation, background/foreground, offline/reconnect, and process
|
||||||
|
recreation do not lose critical state.
|
||||||
|
|
||||||
|
Never ask testers to simulate a real emergency, disclose prescriptions or
|
||||||
|
medical details, exchange money, or travel to meet an unknown person.
|
||||||
|
|
||||||
|
## Feedback questions
|
||||||
|
|
||||||
|
1. What task did you try to complete?
|
||||||
|
2. At which screen did you hesitate or stop?
|
||||||
|
3. Was approximate versus exact location visibility understandable?
|
||||||
|
4. Did notifications arrive, and did they open the expected screen?
|
||||||
|
5. Could you tell when live location was active and stop it?
|
||||||
|
6. Did leaving a request/activity immediately update your participation state?
|
||||||
|
7. What device and Android version did you use?
|
||||||
|
8. Did you encounter a crash, blank screen, inaccessible control, or misleading
|
||||||
|
status?
|
||||||
|
|
||||||
|
## Evidence for production-access application
|
||||||
|
|
||||||
|
- Closed-track name and release/version code.
|
||||||
|
- Dates covering at least the required continuous 14-day interval.
|
||||||
|
- Opted-in tester count shown by Play Console.
|
||||||
|
- Device/Android coverage.
|
||||||
|
- Issues found, fixes made, and how fixes were re-tested.
|
||||||
|
- Summary of feedback and why the app is ready for production.
|
||||||
|
|
||||||
|
Official references:
|
||||||
|
|
||||||
|
- https://support.google.com/googleplay/android-developer/answer/14151465
|
||||||
|
- https://support.google.com/googleplay/android-developer/answer/9845334
|
||||||
92
android/play-store/data-safety.md
Normal file
92
android/play-store/data-safety.md
Normal file
|
|
@ -0,0 +1,92 @@
|
||||||
|
# Google Play Data Safety worksheet
|
||||||
|
|
||||||
|
This is a source-backed worksheet for the current Android build, not a submitted
|
||||||
|
Play Console declaration. Re-check it against the exact release AAB and the
|
||||||
|
current Play form immediately before submission.
|
||||||
|
|
||||||
|
## Form-level answers
|
||||||
|
|
||||||
|
- Does the app collect or share required user data types? **Yes, collects.**
|
||||||
|
- Is all user data encrypted in transit? **Yes.** Production app traffic uses
|
||||||
|
HTTPS; Firebase Cloud Messaging also uses encrypted transport.
|
||||||
|
- Can users request deletion? **Yes.**
|
||||||
|
- In-app path: account menu → account settings → delete-account request.
|
||||||
|
- External URL: `https://whoneedhelp.com/account/delete`.
|
||||||
|
- Does the app independently verify its security practices against a qualifying
|
||||||
|
standard? **No declaration.** Automated security checks are not an
|
||||||
|
independent certification.
|
||||||
|
- Does the app contain ads? **No.**
|
||||||
|
|
||||||
|
## Collected data types
|
||||||
|
|
||||||
|
| Play data type | Required or optional | Purposes | Current behavior/evidence |
|
||||||
|
| --- | --- | --- | --- |
|
||||||
|
| Personal info — Name | Required for an account | App functionality; account management; fraud prevention/security | Display name and profile are stored by the account system. |
|
||||||
|
| Personal info — Email address | Required for email accounts; supplied by Google for Google sign-in | App functionality; account management; security; support communications | Used for authentication, account notices, and support. |
|
||||||
|
| Personal info — User IDs | Required | App functionality; account management; fraud prevention/security | Internal account ID and connected identity identifiers. Provider access tokens are not persisted. |
|
||||||
|
| Personal info — Other info | Optional | App functionality; account management | Optional social-profile links and profile settings. |
|
||||||
|
| Location — Approximate location | Optional | App functionality; fraud prevention/security | Public request/activity location is rounded or hidden according to the user’s visibility choice. |
|
||||||
|
| Location — Precise location | Optional | App functionality; fraud prevention/security | Exact request/activity meeting point and opt-in live tracking. Exact points are restricted to relevant approved people. The current raw tracking point is deleted when sharing stops; derived evidence can remain. |
|
||||||
|
| Health and fitness — Health info | Optional, user-provided | App functionality | A medicine-help request can inherently reveal health-related context even though the UI prohibits prescriptions and unnecessary medical information. |
|
||||||
|
| App activity — App interactions | Required while using the service | App functionality; fraud prevention/security | Requests, matches, handovers, participation decisions, reviews, reports, moderation state, and safety evidence. |
|
||||||
|
| App activity — In-app search history | Optional; processed transiently | App functionality | Category, area, and map-viewport filters are sent to the server to return results and are not intentionally stored as a search-history profile. Select “processed ephemerally” if the current Play form offers it. |
|
||||||
|
| User-generated content — Other user-generated content | Optional | App functionality; fraud prevention/security; support | Request/activity descriptions, pickup instructions, private chat, reviews, category proposals, reports, and support messages. |
|
||||||
|
| Device or other IDs | Automatic for networked app functions | App functionality; fraud prevention/security | Firebase installation ID/FCM registration token, server session/security identifiers, and network identifiers exposed to the configured map-tile provider. No Google Analytics or Crashlytics SDK is included. |
|
||||||
|
|
||||||
|
## Data not collected by the current product
|
||||||
|
|
||||||
|
- Payment-card, bank-account, purchase-history, or payment-processing data.
|
||||||
|
Reimbursement happens outside the platform and sensitive payment data is
|
||||||
|
prohibited in messages.
|
||||||
|
- Contacts/address book.
