diff --git a/android/play-store/release-checklist.md b/android/play-store/release-checklist.md index 8667c75..3e1053a 100644 --- a/android/play-store/release-checklist.md +++ b/android/play-store/release-checklist.md @@ -133,6 +133,8 @@ block publishing changes, including Store Listing, Pricing, and Distribution. disabled. A simultaneous public request returned `200` and displayed the CSAE/CSAM standards and dedicated reporting path, but that technical evidence does not authorise the separate legal-compliance attestation. + The official-requirement matrix and physical-device verification are + recorded in `docs/google-play-child-safety-audit-2026-08-26.md`. ## App content diff --git a/docs/google-play-child-safety-audit-2026-08-26.md b/docs/google-play-child-safety-audit-2026-08-26.md new file mode 100644 index 0000000..416e9cc --- /dev/null +++ b/docs/google-play-child-safety-audit-2026-08-26.md @@ -0,0 +1,65 @@ +# Google Play child-safety audit, 2026-08-26 + +This note compares the current Google Play Child Safety Standards policy with +the release candidate, the deployed production site, and the Play-delivered +Android build. It records technical evidence only. It does not replace the +operator's legal review or authorize submitting the Play Console declaration. + +## Official requirements + +Who Need Help is in scope because its Play Console category is Social. The +policy still applies when an app is adults-only. Google requires an in-scope +app to: + +1. publish globally accessible standards that prohibit child sexual abuse and + exploitation; +2. provide a reporting or feedback mechanism that users can reach without + leaving the app; +3. act on child sexual abuse material after obtaining actual knowledge of it; +4. maintain a process for reporting confirmed CSAM to NCMEC or the relevant + regional authority as required by applicable law; and +5. name an individual in Play Console who can explain and act on the app's + child-safety procedures. + +Google says the public standards must load, cover CSAE or child safety, and +name the app or developer shown on the store listing. Google accepts an +in-app report flow, support email, or chat channel as the feedback mechanism +provided the user can reach it without leaving the app. + +Primary sources: + +- [Google Play Child Endangerment policy](https://support.google.com/googleplay/android-developer/answer/9878809?hl=en) +- [Google Play Child Safety Standards guidance](https://support.google.com/googleplay/android-developer/answer/14747720?hl=en) +- [Google Play policy update announced 15 July 2026](https://support.google.com/googleplay/android-developer/answer/17134731?hl=en) + +## Observed product evidence + +| Requirement | Evidence observed on 2026-08-26 | Result | +| --- | --- | --- | +| Public standards | `https://whoneedhelp.com/child-safety` returned HTTP 200. The page names Who Need Help, explicitly prohibits CSAE and CSAM, describes prohibited conduct, explains reporting, and links to the report form. | Technical requirement present | +| In-app feedback | The footer exposes Child safety and Report content on every application page. On the physical device `72551e60`, the Play-delivered `org.whoneedhelp.mobile` version `0.1.3 (4)` opened Child safety inside `MainActivity`. Tapping Report child-safety content opened the same-origin report form inside the app. | Technical requirement present | +| Report classification | The report form opened with Sexual material involving a minor selected. `ContentRemoval.create_notice/3` assigns an anonymous report in this category the `urgent_review` status. The form does not accept an evidence upload. | Technical requirement present | +| Content and account action | Staff permissions and audited operations can hide reported requests or activities, restrict access, and suspend accounts. The published standard says automated signals can prioritize a case but do not prove it. | Technical controls present | +| Authority reporting process | `docs/trust-safety.md` instructs the responsible operator to report confirmed CSAM to NCMEC or the relevant regional authority when applicable law requires it. The public standard states the same process. | Written process present, legal review still required | +| Child-safety contact | The protected support and legal queues exist, but Play requires the developer to name a real individual who can receive Google's notices, explain the procedures, and take action. Code cannot select or attest for that person. | Operator action required | + +No report or support request was submitted during the device check. The app +remained the foreground activity throughout the navigation. + +## What remains before self-certification + +Do not submit the Play declaration until the operator has done all of the +following: + +- selected a real, monitored child-safety contact and entered that person's + name and contact details in Play Console; +- confirmed that the person can open the urgent legal queue and suspend or + restrict an account through the staff workspace; +- tested inbound mail from Google Play to the selected address; +- reviewed the reporting authority and mandatory reporting procedure for each + launch jurisdiction; and +- personally reviewed the declaration wording before submitting the legal + self-certification. + +The software and deployed reporting path are ready for that review. Legal +compliance and the truth of the Play self-certification remain human decisions.