Document deferred Firebase analytics safeguards
This commit is contained in:
parent
769be81ee3
commit
539076c163
|
|
@ -52,6 +52,20 @@ The following decisions are intentionally not generated by code:
|
|||
incident queues have named owners and monitored contact paths.
|
||||
- [ ] Provider terms and capacity are approved for email, map tiles, Google
|
||||
identity, Web Push, Firebase/FCM, database hosting, backups, and monitoring.
|
||||
- [ ] Google Analytics for Firebase remains disabled until the operator has
|
||||
approved a purpose and event allow-list, updated the privacy notice,
|
||||
implemented an explicit user analytics preference, and verified that the
|
||||
Android client does not initialise Analytics before the user opts in.
|
||||
Analytics events must not contain email addresses, account or device
|
||||
identifiers owned by Who Need Help, request/chat/support text, medicine
|
||||
details, exact or approximate coordinates, handover codes, social-account
|
||||
data, or moderation and safety evidence. The initial useful event set is
|
||||
limited to coarse product milestones such as `registration_completed`,
|
||||
`request_created`, `helper_joined`, `handover_completed`, and
|
||||
`push_opened`; every event and parameter requires a privacy review before
|
||||
release. Enabling Firebase Analytics later is a separate change from the
|
||||
server-side `ProductAnalytics` context, which stores only allow-listed
|
||||
daily aggregate counters without user identifiers.
|
||||
- [ ] Representative load measurements from the intended host and traffic shape
|
||||
justify database pools, action-limit policies, replica counts, memory/CPU
|
||||
allocation, alerts, and any scaling thresholds.
|
||||
|
|
@ -113,4 +127,3 @@ as forward-only rather than receiving an invented database rollback.
|
|||
Record observed timestamps, revision/image identities, and non-secret evidence
|
||||
paths in `docs/verification.md`. Record failed checks as failed; do not convert
|
||||
them into documentation-only success.
|
||||
|
||||
|
|
|
|||
|
|
@ -1721,6 +1721,13 @@ complete.
|
|||
against each explicitly promoted production origin. Unattended background
|
||||
location was not requested or verified. APNs and iOS are outside the current
|
||||
scope.
|
||||
- Google Analytics for Firebase is intentionally deferred rather than silently
|
||||
enabled by the Firebase project wizard. Before enabling it, implement the
|
||||
consent, privacy-notice, event allow-list, sensitive-field exclusions, and
|
||||
opt-in initialization requirements recorded in
|
||||
[`docs/public-launch-checklist.md`](public-launch-checklist.md). This is
|
||||
separate from the existing identifier-free daily aggregate
|
||||
`ProductAnalytics` counters.
|
||||
- Load-test representative data and traffic, then set measured pool, resource,
|
||||
autoscaling, and action-limit policies.
|
||||
- Publish jurisdiction-specific emergency contacts, privacy, retention,
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user