|
||||||
|
- Email-message or mailbox content. The user’s authentication/contact address is
|
||||||
|
declared under **Personal info — Email address**; the app does not read or
|
||||||
|
import email messages.
|
||||||
|
- Photos, videos, audio, files, or documents.
|
||||||
|
- Advertising data.
|
||||||
|
- Google Analytics or Firebase Analytics events.
|
||||||
|
- Crashlytics crash reports.
|
||||||
|
|
||||||
|
## Sharing assessment
|
||||||
|
|
||||||
|
The current implementation sends data to:
|
||||||
|
|
||||||
|
1. The Who Need Help production server and its contracted infrastructure/service
|
||||||
|
providers to operate the product.
|
||||||
|
2. Google Firebase Cloud Messaging to deliver notifications.
|
||||||
|
3. The configured map-tile provider receives the client network request,
|
||||||
|
including its network identifier and requested tile coordinates.
|
||||||
|
4. Other users only through explicit product actions and visibility rules, such
|
||||||
|
as publishing an approximate area, accepting a match, approving an activity
|
||||||
|
participant, sending a message, or starting live sharing.
|
||||||
|
|
||||||
|
Google Play excludes some service-provider transfers and user-initiated sharing
|
||||||
|
from the “shared” declaration. The production map-tile provider and its
|
||||||
|
contractual/service-provider status are not yet confirmed, so the exact
|
||||||
|
top-level “shared” answer is currently **unknown**. Do not submit the form until
|
||||||
|
the final provider, its terms/data-processing role, and the exact release
|
||||||
|
network trace have been reviewed against the definitions shown by the current
|
||||||
|
Play form. If no exemption applies, declare the applicable device/network data
|
||||||
|
as shared.
|
||||||
|
|
||||||
|
## Source checks before every release
|
||||||
|
|
||||||
|
1. Compare this worksheet with `android/app/build.gradle.kts` and the resolved
|
||||||
|
release dependency report.
|
||||||
|
2. Confirm that Analytics, Crashlytics, ads, and delivery-metrics export remain
|
||||||
|
absent or update the declaration.
|
||||||
|
3. Confirm the final map-tile provider, provider agreement, request metadata,
|
||||||
|
and Play sharing classification.
|
||||||
|
4. Compare with `/privacy`, `/account/delete`, Android manifest permissions, and
|
||||||
|
the live-location prominent disclosure.
|
||||||
|
5. Confirm the external deletion URL loads without authentication and submits a
|
||||||
|
deletion request.
|
||||||
|
6. Update the worksheet if media uploads, avatars, payments, analytics, or any
|
||||||
|
new SDK is introduced.
|
||||||
|
|
||||||
|
## Official references
|
||||||
|
|
||||||
|
- https://support.google.com/googleplay/android-developer/answer/10787469
|
||||||
|
- https://support.google.com/googleplay/android-developer/answer/13327111
|
||||||
|
- https://firebase.google.com/docs/android/play-data-disclosure
|
||||||
|
- https://firebase.google.com/support/privacy/
|
||||||
79
android/play-store/release-checklist.md
Normal file
79
android/play-store/release-checklist.md
Normal file
|
|
@ -0,0 +1,79 @@
|
||||||
|
# Google Play release checklist
|
||||||
|
|
||||||
|
## External account gate
|
||||||
|
|
||||||
|
- [ ] Google Play developer identity verification approved.
|
||||||
|
- [ ] Contact phone verification completed.
|
||||||
|
- [ ] Play Console enables **Create app**.
|
||||||
|
|
||||||
|
## App identity and signing
|
||||||
|
|
||||||
|
- [ ] Create Android app `Who Need Help` with package
|
||||||
|
`org.whoneedhelp.mobile`.
|
||||||
|
- [ ] Default language: English (United States).
|
||||||
|
- [ ] App: not a game; free; no ads.
|
||||||
|
- [ ] Accept Play App Signing.
|
||||||
|
- [ ] Record upload-certificate SHA-256 and Play App Signing SHA-256 separately.
|
||||||
|
- [ ] Add the Play App Signing SHA-256 to production Google/Firebase Android
|
||||||
|
configuration.
|
||||||
|
- [ ] Publish and verify
|
||||||
|
`https://whoneedhelp.com/.well-known/assetlinks.json` for the Play
|
||||||
|
certificate.
|
||||||
|
|
||||||
|
## Build
|
||||||
|
|
||||||
|
- [ ] Build from the exact committed candidate with the production checkout’s
|
||||||
|
single `.env`.
|
||||||
|
- [ ] Run `scripts/android-release-build.sh`.
|
||||||
|
- [ ] Verify source fingerprint, signing certificate, bundletool validation,
|
||||||
|
lint, package name, version code/name, target SDK, and production origin.
|
||||||
|
- [ ] Install the universal APK generated from the same AAB on a clean physical
|
||||||
|
phone and run the release smoke test.
|
||||||
|
- [ ] Upload the source-bound AAB first to internal testing.
|
||||||
|
|
||||||
|
## Store presence
|
||||||
|
|
||||||
|
- [x] 512×512 Play icon prepared.
|
||||||
|
- [x] 1024×500 24-bit PNG feature graphic prepared.
|
||||||
|
- [x] Four current 1080×1920 physical-phone screenshots captured and reviewed.
|
||||||
|
- [x] English, Ukrainian, and Russian listing copy prepared.
|
||||||
|
- [x] Alt-text copy (≤140 characters) prepared in `store-assets/README.md`.
|
||||||
|
- [ ] Enter the prepared alt text when the assets are uploaded in Play Console.
|
||||||
|
- [ ] Choose category/tags in the current Console options.
|
||||||
|
|
||||||
|
## App content
|
||||||
|
|
||||||
|
- [ ] Privacy policy URL.
