# Google Play release checklist ## External account gate - [x] Google Play developer identity verification approved. - [x] Contact phone verification completed. - [x] Play Console enables **Create app**. ## App identity and signing - [x] Create Android app `Who Need Help` with package `org.whoneedhelp.mobile`. - [x] Default language: English (United States). - [x] App: not a game; free; no ads. - [x] Accept Play App Signing. - [x] Record the upload-certificate SHA-1 and SHA-256 with the source-bound candidate. - [ ] Record the distinct Play App Signing SHA-1 and SHA-256 after Play accepts the first internal release. - [ ] Add the Play App Signing SHA-256 to production Google/Firebase Android configuration. - [ ] Publish and verify `https://whoneedhelp.com/.well-known/assetlinks.json` for the Play certificate. ## Build - [x] Build from the exact committed candidate with the validated Android allow-list read from the production checkout’s single `.env`. - [x] Run `scripts/android-release-build.sh`. - [x] Verify source fingerprint, signing certificate, bundletool validation, lint, package name, version code/name, target SDK, and production origin. - [x] Install the release APK generated from the same source-bound build on the authorized physical phone and run the release smoke test. - [ ] Save and publish the source-bound AAB currently uploaded to the internal testing draft. Do not mark this complete until Play Console shows one accepted artifact and the internal release is available to testers. ## Store presence - [x] 512×512 Play icon prepared. - [x] 1024×500 24-bit PNG feature graphic prepared. - [x] Four current 1080×1920 physical-phone screenshots captured and reviewed. - [x] English, Ukrainian, and Russian listing copy prepared. - [x] Alt-text copy (≤140 characters) prepared in `store-assets/README.md`. - [ ] Enter the prepared alt text when the assets are uploaded in Play Console. - [ ] Choose category/tags in the current Console options. ## App content - [ ] Privacy policy URL. - [ ] Ads declaration: no ads. - [ ] Both App access accounts and both sides of the reviewer instructions tested from a clean Play-delivered install. - [ ] Target audience/adult-only positioning confirmed. - [ ] Content rating questionnaire completed truthfully. - [ ] Data Safety worksheet reconciled with the final dependency report. - [ ] Account deletion questions and external URL completed. - [ ] Government/news/financial/health declarations answered from actual app behavior; do not describe the app as a medical service. - [ ] Foreground-service/location declarations completed from the exact AAB if Play Console asks. The current source requests coarse/fine foreground location and a location foreground service; it does not declare `ACCESS_BACKGROUND_LOCATION`. Re-check the uploaded artifact rather than inferring the Console form from this note. ## Testing - [ ] Internal track smoke test passed. - [ ] Closed track created and opt-in link tested. - [ ] At least 12 testers continuously opted in for 14 days. - [ ] Tester feedback and fixes documented. - [ ] Production-access questionnaire completed from actual evidence. ## Publishing - [ ] Managed publishing enabled if desired. - [ ] Countries/regions and support contact reviewed. - [ ] Production submission reviewed for accidental test URLs or credentials. - [ ] Rollback and support/incident response are ready. Official references: - https://support.google.com/googleplay/android-developer/answer/9859152 - https://support.google.com/googleplay/android-developer/answer/9866151 - https://support.google.com/googleplay/android-developer/answer/9859455 - https://support.google.com/googleplay/android-developer/answer/10787469 - https://support.google.com/googleplay/android-developer/answer/13327111 - https://support.google.com/googleplay/android-developer/answer/14151465