From 539076c16311ab920684dc95f7af7577e55d616c Mon Sep 17 00:00:00 2001 From: SimpleTest Date: Sat, 25 Jul 2026 19:15:27 +0300 Subject: [PATCH] Document deferred Firebase analytics safeguards --- docs/public-launch-checklist.md | 15 ++++++++++++++- docs/verification.md | 7 +++++++ 2 files changed, 21 insertions(+), 1 deletion(-) diff --git a/docs/public-launch-checklist.md b/docs/public-launch-checklist.md index 899cfdb..b0c082b 100644 --- a/docs/public-launch-checklist.md +++ b/docs/public-launch-checklist.md @@ -52,6 +52,20 @@ The following decisions are intentionally not generated by code: incident queues have named owners and monitored contact paths. - [ ] Provider terms and capacity are approved for email, map tiles, Google identity, Web Push, Firebase/FCM, database hosting, backups, and monitoring. +- [ ] Google Analytics for Firebase remains disabled until the operator has + approved a purpose and event allow-list, updated the privacy notice, + implemented an explicit user analytics preference, and verified that the + Android client does not initialise Analytics before the user opts in. + Analytics events must not contain email addresses, account or device + identifiers owned by Who Need Help, request/chat/support text, medicine + details, exact or approximate coordinates, handover codes, social-account + data, or moderation and safety evidence. The initial useful event set is + limited to coarse product milestones such as `registration_completed`, + `request_created`, `helper_joined`, `handover_completed`, and + `push_opened`; every event and parameter requires a privacy review before + release. Enabling Firebase Analytics later is a separate change from the + server-side `ProductAnalytics` context, which stores only allow-listed + daily aggregate counters without user identifiers. - [ ] Representative load measurements from the intended host and traffic shape justify database pools, action-limit policies, replica counts, memory/CPU allocation, alerts, and any scaling thresholds. @@ -113,4 +127,3 @@ as forward-only rather than receiving an invented database rollback. Record observed timestamps, revision/image identities, and non-secret evidence paths in `docs/verification.md`. Record failed checks as failed; do not convert them into documentation-only success. - diff --git a/docs/verification.md b/docs/verification.md index 56c9a43..4ad9672 100644 --- a/docs/verification.md +++ b/docs/verification.md @@ -1721,6 +1721,13 @@ complete. against each explicitly promoted production origin. Unattended background location was not requested or verified. APNs and iOS are outside the current scope. +- Google Analytics for Firebase is intentionally deferred rather than silently + enabled by the Firebase project wizard. Before enabling it, implement the + consent, privacy-notice, event allow-list, sensitive-field exclusions, and + opt-in initialization requirements recorded in + [`docs/public-launch-checklist.md`](public-launch-checklist.md). This is + separate from the existing identifier-free daily aggregate + `ProductAnalytics` counters. - Load-test representative data and traffic, then set measured pool, resource, autoscaling, and action-limit policies. - Publish jurisdiction-specific emergency contacts, privacy, retention,