|
||||||
|
- [ ] Ads declaration: no ads.
|
||||||
|
- [ ] App access instructions tested from a clean install.
|
||||||
|
- [ ] Target audience/adult-only positioning confirmed.
|
||||||
|
- [ ] Content rating questionnaire completed truthfully.
|
||||||
|
- [ ] Data Safety worksheet reconciled with the final dependency report.
|
||||||
|
- [ ] Account deletion questions and external URL completed.
|
||||||
|
- [ ] Government/news/financial/health declarations answered from actual app
|
||||||
|
behavior; do not describe the app as a medical service.
|
||||||
|
- [ ] Foreground-service/location declarations completed if Play Console asks.
|
||||||
|
|
||||||
|
## Testing
|
||||||
|
|
||||||
|
- [ ] Internal track smoke test passed.
|
||||||
|
- [ ] Closed track created and opt-in link tested.
|
||||||
|
- [ ] At least 12 testers continuously opted in for 14 days.
|
||||||
|
- [ ] Tester feedback and fixes documented.
|
||||||
|
- [ ] Production-access questionnaire completed from actual evidence.
|
||||||
|
|
||||||
|
## Publishing
|
||||||
|
|
||||||
|
- [ ] Managed publishing enabled if desired.
|
||||||
|
- [ ] Countries/regions and support contact reviewed.
|
||||||
|
- [ ] Production submission reviewed for accidental test URLs or credentials.
|
||||||
|
- [ ] Rollback and support/incident response are ready.
|
||||||
|
|
||||||
|
Official references:
|
||||||
|
|
||||||
|
- https://support.google.com/googleplay/android-developer/answer/9859152
|
||||||
|
- https://support.google.com/googleplay/android-developer/answer/9866151
|
||||||
|
- https://support.google.com/googleplay/android-developer/answer/9859455
|
||||||
|
- https://support.google.com/googleplay/android-developer/answer/10787469
|
||||||
|
- https://support.google.com/googleplay/android-developer/answer/13327111
|
||||||
|
- https://support.google.com/googleplay/android-developer/answer/14151465
|
||||||
41
android/play-store/review-access.md
Normal file
41
android/play-store/review-access.md
Normal file
|
|
@ -0,0 +1,41 @@
|
||||||
|
# Google Play review access
|
||||||
|
|
||||||
|
The app has public pages, email/passwordless authentication, and Google sign-in.
|
||||||
|
Reviewers must be able to inspect restricted functionality without contacting a
|
||||||
|
real requester or sharing real personal/medical information.
|
||||||
|
|
||||||
|
## Recommended reviewer instructions
|
||||||
|
|
||||||
|
1. Open the app. The product home, Safety, Privacy, Terms, Support, content
|
||||||
|
reporting, and Account deletion pages are available without a reviewer
|
||||||
|
account. Request, activity, category-proposal, profile, notification, and
|
||||||
|
moderation LiveViews require authentication.
|
||||||
|
2. For authenticated functionality, use the dedicated production reviewer
|
||||||
|
account prepared immediately before submission.
|
||||||
|
3. Enter the reviewer email on the Log in screen and use the current one-time
|
||||||
|
sign-in link delivered to the reviewer mailbox, or use the supplied password
|
||||||
|
if Play Console’s access-instructions field requires fixed credentials.
|
||||||
|
4. Use only the pre-created synthetic requests and activity. Their titles must
|
||||||
|
start with `Play review`.
|
||||||
|
5. A second synthetic account must already be assigned as the counterpart so the
|
||||||
|
reviewer can inspect chat, optional tracking controls, handover, withdrawal,
|
||||||
|
reviews, blocking, reporting, support, privacy, and account deletion.
|
||||||
|
|
||||||
|
## Submission-time values
|
||||||
|
|
||||||
|
Do not store credentials here or in Git. Put them only in Play Console’s app
|
||||||
|
access field:
|
||||||
|
|
||||||
|
- Reviewer email: create at release time.
|
||||||
|
- Reviewer password or mailbox access instructions: create at release time.
|
||||||
|
- Stable synthetic request URL: create at release time.
|
||||||
|
- Stable synthetic activity URL: create at release time.
|
||||||
|
- Support contact: `contact@whoneedhelp.com`.
|
||||||
|
|
||||||
|
## Verification before submission
|
||||||
|
|
||||||
|
- Test the exact instructions in a clean Android install from the Play track.
|
||||||
|
- Confirm they do not depend on a developer browser session, VPN, localhost,
|
||||||
|
expiring fixture, or test/staging domain.
|
||||||
|
- Confirm the reviewer account is not a moderator or administrator.
|
||||||
|
- Confirm all data is synthetic and no real user can be messaged or located.
|
||||||
48
android/play-store/store-listing-en-US.md
Normal file
48
android/play-store/store-listing-en-US.md
Normal file
|
|
@ -0,0 +1,48 @@
|
||||||
|
# Google Play listing — English (United States)
|
||||||
|
|
||||||
|
## App name
|
||||||
|
|
||||||
|
Who Need Help
|
||||||
|
|
||||||
|
## Short description
|
||||||
|
|
||||||
|
Find nearby voluntary help for medicine pickup and urgent everyday needs
|
||||||
|
|
||||||
|
## Full description
|
||||||
|
|
||||||
|
Who Need Help connects people who need prompt, non-emergency assistance with nearby volunteers.
|
||||||
|
|
||||||
|
Medicine pickup is the first priority. You can ask someone nearby to collect medicine that is already purchased or reserved. If a volunteer agrees to purchase an eligible item, the people involved arrange the lawful purchase and any reimbursement directly in their private chat. Who Need Help does not prescribe, recommend, or sell medicine, process payments, or support controlled substances.
