From 67990ee47f882a3a98d3027541e4f145e6bb9941 Mon Sep 17 00:00:00 2001 From: SimpleTest Date: Sat, 8 Aug 2026 16:23:18 +0300 Subject: [PATCH] Document Android Play release readiness --- android/play-store/data-safety.md | 22 ++++++++++++++++++++++ android/play-store/release-checklist.md | 24 +++++++++++++++++++++--- 2 files changed, 43 insertions(+), 3 deletions(-) diff --git a/android/play-store/data-safety.md b/android/play-store/data-safety.md index 8ad7620..f247151 100644 --- a/android/play-store/data-safety.md +++ b/android/play-store/data-safety.md @@ -122,6 +122,28 @@ coordinates and ordinary HTTP request metadata. and intentionally is not treated as a permanent substitute for re-checking the final AAB and current Google Play form. +## 2026-08-08 pre-submission re-check + +- The current Android source fingerprint is still + `f2f281210d11465d8f7fda20a78d1ed2527660d2e8a10a29ed31bf031a29ce43`, + which exactly matches the source-bound release candidate in + `android/dist-release-20260803-162910/`. +- A fresh `releaseRuntimeClasspath` report resolves + `firebase-messaging:25.1.1` and `firebase-installations:19.1.2`. It does not + resolve Firebase Analytics, Crashlytics, Performance Monitoring, an ads SDK, + or another product-analytics SDK. +- `firebase-measurement-connector:19.0.0` is present only as a transitive + dependency of `firebase-messaging:25.1.1`; Gradle `dependencyInsight` + confirms that it was not added by an Analytics dependency. +- The public production pages `/privacy`, `/terms`, and `/account/delete` + returned HTTP 200 without authentication. The published Privacy Policy + describes FCM/Firebase Installations, direct OpenStreetMap tile requests, + foreground live-location sharing, retention, and account-deletion controls. +- `https://whoneedhelp.com/.well-known/assetlinks.json` currently publishes the + upload-certificate SHA-256 only. Re-run this worksheet after the separate + Google Play App Signing certificate is added and before submitting the Play + Data Safety form. + ## Official references - https://support.google.com/googleplay/android-developer/answer/10787469 diff --git a/android/play-store/release-checklist.md b/android/play-store/release-checklist.md index 13c8559..8d412ac 100644 --- a/android/play-store/release-checklist.md +++ b/android/play-store/release-checklist.md @@ -15,8 +15,9 @@ - [x] Accept Play App Signing. - [x] Record the upload-certificate SHA-1 and SHA-256 with the source-bound candidate. -- [ ] Record the distinct Play App Signing SHA-1 and SHA-256 after Play accepts - the first internal release. +- [ ] Record the distinct Play App Signing SHA-1 and SHA-256 after the first AAB + upload makes Play generate the app-signing key and before any tester + rollout. - [ ] Add the Play App Signing SHA-256 to production Google/Firebase Android configuration. - [ ] Publish and verify @@ -36,6 +37,17 @@ testing draft. Do not mark this complete until Play Console shows one accepted artifact and the internal release is available to testers. +## Production capability gate + +- [x] On 2026-08-08, run the current candidate validator against the live + production `.env` with `--require-server-release`: all twelve capability + checks reported `READY`, with zero blocking items and zero local-only + warnings. The validator did not print secret values and did not modify + production. +- [ ] Pass the stricter `--require-release` gate. Its only remaining blocking + item on 2026-08-08 is the not-yet-generated Play App Signing SHA-256; + every other capability reported `READY`. + ## Store presence - [x] 512×512 Play icon prepared. @@ -54,7 +66,12 @@ tested from a clean Play-delivered install. - [ ] Target audience/adult-only positioning confirmed. - [ ] Content rating questionnaire completed truthfully. -- [ ] Data Safety worksheet reconciled with the final dependency report. +- [x] Local Data Safety worksheet reconciled with the source-bound candidate, + a fresh resolved release dependency report, and the published privacy and + account-deletion pages. +- [ ] Enter and review those reconciled answers in the current Play Console + Data Safety form; do not mark this complete from the local worksheet + alone. - [ ] Account deletion questions and external URL completed. - [ ] Government/news/financial/health declarations answered from actual app behavior; do not describe the app as a medical service. @@ -89,6 +106,7 @@ Official references: - https://support.google.com/googleplay/android-developer/answer/9859152 +- https://support.google.com/googleplay/android-developer/answer/9842756 - https://support.google.com/googleplay/android-developer/answer/9866151 - https://support.google.com/googleplay/android-developer/answer/9859455 - https://support.google.com/googleplay/android-developer/answer/10787469