diff --git a/android/play-store/location-and-fgs-declaration.md b/android/play-store/location-and-fgs-declaration.md index 2ff6a83..4b15fd4 100644 --- a/android/play-store/location-and-fgs-declaration.md +++ b/android/play-store/location-and-fgs-declaration.md @@ -206,6 +206,30 @@ Stop action was performed immediately afterward: server verification observed 41 samples and zero retained raw positions, and exact fixture cleanup passed. A new concise take must visibly include Stop and the stopped state. +### Final Play-delivered demonstration + +The final concise demonstration was recorded on 2026-08-10 from the exact +Google Play Internal-testing install `0.1.2 (3)` and saved as: + +`output/android/play-console/wnh-fgs-review-final-v5.mp4` + +It is 21.379802 seconds, H.264, 720×1600, and its SHA-256 is +`3c5f52019bf8a42ff42e1d9232afc126b62627390d74eed75084d82ecb33ac56`. +Visual review confirms that it shows the in-app trigger and prominent +disclosure, Android location prompt, active sharing state, minimized-app +persistent notification, visible notification Stop action, and the returned +stopped state with **Share location** available again. It contains no account +email, fixture credentials, precise map, medical information, chat, or handover +code. + +Server-side verification for the same take observed active tracking with a +retained current position, then stopped tracking with zero retained raw +positions. Exact cleanup deleted the run-scoped request, assignment, tracking +session, and temporary requester; the protected runtime state and prepare log +were removed. Production readiness remained healthy. This file is final local +evidence, but it is not considered submitted until an unlisted hosted URL is +entered and saved in Play Console. + The remaining Play policy references were last checked on 2026-08-03; refresh them again immediately before submitting the declaration because the Help Center pages can change independently of the Android platform documentation: diff --git a/android/play-store/release-checklist.md b/android/play-store/release-checklist.md index 47a4bd2..eeee3b9 100644 --- a/android/play-store/release-checklist.md +++ b/android/play-store/release-checklist.md @@ -91,6 +91,12 @@ - [ ] Complete **Set up your store listing** in Play Console using the prepared localized copy and assets. The same Dashboard inspection showed overall app setup at 9 of 11 tasks. +- [ ] If the truthful category remains **Social**, publish and verify the + `/child-safety` standards, select a monitored child-safety point of + contact, verify that contact can access the urgent queue, and complete + the Play child-safety self-certification only from observed operational + evidence. Adult-only positioning does not remove this requirement for an + app declared as Social. ## App content @@ -121,7 +127,11 @@ saved task selection; no incomplete form was saved or submitted. - [ ] Upload the unlisted demonstration video showing the user-triggered start, prominent disclosure, Android permission, persistent notification, - minimized-app operation, and Stop action. + minimized-app operation, and Stop action. The final local 21.379802-second + Play-delivered evidence file has been visually and server-side verified; + its exact path and checksum are recorded in + `location-and-fgs-declaration.md`. Hosting it as an unlisted video and + saving the resulting URL in Play Console remain incomplete. - [ ] Reconcile any target-SDK-37 persistent precise-location declaration shown by Play Console with the exact artifact. The app uses a user-started location foreground service and does not declare diff --git a/android/play-store/store-presence-runbook.md b/android/play-store/store-presence-runbook.md new file mode 100644 index 0000000..b761921 --- /dev/null +++ b/android/play-store/store-presence-runbook.md @@ -0,0 +1,81 @@ +# Google Play store presence runbook + +This runbook records the exact local inputs and the observed Console gaps. It +does not authorize saving fields in Play Console or publishing a release. + +## Observed Console state on 2026-08-10 + +- App type is **App**. +- App category is not selected. +- Tags are not selected. +- Store-listing contact email, phone, and website are empty. +- No default store listing has been created. +- The Dashboard showed 9 of 11 setup tasks complete. The remaining setup tasks + were category/contact details and the store listing. + +These are direct observations from the authenticated Play Console session on +that date. Recheck the Console before applying because its fields and policy +requirements can change. + +## Prepared local inputs + +- English listing: `android/play-store/store-listing-en-US.md` +- Ukrainian listing: `android/play-store/store-listing-uk-UA.md` +- Russian listing: `android/play-store/store-listing-ru-RU.md` +- Icon: `android/store-assets/icon-512.png` +- Feature graphic: `android/store-assets/feature-graphic-1024x500.png` +- Phone screenshots: `android/store-assets/screenshots/phone/` +- Screenshot alt text: `android/store-assets/README.md` + +Run `./scripts/android-store-assets-validate.sh` immediately before upload. +The validator checks