|
||||||
|
|
||||||
|
You can also ask for roadside help, such as fuel or wheel assistance, and find people for approved community activities.
|
||||||
|
|
||||||
|
Key features:
|
||||||
|
|
||||||
|
- Create a categorized request and show only an approximate public area, or hide the map point until you approve a participant.
|
||||||
|
- Accept a request and coordinate in private real-time chat.
|
||||||
|
- Share live location only when you choose, with a persistent Android notification and a visible stop action.
|
||||||
|
- Confirm a handover with a one-time code and completion from both people.
|
||||||
|
- Join moderated social activities and use participant group chat after approval.
|
||||||
|
- Build trust through completed-help history and double-blind reviews.
|
||||||
|
- Block users, report safety concerns, and contact support from the app.
|
||||||
|
|
||||||
|
Who Need Help is not an emergency, medical, pharmacy, taxi, or delivery service. If anyone is in immediate danger, contact local emergency services. Never share passwords, payment-card data, access codes, prescriptions, or unnecessary medical information.
|
||||||
|
|
||||||
|
Privacy controls limit public location precision. Exact request and activity meeting points are available only to the relevant approved people. Live tracking is optional, and the current raw position is deleted when sharing stops; limited summary evidence may be retained for safety and abuse prevention as explained in the Privacy Policy.
|
||||||
|
|
||||||
|
## Suggested category
|
||||||
|
|
||||||
|
Social
|
||||||
|
|
||||||
|
## Suggested tags
|
||||||
|
|
||||||
|
- Volunteering
|
||||||
|
- Local community
|
||||||
|
- Social
|
||||||
|
|
||||||
|
## Support and policy URLs
|
||||||
|
|
||||||
|
- Website: https://whoneedhelp.com/
|
||||||
|
- Support: https://whoneedhelp.com/support
|
||||||
|
- Privacy policy: https://whoneedhelp.com/privacy
|
||||||
|
- Account deletion: https://whoneedhelp.com/account/delete
|
||||||
38
android/play-store/store-listing-ru-RU.md
Normal file
38
android/play-store/store-listing-ru-RU.md
Normal file
|
|
@ -0,0 +1,38 @@
|
||||||
|
# Google Play — русский
|
||||||
|
|
||||||
|
## Название
|
||||||
|
|
||||||
|
Who Need Help
|
||||||
|
|
||||||
|
## Краткое описание
|
||||||
|
|
||||||
|
Добровольная помощь рядом: лекарства и срочные бытовые задачи
|
||||||
|
|
||||||
|
## Полное описание
|
||||||
|
|
||||||
|
Who Need Help помогает людям, которым срочно нужна неэкстренная помощь, связаться с волонтёрами поблизости.
|
||||||
|
|
||||||
|
В первую очередь сервис предназначен для доставки лекарств. Можно попросить забрать уже купленное или зарезервированное лекарство. Если волонтёр согласен сам купить разрешённый товар, участники самостоятельно договариваются о законной покупке и возмещении расходов в приватном чате. Who Need Help не назначает, не рекомендует и не продаёт лекарства, не обрабатывает платежи и не допускает запросы на контролируемые вещества.
|
||||||
|
|
||||||
|
Также можно попросить о помощи в дороге, например с топливом или колесом, и найти людей для одобренных совместных мероприятий.
|
||||||
|
|
||||||
|
Основные возможности:
|
||||||
|
|
||||||
|
- Создание заявки по категории с примерной публичной областью или скрытой до одобрения точкой.
|
||||||
|
- Принятие заявки и координация в приватном чате в реальном времени.
|
||||||
|
- Добровольная трансляция геопозиции с постоянным уведомлением Android и заметной кнопкой остановки.
|
||||||
|
- Подтверждение передачи одноразовым кодом и завершение обеими сторонами.
|
||||||
|
- Участие в модерируемых мероприятиях и групповом чате после одобрения.
|
||||||
|
- История выполненной помощи и взаимные скрытые до завершения отзывы.
|
||||||
|
- Блокировка пользователей, жалобы на проблемы безопасности и обращение в поддержку.
|
||||||
|
|
||||||
|
Who Need Help не является экстренной, медицинской, аптечной, такси- или курьерской службой. При непосредственной опасности обратитесь в местные экстренные службы. Не публикуйте пароли, данные банковских карт, коды доступа, рецепты и лишнюю медицинскую информацию.
|
||||||
|
|
||||||
|
Настройки конфиденциальности ограничивают точность публичной карты. Точные точки заявок и мероприятий доступны только соответствующим одобренным участникам. Трансляция геопозиции необязательна; текущая точная позиция удаляется после остановки. Ограниченные сводные признаки могут храниться для безопасности и предотвращения злоупотреблений в соответствии с Политикой конфиденциальности.
|
||||||
|
|
||||||
|
## Ссылки
|
||||||
|
|
||||||
|
- Сайт: https://whoneedhelp.com/
|
||||||
|
- Поддержка: https://whoneedhelp.com/support
|
||||||
|
- Политика конфиденциальности: https://whoneedhelp.com/privacy
|
||||||
|
- Удаление аккаунта: https://whoneedhelp.com/account/delete
|
||||||
38
android/play-store/store-listing-uk-UA.md
Normal file
38
android/play-store/store-listing-uk-UA.md
Normal file
|
|
@ -0,0 +1,38 @@
|
||||||
|
# Google Play — українська
|
||||||
|
|
||||||
|
## Назва
|
||||||
|
|
||||||
|
Who Need Help
|
||||||
|
|
||||||
|
## Короткий опис
|
||||||
|
|
||||||
|
Добровільна допомога поруч: ліки та термінові побутові завдання
|
||||||
|
|
||||||
|
## Повний опис
|
||||||
|
|
||||||
|
Who Need Help допомагає людям, яким терміново потрібна неекстрена допомога, зв’язатися з волонтерами поблизу.
