# Google Play Data Safety worksheet This is the source-backed worksheet for the current Android build. Its answers were entered into Google Play Console and saved as a draft on 2026-08-09. The overall Publishing overview was deliberately **not** sent for review. Re-check the worksheet against the exact release AAB and the current Play form before a future review submission. ## Form-level answers - Does the app collect or share required user data types? **Yes, collects and shares.** The conservative sharing declaration is required by the current direct OpenStreetMap tile integration described below. - Is all user data encrypted in transit? **Yes.** Production app traffic uses HTTPS; Firebase Cloud Messaging also uses encrypted transport. - Can users request deletion? **Yes.** - In-app path: account menu → account settings → delete-account request. - External URL: `https://whoneedhelp.com/account/delete`. - Does the app independently verify its security practices against a qualifying standard? **No declaration.** Automated security checks are not an independent certification. - Does the app contain ads? **No.** ## Collected data types | Play data type | Required or optional | Purposes | Current behavior/evidence | | --- | --- | --- | --- | | Personal info — Name | Required for an account | App functionality; account management; fraud prevention/security | Display name and profile are stored by the account system. | | Personal info — Email address | Required for email accounts; supplied by Google for Google sign-in | App functionality; account management; security; support communications | Used for authentication, account notices, and support. | | Personal info — User IDs | Required | App functionality; account management; fraud prevention/security | Internal account ID and connected identity identifiers. Provider access tokens are not persisted. | | Personal info — Other info | Optional | App functionality; account management | Optional social-profile links and profile settings. | | Location — Approximate location | Optional | App functionality; fraud prevention/security | Public request/activity location is rounded or hidden according to the user’s visibility choice. | | Location — Precise location | Optional | App functionality; fraud prevention/security | Exact request/activity meeting point and opt-in live tracking. Exact points are restricted to relevant approved people. The current raw tracking point is deleted when sharing stops; derived evidence can remain. | | Health and fitness — Health info | Optional, user-provided | App functionality | A medicine-help request can inherently reveal health-related context even though the UI prohibits prescriptions and unnecessary medical information. | | App activity — App interactions | Required while using the service | App functionality; fraud prevention/security | Requests, matches, handovers, participation decisions, reviews, reports, moderation state, and safety evidence. | | App activity — In-app search history | Optional; processed transiently | App functionality | Category, area, and map-viewport filters are sent to the server to return results and are not intentionally stored as a search-history profile. Select “processed ephemerally” if the current Play form offers it. | | User-generated content — Other user-generated content | Optional | App functionality; fraud prevention/security; support | Request/activity descriptions, pickup instructions, private chat, reviews, category proposals, reports, and support messages. | | Device or other IDs | Automatic for networked app functions | App functionality; fraud prevention/security | Firebase installation ID/FCM registration token, server session/security identifiers, and network identifiers exposed to the configured map-tile provider. No Google Analytics or Crashlytics SDK is included. | ## Data not collected by the current product - Payment-card, bank-account, purchase-history, or payment-processing data. Reimbursement happens outside the platform and sensitive payment data is prohibited in messages. - Contacts/address book. - Email-message or mailbox content. The user’s authentication/contact address is declared under **Personal info — Email address**; the app does not read or import email messages. - Photos, videos, audio, files, or documents. - Advertising data. - Google Analytics or Firebase Analytics events. - Crashlytics crash reports. ## Sharing assessment The current implementation sends data to: 1. The Who Need Help production server and its contracted infrastructure/service providers to operate the product. 2. Google Firebase Cloud Messaging to deliver notifications. 3. The configured map-tile provider receives the client network request, including its network identifier and requested tile coordinates. 4. Other users only through explicit product actions and visibility rules, such as publishing an approximate area, accepting a match, approving an activity participant, sending a message, or starting live sharing. Google Play excludes some service-provider transfers and user-initiated sharing from the “shared” declaration. The current default production configuration loads raster tiles directly from `tile.openstreetmap.org`; OSMF is an independent third party and there is no verified service-provider agreement under which it processes data solely on behalf of Who Need Help. OSMF's current privacy policy says that requests to its services produce records including IP address, browser/device type, operating system, referrer, time, and requested pages. At detailed zoom levels, requested tile coordinates can also describe an area smaller than 3 km². Until the release uses a separately verified provider relationship, answer the top-level sharing question **Yes** and conservatively declare these current direct tile transfers: - **Approximate location — shared, optional, app functionality.