# Google Play review access The app has public pages, email/passwordless authentication, password authentication, and Google sign-in. Reviewers must be able to inspect restricted functionality without contacting a real requester or sharing real personal/medical information. ## Recommended reviewer instructions 1. Open the app. The product home, Safety, Privacy, Terms, Support, content reporting, and Account deletion pages are available without a reviewer account. Request, activity, category-proposal, profile, notification, and moderation LiveViews require authentication. 2. For authenticated functionality, use the dedicated production reviewer account prepared immediately before submission. 3. Expand **Use a password instead**, then enter the dedicated reviewer email and password supplied in Play Console. Do not use an email link or Google sign-in for review: the supplied password must remain reusable, always available, and independent of a developer mailbox or one-time code. 4. Use only the pre-created synthetic requests and activity. Their titles must start with `Play review`. 5. A second synthetic account must already be assigned as the counterpart so the reviewer can inspect chat, optional tracking controls, handover, withdrawal, reviews, blocking, reporting, support, privacy, and account deletion. ## Submission-time values Do not store credentials here or in Git. Put them only in Play Console’s app access field: - Reviewer email: create at release time. - Reviewer password: create at release time and store only in Play Console and the operator-controlled password manager. - Stable synthetic request URL: create at release time. - Stable synthetic activity URL: create at release time. - Support contact: `contact@whoneedhelp.com`. ## Copy for Play Console App access Use the following English instructions only after replacing both bracketed values with the dedicated production reviewer credentials and after testing the exact text from a clean Play-delivered installation. Never commit the completed version. ```text This app has public pages and authenticated product flows. 1. Open the app and tap Log in. 2. Expand "Use a password instead". 3. Enter the reusable reviewer credentials below. 4. After signing in, open Requests to inspect the pre-created synthetic help request and its private chat, location controls, handover and reporting. 5. Open Activities to inspect the pre-created synthetic cinema activity and participation controls. Reviewer email: [ENTER IN PLAY CONSOLE ONLY] Reviewer password: [ENTER IN PLAY CONSOLE ONLY] All records whose titles start with "Play review" are synthetic. No purchase, payment, medicine, travel or real-world meeting is required. The credentials are reusable, do not require a one-time code or developer mailbox, and work independently of reviewer location. Support: contact@whoneedhelp.com ``` After `scripts/prepare-play-review.sh ... --confirm` succeeds, append the exact production request and activity URLs printed by the command. Do not use a dev, test, localhost or expiring sign-in URL. ## Verification before submission - Test the exact instructions in a clean Android install from the Play track. - Confirm they do not depend on a developer browser session, VPN, localhost, expiring fixture, or test/staging domain. - Confirm the reviewer account is not a moderator or administrator. - Confirm all data is synthetic and no real user can be messaged or located. - Confirm the password works from a clean Play-delivered install without a second factor, one-time code, developer browser session, or location gate. - Confirm the final Play Console instructions are in English and every route they mention is reachable by the reviewer account. After both dedicated accounts have registered, confirmed their email, and set their fixed passwords through the production UI, first run the read-only readiness check from the production checkout: ```bash ./scripts/prepare-play-review.sh \ REVIEWER_EMAIL COUNTERPART_EMAIL \ --check-only whoneedhelp.com \ /srv/who_need_help-production/.env ``` Only after that check succeeds should an operator create the stable synthetic records: ```bash ./scripts/prepare-play-review.sh \ REVIEWER_EMAIL COUNTERPART_EMAIL \ --confirm whoneedhelp.com \ /srv/who_need_help-production/.env ``` The command does not create or change credentials. It refuses missing, unconfirmed, suspended, passwordless, staff, or duplicate accounts and is idempotent for its one request and one activity.