|
||||||
|
|
||||||
|
Насамперед сервіс призначений для доставки ліків. Можна попросити забрати вже придбані або зарезервовані ліки. Якщо волонтер погоджується сам придбати дозволений товар, учасники самостійно домовляються про законну покупку та відшкодування витрат у приватному чаті. Who Need Help не призначає, не рекомендує і не продає ліки, не обробляє платежі та не дозволяє запити на контрольовані речовини.
|
||||||
|
|
||||||
|
Також можна попросити про допомогу в дорозі, наприклад із пальним або колесом, і знайти людей для схвалених спільних заходів.
|
||||||
|
|
||||||
|
Основні можливості:
|
||||||
|
|
||||||
|
- Створення заявки за категорією з приблизною публічною областю або прихованою до схвалення точкою.
|
||||||
|
- Прийняття заявки та координація у приватному чаті в реальному часі.
|
||||||
|
- Добровільна трансляція геопозиції з постійним сповіщенням Android і помітною дією зупинки.
|
||||||
|
- Підтвердження передачі одноразовим кодом і завершення обома сторонами.
|
||||||
|
- Участь у модерованих заходах і груповому чаті після схвалення.
|
||||||
|
- Історія виконаної допомоги та взаємні відгуки, приховані до завершення.
|
||||||
|
- Блокування користувачів, повідомлення про загрози безпеці та звернення до підтримки.
|
||||||
|
|
||||||
|
Who Need Help не є екстреною, медичною, аптечною, таксі- або кур’єрською службою. За безпосередньої небезпеки зверніться до місцевих екстрених служб. Не публікуйте паролі, дані банківських карток, коди доступу, рецепти та зайву медичну інформацію.
|
||||||
|
|
||||||
|
Налаштування конфіденційності обмежують точність публічної карти. Точні точки заявок і заходів доступні лише відповідним схваленим учасникам. Трансляція геопозиції необов’язкова; поточна точна позиція видаляється після зупинки. Обмежені зведені ознаки можуть зберігатися для безпеки та запобігання зловживанням відповідно до Політики конфіденційності.
|
||||||
|
|
||||||
|
## Посилання
|
||||||
|
|
||||||
|
- Сайт: https://whoneedhelp.com/
|
||||||
|
- Підтримка: https://whoneedhelp.com/support
|
||||||
|
- Політика конфіденційності: https://whoneedhelp.com/privacy
|
||||||
|
- Видалення облікового запису: https://whoneedhelp.com/account/delete
|
||||||
48
android/store-assets/README.md
Normal file
48
android/store-assets/README.md
Normal file
|
|
@ -0,0 +1,48 @@
|
||||||
|
# Google Play graphic assets
|
||||||
|
|
||||||
|
## Prepared assets
|
||||||
|
|
||||||
|
- `icon-512.png` — 512×512 RGBA Play icon, below the 1 MB limit.
|
||||||
|
- `feature-graphic.svg` — editable deterministic source.
|
||||||
|
- `feature-graphic-1024x500.png` — required 1024×500 24-bit RGB feature
|
||||||
|
graphic without alpha.
|
||||||
|
|
||||||
|
The feature graphic intentionally contains no localized text, ranking, price,
|
||||||
|
store badge, device frame, or third-party mark.
|
||||||
|
|
||||||
|
Suggested alt text:
|
||||||
|
|
||||||
|
> Two nearby people connected by a dotted route around the Who Need Help
|
||||||
|
> location mark.
|
||||||
|
|
||||||
|
## Screenshots
|
||||||
|
|
||||||
|
The four files in `screenshots/phone/` were captured from the development
|
||||||
|
Android client on a physical 1220×2712 device and cropped without stretching to
|
||||||
|
1080×1920. They contain only public examples or synthetic E2E data:
|
||||||
|
|
||||||
|
1. `01-home.png` — public product explanation and example medicine request.
|
||||||
|
2. `02-discovery.png` — authenticated request discovery and filters.
|
||||||
|
3. `03-private-request.png` — completed synthetic request, double-blind review,
|
||||||
|
and approximate request area.
|
||||||
|
4. `04-activity.png` — approved synthetic group chat and exact meeting point
|
||||||
|
disclosed to an approved participant.
|
||||||
|
|
||||||
|
The uncropped ADB source captures are intentionally kept outside Git. No real
|
||||||
|
email, real user message, notification, medical detail, or exact real-user
|
||||||
|
location is present in the approved outputs.
|
||||||
|
|
||||||
|
These screenshots remain valid only while the release UI matches the captured
|
||||||
|
development build. Recapture and re-review them after any relevant UI, copy,
|
||||||
|
privacy, or map behavior change.
|
||||||
|
|
||||||
|
Suggested English alt text:
|
||||||
|
|
||||||
|
1. `Who Need Help home screen explaining nearby voluntary assistance.`
|
||||||
|
2. `Nearby help request discovery with category, urgency, and area filters.`
|
||||||
|
3. `Completed synthetic request with double-blind review and approximate map area.`
|
||||||
|
4. `Approved synthetic activity group chat with its disclosed meeting point.`
|
||||||
|
|
||||||
|
Official asset requirements:
|
||||||
|
|
||||||
|
- https://support.google.com/googleplay/android-developer/answer/9866151
|
||||||
BIN
android/store-assets/feature-graphic-1024x500.png
Normal file
BIN
android/store-assets/feature-graphic-1024x500.png
Normal file
Binary file not shown.