image dimensions/formats and listing-length constraints; +it does not prove Play policy approval or visual quality. + +## Contact fields + +- Public support email candidate: `contact@whoneedhelp.com` +- Website: `https://whoneedhelp.com/` +- Public phone: leave empty unless the operator deliberately chooses a number + that can be published and monitored. + +Do not save the email merely because it is used as an outbound sender. First +send a real inbound message to it, observe arrival in the monitored mailbox, +and verify that replies are handled. Google recommends keeping the public app +support address distinct from the developer-account sign-in address. + +## Category and child-safety gate + +The prepared listing suggests **Social**, which accurately describes the +community and participant features. Google Play's current Child Safety +Standards policy applies to every app that declares itself as Social, including +adult-only apps. Before saving that category or self-certifying: + +1. Deploy and open the globally accessible `/child-safety` standards. +2. Verify the in-app and public report paths for child-safety content. +3. Select a monitored child-safety point of contact who can access the urgent + restricted queue and act on reports. +4. Test inbound delivery to the selected contact. +5. Confirm the launch-jurisdiction escalation and authority-reporting process. +6. Record the evidence and only then complete Play's self-certification. + +Do not choose a less accurate category merely to avoid a policy declaration. +Do not claim cross-jurisdiction legal compliance from the presence of a page, +queue, or automated test. + +## Suggested apply order after explicit permission + +1. Recheck the current Console fields and policy warnings read-only. +2. Verify the production policy/support URLs and monitored email. +3. Save category, tags, contact email, and website. +4. Create the default English (United States) listing with prepared text, + images, and alt text. +5. Add Ukrainian and Russian localizations from their prepared files. +6. Reopen the Dashboard and verify both setup tasks are marked complete. +7. Recheck App content; do not start Closed or Production rollout as part of + store-presence setup. + +Official references rechecked on 2026-08-10: + +- https://support.google.com/googleplay/android-developer/answer/9859454 +- https://support.google.com/googleplay/android-developer/answer/14747720 +- https://support.google.com/googleplay/android-developer/answer/9878809 diff --git a/docs/trust-safety.md b/docs/trust-safety.md index 9d44a63..4344e75 100644 --- a/docs/trust-safety.md +++ b/docs/trust-safety.md @@ -159,3 +159,36 @@ and a dedicated TAKE IT DOWN intake are described in `docs/support-and-content-removal.md`. Public contacts are verified through an emailed private status link; moderator/admin decisions and access remain audited. The removal forms never accept intimate-media uploads. + +### Child sexual abuse and exploitation + +The public `/child-safety` standards explicitly prohibit child sexual abuse +and exploitation (CSAE), including child sexual abuse material (CSAM), grooming, +sextortion, sexualization, and child trafficking for sexual exploitation. This +policy applies even though registration is limited to adults and the current +product does not accept user media uploads. + +Users can report the relevant request, activity, profile, or message in the +product. The public `/legal/content-removal` route also accepts an anonymous +`child_sexual_abuse_material` report without accepting a file upload. Reporters +are instructed not to reproduce, forward, download, or email suspected CSAM. + +The category enters the restricted legal queue as `urgent_review`. The assigned +operator must immediately assess whether access should be restricted, content +disabled, or an account suspended; preserve only information necessary for the +review and applicable reporting duties; and record the decision in the audited +case. After actual knowledge of confirmed CSAM, the responsible operator must +report it to NCMEC or the relevant regional authority where applicable law +requires that report. The operator must not mark Google Play's child-safety +self-certification complete until all of the following are true: + +- a named, monitored child-safety point of contact has been selected; +- that person can access the urgent queue and understands this procedure; +- inbound contact from Google Play to the selected address has been tested; +- the applicable reporting authority and escalation path for the launch + jurisdiction have been reviewed by the operator; and +- the public standards and in-app reporting path have been verified against the + deployed release. + +This is an operational policy and implementation record, not a claim that code +alone establishes legal compliance in every jurisdiction. diff --git a/lib/who_need_help_web/components/layouts.ex b/lib/who_need_help_web/components/layouts.ex index 77950e4..6508ee7 100644 --- a/lib/who_need_help_web/components/layouts.ex +++ b/lib/who_need_help_web/components/layouts.ex @@ -190,6 +190,8 @@ defmodule WhoNeedHelpWeb.Layouts do