# Google Play pre-upload audit — 2026-08-03 This audit separates verified repository/device facts from actions that still require Play Console. It contains no account credentials or signing keys. ## Verified locally - The selected upload artifact and its checksum are recorded in `docs/google-play-release-candidate-2026-08-03.md`. - Package `org.whoneedhelp.mobile`, version code `1`, version name `0.1.0`, minimum SDK `24`, and target SDK `37` were verified from the release build. - Release unit tests, lint, R8, signing verification, and bundletool validation passed. The release lint report contains no errors or warnings. - The native disclosure appears before the location permission flow and explicitly describes precise-location collection and transmission, background use while minimized or not in use, persistent notification, stopping, raw-location deletion, and retained summary evidence. - English, Russian, and Ukrainian disclosure and store-listing text describe the same behavior. - The public Privacy page identifies Firebase Cloud Messaging and Firebase Installations, the current OpenStreetMap Foundation tile service, and the Android foreground location service behavior. - Public Privacy, Terms, Safety, Support, content-reporting, and account-deletion routes exist in the product. Reviewer guidance is recorded in `android/play-store/review-access.md`. - The release APK was installed on the authorised Android 16 physical device. The production home and Safety pages rendered, the production App Link opened `MainActivity`, and Android reported `whoneedhelp.com` as verified. - The clean PID-scoped application log contains no application crash, AndroidRuntime, TLS/SSL, or WebView load error. - No analytics SDK is declared as active in the Android application. Data Safety answers must still describe the behavior of Firebase Messaging/Installations and the app's own server communication. ## Verified Play Console state - The personal developer identity and contact phone are verified. - The Play application exists as app ID `4972430103169452589`, package `org.whoneedhelp.mobile`; it is a free app, not a game, with no ads. - Play App Signing was accepted. - The exact version-code `1` release AAB is retained in an internal-testing draft. The internal release is not yet available to testers, so its Play-generated signing identity and Play-delivered behavior remain unknown. ## Required before Play review - Register and confirm two dedicated non-staff production review accounts with fixed, reusable passwords: one requester/organizer and one helper/participant. Put both credential pairs only in Play Console App access and the operator-controlled password manager. - Create their stable synthetic `Play review` request and activity using `scripts/prepare-play-review.sh`. Verify both roles and every reviewer instruction from a clean Play-delivered installation. - Complete App content: App access, Ads, Content rating, Target audience, News-app declaration, Data Safety, foreground-service location declaration, any target-SDK-37 persistent precise-location declaration actually presented by Play, and the account-deletion URL. Use `android/play-store/location-and-fgs-declaration.md`; do not claim the app requests `ACCESS_BACKGROUND_LOCATION`. - Record and upload the foreground-service demonstration video from the exact candidate using the prepared evidence script. - Recheck the store listing, screenshots, support contact, and privacy-policy URL in Play Console against the prepared files under `android/play-store/`. ## Required immediately after the internal release is accepted - Record the Google Play App Signing SHA-1 and SHA-256. These are different from the upload-certificate fingerprints documented for the local artifact. - Add the Play App Signing fingerprints to the production Firebase Android app and production App Links association, then recheck domain verification. - Install the Play-delivered build from the internal-testing opt-in link and repeat production-origin, sign-in, push-notification, foreground/background location, stop-sharing, and App Link smoke tests. - Only after the Play-delivered build passes, prepare the closed test with at least 12 continuously opted-in testers for at least 14 days before requesting production access. ## Scope protection - Do not upload an older candidate or rebuild after choosing the upload AAB without recording a new source fingerprint and SHA-256. - Do not put reviewer passwords, service-account JSON, signing keys, `.env` files, or Play Console tokens in Git. - Do not update or restart the frozen hackathon test project as part of the Play release workflow.