|
After Width: | Height: | Size: 272 KiB |
72
android/store-assets/feature-graphic.svg
Normal file
72
android/store-assets/feature-graphic.svg
Normal file
|
|
@ -0,0 +1,72 @@
|
||||||
|
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 1024 500" role="img" aria-labelledby="title desc">
|
||||||
|
<title id="title">Who Need Help feature graphic</title>
|
||||||
|
<desc id="desc">Two nearby people connected by a safe route around the Who Need Help location mark.</desc>
|
||||||
|
<defs>
|
||||||
|
<linearGradient id="background" x1="0" y1="0" x2="1" y2="1">
|
||||||
|
<stop offset="0" stop-color="#d8f2ec"/>
|
||||||
|
<stop offset="0.55" stop-color="#f4f5ef"/>
|
||||||
|
<stop offset="1" stop-color="#f6d8ca"/>
|
||||||
|
</linearGradient>
|
||||||
|
</defs>
|
||||||
|
|
||||||
|
<rect width="1024" height="500" fill="url(#background)"/>
|
||||||
|
|
||||||
|
<g fill="none" stroke="#047b68" stroke-linecap="round" opacity=".14">
|
||||||
|
<path d="M-30 92C130 78 198 153 332 137S548 59 1058 112" stroke-width="24"/>
|
||||||
|
<path d="M-28 430C169 332 244 392 362 354s240-148 700-107" stroke-width="14"/>
|
||||||
|
<path d="M151-20c-4 173 86 205 57 363-12 66-42 122-78 177" stroke-width="9"/>
|
||||||
|
<path d="M883-20c-88 138-63 243-24 333 22 51 31 119 24 207" stroke-width="9"/>
|
||||||
|
</g>
|
||||||
|
|
||||||
|
<g fill="none" stroke="#b83b12" stroke-linecap="round" opacity=".12">
|
||||||
|
<path d="M-20 253c177-3 287-78 418-55 126 22 224 142 646 105" stroke-width="18"/>
|
||||||
|
<path d="M712-30c-77 113-131 192-118 306 8 70 48 143 87 244" stroke-width="8"/>
|
||||||
|
</g>
|
||||||
|
|
||||||
|
<g fill="#fff" opacity=".74">
|
||||||
|
<circle cx="103" cy="92" r="10"/>
|
||||||
|
<circle cx="241" cy="367" r="8"/>
|
||||||
|
<circle cx="785" cy="118" r="9"/>
|
||||||
|
<circle cx="921" cy="371" r="12"/>
|
||||||
|
</g>
|
||||||
|
|
||||||
|
<path
|
||||||
|
d="M227 307C339 307 369 212 470 229c72 12 93 70 169 52 51-12 88-49 158-49"
|
||||||
|
fill="none"
|
||||||
|
stroke="#fff"
|
||||||
|
stroke-width="16"
|
||||||
|
stroke-linecap="round"
|
||||||
|
stroke-dasharray="1 31"
|
||||||
|
/>
|
||||||
|
|
||||||
|
<g>
|
||||||
|
<circle cx="212" cy="307" r="60" fill="#047b68"/>
|
||||||
|
<circle cx="212" cy="284" r="18" fill="#fff"/>
|
||||||
|
<path d="M173 334c12-28 65-28 78 0" fill="none" stroke="#fff" stroke-width="18" stroke-linecap="round"/>
|
||||||
|
|
||||||
|
<circle cx="812" cy="232" r="60" fill="#b83b12"/>
|
||||||
|
<circle cx="812" cy="209" r="18" fill="#fff"/>
|
||||||
|
<path d="M773 259c12-28 65-28 78 0" fill="none" stroke="#fff" stroke-width="18" stroke-linecap="round"/>
|
||||||
|
</g>
|
||||||
|
|
||||||
|
<g transform="translate(392 75) scale(.47)">
|
||||||
|
<path
|
||||||
|
fill="#047b68"
|
||||||
|
d="M256 12C122 12 22 112 22 236c0 117 96 207 234 270 138-63 234-153 234-270C490 112 390 12 256 12Z"
|
||||||
|
/>
|
||||||
|
<path
|
||||||
|
fill="#b83b12"
|
||||||
|
d="M425 176c42 91 10 189-57 250-32 29-70 56-112 80V282c62-11 123-51 169-106Z"
|
||||||
|
/>
|
||||||
|
<path
|
||||||
|
fill="#fff"
|
||||||
|
d="M256 55c-94 0-171 53-171 118 0 47 48 65 119 69 19 1 25 19 10 31-17 13-36 20-53 26-16 6-18 26-4 37 20 16 45 19 67 16l32 36 32-36c22 3 47 0 67-16 14-11 12-31-4-37-17-6-36-13-53-26-15-12-9-30 10-31 71-4 119-22 119-69 0-65-77-118-171-118Z"
|
||||||
|
/>
|
||||||
|
<circle cx="153" cy="170" r="34" fill="#047b68"/>
|
||||||
|
<circle cx="359" cy="170" r="34" fill="#b83b12"/>
|
||||||
|
<path
|
||||||
|
fill="#b83b12"
|
||||||
|
d="M256 252c5 20 16 31 36 36-20 5-31 16-36 36-5-20-16-31-36-36 20-5 31-16 36-36Z"
|
||||||
|
/>
|
||||||
|
</g>
|
||||||
|
</svg>
|
||||||
|
After Width: | Height: | Size: 2.9 KiB |
BIN
android/store-assets/screenshots/phone/01-home.png
Normal file
BIN
android/store-assets/screenshots/phone/01-home.png
Normal file
Binary file not shown.