** - **Precise location — shared, optional, app functionality.** This applies when a user opens a detailed map around an exact or live point. - **Device or other IDs — shared, required while maps are used, app functionality.** This is the conservative classification for the network and browser/application identifiers recorded by OSMF. This is a disclosure choice, not permission to send private request text, messages, email, handover codes, or raw live-location API payloads to the tile provider; the current tile requests must remain limited to standard tile coordinates and ordinary HTTP request metadata. ## Source checks before every release 1. Compare this worksheet with `android/app/build.gradle.kts` and the resolved release dependency report. 2. Confirm that Analytics, Crashlytics, ads, and delivery-metrics export remain absent or update the declaration. 3. Confirm the final map-tile provider, provider agreement, request metadata, and Play sharing classification. If the direct OSMF integration remains, keep the conservative sharing declarations above. 4. Compare with `/privacy`, `/account/delete`, Android manifest permissions, and the live-location prominent disclosure. 5. Confirm the external deletion URL loads without authentication and submits a deletion request. 6. Update the worksheet if media uploads, avatars, payments, analytics, or any new SDK is introduced. ## 2026-07-31 release-candidate verification - `releaseRuntimeClasspath` contains Firebase Cloud Messaging 25.1.1 and its Firebase Installations dependency. It does not contain the Firebase Analytics, Crashlytics, Performance Monitoring, or advertising SDKs. - The manifest keeps FCM auto-initialization and Firebase Analytics collection disabled. Push registration is enabled only after the user requests it in the product UI. - No call enabling BigQuery message-delivery export was found in the Android source. - Firebase's current Android disclosure reference says FCM automatically collects the app version and Firebase user agent, while Firebase Installations generates and collects a per-installation FID. The device-ID row above conservatively accounts for the installation identifier. - The exact dependency report is generated locally during release validation and intentionally is not treated as a permanent substitute for re-checking the final AAB and current Google Play form. ## 2026-08-08 pre-submission re-check - The current Android source fingerprint is still `f2f281210d11465d8f7fda20a78d1ed2527660d2e8a10a29ed31bf031a29ce43`, which exactly matches the source-bound release candidate in `android/dist-release-20260803-162910/`. - A fresh `releaseRuntimeClasspath` report resolves `firebase-messaging:25.1.1` and `firebase-installations:19.1.2`. It does not resolve Firebase Analytics, Crashlytics, Performance Monitoring, an ads SDK, or another product-analytics SDK. - `firebase-measurement-connector:19.0.0` is present only as a transitive dependency of `firebase-messaging:25.1.1`; Gradle `dependencyInsight` confirms that it was not added by an Analytics dependency. - The public production pages `/privacy`, `/terms`, and `/account/delete` returned HTTP 200 without authentication. The published Privacy Policy describes FCM/Firebase Installations, direct OpenStreetMap tile requests, foreground live-location sharing, retention, and account-deletion controls. - `https://whoneedhelp.com/.well-known/assetlinks.json` currently publishes the upload-certificate SHA-256 only. Re-run this worksheet after the separate Google Play App Signing certificate is added and before submitting the Play Data Safety form. ## 2026-08-09 Play Console draft - The Console draft records that the app collects and shares data, encrypts data in transit, supports account creation through password/other authentication and OAuth, and accepts deletion requests at `https://whoneedhelp.com/account/delete`. - The saved draft contains all twelve selected data types documented in this worksheet: four Personal info types, two Location types, Health info, Other in-app messages, three App activity types, and Device or other IDs. - Approximate location, Precise location, and Device or other IDs are the only types conservatively marked as shared. The sharing purpose is App functionality. - In-app search history is marked as optional and processed ephemerally. The other selected types use the collection, optionality, retention, and purpose answers documented in the tables above. - The Console preview showed the expected collected/shared categories, encryption statement, deletion URL, and Privacy Policy URL. The final form save succeeded and Play directed the operator to Publishing overview. - The operator chose **Not now**. This records a saved declaration draft; it is not evidence of Google review or approval. ## Official references - https://support.google.com/googleplay/android-developer/answer/10787469 - https://support.google.com/googleplay/android-developer/answer/13327111 - https://firebase.google.com/docs/android/play-data-disclosure - https://firebase.google.com/support/privacy/ - https://operations.osmfoundation.org/policies/tiles/ - https://osmfoundation.org/wiki/Privacy_Policy