Document deferred Firebase analytics safeguards

This commit is contained in:
SimpleTest 2026-07-25 19:15:27 +03:00
parent 769be81ee3
commit 539076c163
2 changed files with 21 additions and 1 deletions

View File

@ -52,6 +52,20 @@ The following decisions are intentionally not generated by code:
incident queues have named owners and monitored contact paths.
- [ ] Provider terms and capacity are approved for email, map tiles, Google
identity, Web Push, Firebase/FCM, database hosting, backups, and monitoring.
- [ ] Google Analytics for Firebase remains disabled until the operator has
approved a purpose and event allow-list, updated the privacy notice,
implemented an explicit user analytics preference, and verified that the
Android client does not initialise Analytics before the user opts in.
Analytics events must not contain email addresses, account or device
identifiers owned by Who Need Help, request/chat/support text, medicine
details, exact or approximate coordinates, handover codes, social-account
data, or moderation and safety evidence. The initial useful event set is
limited to coarse product milestones such as `registration_completed`,
`request_created`, `helper_joined`, `handover_completed`, and
`push_opened`; every event and parameter requires a privacy review before
release. Enabling Firebase Analytics later is a separate change from the
server-side `ProductAnalytics` context, which stores only allow-listed
daily aggregate counters without user identifiers.
- [ ] Representative load measurements from the intended host and traffic shape
justify database pools, action-limit policies, replica counts, memory/CPU
allocation, alerts, and any scaling thresholds.
@ -113,4 +127,3 @@ as forward-only rather than receiving an invented database rollback.
Record observed timestamps, revision/image identities, and non-secret evidence
paths in `docs/verification.md`. Record failed checks as failed; do not convert
them into documentation-only success.

View File

@ -1721,6 +1721,13 @@ complete.
against each explicitly promoted production origin. Unattended background
location was not requested or verified. APNs and iOS are outside the current
scope.
- Google Analytics for Firebase is intentionally deferred rather than silently
enabled by the Firebase project wizard. Before enabling it, implement the
consent, privacy-notice, event allow-list, sensitive-field exclusions, and
opt-in initialization requirements recorded in
[`docs/public-launch-checklist.md`](public-launch-checklist.md). This is
separate from the existing identifier-free daily aggregate
`ProductAnalytics` counters.
- Load-test representative data and traffic, then set measured pool, resource,
autoscaling, and action-limit policies.
- Publish jurisdiction-specific emergency contacts, privacy, retention,