|
After Width: | Height: | Size: 298 KiB |
BIN
android/store-assets/screenshots/phone/02-discovery.png
Normal file
BIN
android/store-assets/screenshots/phone/02-discovery.png
Normal file
Binary file not shown.
|
After Width: | Height: | Size: 229 KiB |
BIN
android/store-assets/screenshots/phone/03-private-request.png
Normal file
BIN
android/store-assets/screenshots/phone/03-private-request.png
Normal file
Binary file not shown.
|
After Width: | Height: | Size: 1.2 MiB |
BIN
android/store-assets/screenshots/phone/04-activity.png
Normal file
BIN
android/store-assets/screenshots/phone/04-activity.png
Normal file
Binary file not shown.
|
After Width: | Height: | Size: 1.1 MiB |
|
|
@ -1,8 +1,43 @@
|
||||||
# Who Need Help — implementation verification
|
# Who Need Help — implementation verification
|
||||||
|
|
||||||
Observed through 2026-07-25 in the local workspace. This report separates observed
|
Observed through 2026-07-28 in the local workspace. This report separates observed
|
||||||
results from product limits and unknown production properties.
|
results from product limits and unknown production properties.
|
||||||
|
|
||||||
|
## Physical Android and Play preflight on 2026-07-28
|
||||||
|
|
||||||
|
The application source below is exact local commit
|
||||||
|
`c863b47e5ff9a0e90240a7cf286e627bd87e04ec`. No push, hackathon-test
|
||||||
|
deployment, production deployment, Devpost edit, branch, or tag was made.
|
||||||
|
|
||||||
|
- `./scripts/quality.sh` passed ShellCheck, Hadolint at the configured
|
||||||
|
threshold, actionlint, release/rollback/migration drills, every Compose
|
||||||
|
render, Prometheus and Alertmanager validation, Helm lint, tracked-source
|
||||||
|
and runtime-image scans, formatting, warnings-as-errors compilation, xref,
|
||||||
|
Credo, Sobelow, Dialyzer, Hex/npm audits, and all 394 ExUnit tests. The
|
||||||
|
configured source and image scans reported zero vulnerability or secret
|
||||||
|
findings, and the quality run exited successfully after exact scoped
|
||||||
|
cleanup.
|
||||||
|
- The existing signed development application and its instrumentation package
|
||||||
|
were installed atomically on the connected physical Android device. The
|
||||||
|
development cross-client replay passed magic-link login, private Android to
|
||||||
|
browser and browser to Android messages, real FCM registration and
|
||||||
|
notification delivery, foreground live-location sharing, browser marker
|
||||||
|
visibility, stop-sharing cleanup, zero retained raw position, and zero
|
||||||
|
browser TLS or fatal errors. Exact cleanup retained no run-scoped users or
|
||||||
|
new push device and restored every other tracked application-table count.
|
||||||
|
Evidence is
|
||||||
|
`output/android-browser-development-e2e/20260728010201-2368495`.
|
||||||
|
- The physical-device path now reuses the explicitly selected authorized
|
||||||
|
device and already installed development packages. It refuses test/staging
|
||||||
|
variants, does not create an emulator image, and retains run diagnostics
|
||||||
|
while enforcing exact fixture cleanup after success, failure, or interrupt.
|
||||||
|
- A read-only inspection of the authenticated Play Console showed no existing
|
||||||
|
Play application. Google was still verifying the uploaded identity
|
||||||
|
documents; contact-phone verification was unavailable until that review
|
||||||
|
completes, and **Create app** was disabled. Firebase development and
|
||||||
|
production Android clients already exist, but they are not Play listings.
|
||||||
|
No duplicate Firebase, Google Cloud, or Play application was created.
|
||||||
|
|
||||||
## Live development deployment verification on 2026-07-25
|
## Live development deployment verification on 2026-07-25
|
||||||
|
|
||||||
The local development Compose project was rebuilt and restarted from exact
|
The local development Compose project was rebuilt and restarted from exact
|
||||||
|
|
@ -229,13 +264,23 @@ These observations apply to the local checkout, its isolated test projects, and
|
||||||
`https://whoneedhelp.imalto.site`. No push, test/production deployment, Devpost
|
`https://whoneedhelp.imalto.site`. No push, test/production deployment, Devpost
|
||||||
edit, branch, or tag was made.
|
edit, branch, or tag was made.
|
||||||
|
|
||||||
- The separate Firebase project `who-need-help-dev-firebase` uses the free Spark
|
- Development Google OAuth, Firebase Android configuration, Analytics, and FCM
|
||||||
plan, has Gemini and Analytics disabled, and contains the development Android
|
are consolidated in the Spark-plan project `who-need-help-development`. It
|
||||||
app `org.whoneedhelp.mobile.development`. Its public Android configuration and
|
contains the Android app `org.whoneedhelp.mobile.development`, both measured
|
||||||
a dedicated FCM service-account credential are present only in the ignored
|
development signing-certificate fingerprints, and the dedicated
|
||||||
mode-`0600` development `.env`. The service account has the exact Firebase
|
`wnh-dev-fcm-sender` service account. Public Android identifiers and the FCM
|
||||||
Cloud Messaging API Admin role. `check-environment-readiness.sh .env
|
service-account credential are present only in the ignored mode-`0600`
|
||||||
--require-release` reports zero blocking items and zero local-only warnings.
|
development `.env`. `check-environment-readiness.sh .env --require-release`
|
||||||
|
reports zero blocking items and zero local-only warnings.
|
||||||
|
- The superseded project `who-need-help-dev-firebase` was audited before
|
||||||
|
shutdown on 2026-07-28. Google Analytics and BigQuery integration were not
|
||||||
|
enabled, and Firestore, Cloud Storage, Cloud SQL, BigQuery datasets, and
|
||||||
|
Firebase Authentication contained no configured data resources. Its only
|
||||||
|
non-default resource was the replaced development FCM service account and
|
||||||
|
key. Google accepted the exact project deletion request and reported the
|
||||||
|
project as shut down and scheduled for deletion with the documented 30-day
|
||||||
|
owner recovery window. The development, production, and frozen staging
|
||||||
|
projects were not selected by that operation.
|
||||||
- The current development workers were recreated with that FCM configuration
|
- The current development workers were recreated with that FCM configuration
|
||||||
only after a mode-`0600` custom-format database backup was written to
|
only after a mode-`0600` custom-format database backup was written to
|
||||||
`output/backups/dev-before-fcm-workers-20260724-114450.dump` and its checksum
|
`output/backups/dev-before-fcm-workers-20260724-114450.dump` and its checksum
|
||||||
|
|
|
||||||
110
scripts/android-store-assets-validate.sh
Executable file
110
scripts/android-store-assets-validate.sh
Executable file
|
|
@ -0,0 +1,110 @@
|
||||||
|
#!/bin/sh
|
||||||
|
set -eu
|
||||||
|
|
||||||
|
ROOT=$(CDPATH='' cd -- "$(dirname -- "$0")/.." && pwd)
|
||||||
|
ASSETS="$ROOT/android/store-assets"
|
||||||
|
LISTINGS="$ROOT/android/play-store"
|
||||||
|
|
||||||
|
if ! command -v identify >/dev/null 2>&1; then
|
||||||
|
echo "ImageMagick identify is required to validate Play Store assets." >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
validate_image() {
|
||||||
|
path=$1
|
||||||
|
expected_width=$2
|
||||||
|
expected_height=$3
|
||||||
|
max_bytes=$4
|
||||||
|
alpha_policy=$5
|
||||||
|
|
||||||
|
if [ ! -s "$path" ]; then
|
||||||
|
echo "Missing or empty Play Store asset: $path" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
dimensions=$(identify -format '%wx%h' "$path")
|
||||||
|
if [ "$dimensions" != "${expected_width}x${expected_height}" ]; then
|
||||||
|
echo "Unexpected dimensions for $path: $dimensions" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
bytes=$(stat -c '%s' "$path")
|
||||||
|
if [ "$bytes" -gt "$max_bytes" ]; then
|
||||||
|
echo "Play Store asset exceeds its size limit: $path ($bytes bytes)" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
channels=$(identify -format '%[channels]' "$path")
|
||||||
|
case "$alpha_policy:$channels" in
|
||||||
|
required:*a*) ;;
|
||||||
|
forbidden:*a*)
|
||||||
|
echo "Play Store asset must not contain an alpha channel: $path" >&2
|
||||||
|
exit 1
|
||||||
|
;;
|
||||||
|
forbidden:*) ;;
|
||||||
|
required:*)
|
||||||
|
echo "Play Store asset must contain an alpha channel: $path" >&2
|
||||||
|
exit 1
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
}
|
||||||
|
|
||||||
|
extract_section() {
|
||||||
|
file=$1
|
||||||
|
heading=$2
|
||||||
|
|
||||||
|
awk -v heading="$heading" '
|
||||||
|
$0 == heading {in_section = 1; next}
|
||||||
|
in_section && /^## / {exit}
|
||||||
|
in_section {
|
||||||
|
if (seen || $0 != "") {
|
||||||
|
print
|
||||||
|
seen = 1
|
||||||
|
}
|
||||||
|
}
|
||||||
|
' "$file" |
|
||||||
|
sed -e '/^[[:space:]]*$/d' -e '${/^$/d;}'
|
||||||
|
}
|
||||||
|
|
||||||
|
validate_image "$ASSETS/icon-512.png" 512 512 1048576 required
|
||||||
|
validate_image \
|
||||||
|
"$ASSETS/feature-graphic-1024x500.png" \
|
||||||
|
1024 500 15728640 forbidden
|
||||||
|
|
||||||
|
screenshot_count=0
|
||||||
|
for screenshot in "$ASSETS"/screenshots/phone/*.png; do
|
||||||
|
validate_image "$screenshot" 1080 1920 8388608 forbidden
|
||||||
|
screenshot_count=$((screenshot_count + 1))
|
||||||
|
done
|
||||||
|
|
||||||
|
if [ "$screenshot_count" -lt 4 ]; then
|
||||||
|
echo "At least four approved phone screenshots are required." >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
for listing in "$LISTINGS"/store-listing-*.md; do
|
||||||
|
app_name=$(extract_section "$listing" "## App name")
|
||||||
|
short_description=$(extract_section "$listing" "## Short description")
|
||||||
|
full_description=$(extract_section "$listing" "## Full description")
|
||||||
|
|
||||||
|
app_name_length=$(printf '%s' "$app_name" | wc -m)
|
||||||
|
short_length=$(printf '%s' "$short_description" | wc -m)
|
||||||
|
full_length=$(printf '%s' "$full_description" | wc -m)
|
||||||
|
|
||||||
|
if [ "$app_name_length" -gt 30 ]; then
|
||||||
|
echo "App name exceeds 30 characters in $listing." >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [ "$short_length" -gt 80 ]; then
|
||||||
|
echo "Short description exceeds 80 characters in $listing." >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [ "$full_length" -gt 4000 ]; then
|
||||||
|
echo "Full description exceeds 4000 characters in $listing." >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
|
||||||
|
echo "Play Store assets and listing lengths are valid."
|
||||||
Loading…
Reference in New Issue
Block a user