who_need_help/android/play-store/location-and-fgs-declaration.md

11 KiB
Raw Permalink Blame History

Google Play location and foreground-service declaration

This file is the source copy for Play Console. It describes the exact current Android behavior; it is not evidence that Google Play has approved the feature. Reconcile every answer with the AAB selected for release.

Manifest and permission facts

  • Package: org.whoneedhelp.mobile
  • Target SDK: 37
  • Foreground service type: location
  • Foreground-service permissions: FOREGROUND_SERVICE and FOREGROUND_SERVICE_LOCATION
  • Runtime location permissions: ACCESS_COARSE_LOCATION and ACCESS_FINE_LOCATION
  • The app does not request ACCESS_BACKGROUND_LOCATION.
  • The app also declares USE_LOCATION_BUTTON for the separate one-time foreground action that places a request or activity point. It must not use onlyForLocationButton, because the distinct live-location flow also needs precise location after the user starts the foreground service.

Foreground-service declaration copy

Use case: User-initiated location sharing.

Feature using the service:

During an active mutual-aid assignment, an accepted requester or helper can explicitly start live location sharing with the matched participant. Who Need Help starts a location foreground service only after the user opens the active assignment, taps Share live location, reads the prominent disclosure, and grants Android location permission. A persistent notification remains visible for the full session and includes a Stop sharing action.

Why the task must start immediately:

The participant starts sharing to coordinate an active, time-sensitive handoff. Deferring the first update would show the matched participant stale or missing position information at the moment the user deliberately requested sharing.

Impact if Android interrupts the task:

New location updates stop. The app does not silently restart sharing. The user must return to the active assignment and start it again. The matched participant no longer receives a current position.

How it ends:

  • The user taps Stop sharing in the app or in the persistent notification.
  • Cancelling, withdrawing from, completing, or otherwise leaving the active assignment stops the native service through the server-driven terminal state.
  • The service also stops on an authorization or missing-assignment response.
  • Stopping removes the current raw location from the server. Limited derived safety evidence can remain as stated in the Privacy Policy.
  • Sharing is never started from boot, a background receiver, a push notification, or an unattended scheduled task.

Play Console answers

Use these only when the current Console wording matches the stated fact:

  • Foreground service type: Location
  • Closest preset use case: Background Location Updates — User-initiated location sharing
  • Core user benefit: safe coordination between the two people already matched for an active help request
  • Persistent notification: shown after the explicit in-app start and prominent disclosure, with a user-visible Stop action
  • Background-location runtime permission declared: No
  • Location foreground service declared: Yes

Google Play requires a foreground-service declaration for apps targeting Android 14 or newer. Do not describe this feature as passive, continuous, always-on, emergency, medical, or hidden tracking.

Video evidence script

Record one short, unlisted video from the exact Play candidate. Keep the phone screen readable and show the complete trigger path without cuts that hide a permission or disclosure screen.

  1. Start on an active synthetic request in which the signed-in reviewer is an accepted requester or helper.
  2. Scroll to live-location controls and tap Share live location.
  3. Pause on the prominent disclosure long enough to read what is collected, who receives it, minimized-app use, deletion, and the Stop action.
  4. Tap Continue and share and grant the Android location permission.
  5. Show the persistent Sharing live location system notification.
  6. Press Home so the app is minimized; show that the notification remains visible and that the matched browser receives a current synthetic position.
  7. Tap Stop sharing in the notification.
  8. Return to the request and show that sharing is stopped and the live marker is no longer available.

Do not use a real home address, real medical information, chat text, email, handover code, access token, or another person's location in the recording.

Retained operator copy

Earlier draft recordings were removed after the final Play-delivered evidence was approved. The retained operator copy is:

/home/simple/Downloads/Who-Need-Help-Google-Play-FGS-location-review.mp4

It is the verified 21.379802-second edit described below, not a separate draft.

Reproducible production fixture

The production operator script creates one run-scoped requester with a temporary password, one synthetic matched medicine request, and one accepted assignment for an existing confirmed helper. It refuses any root, Compose project, public origin, image, health state, or database other than the explicitly verified production values. It stores the exact IDs and temporary credentials only in ignored mode-0600 runtime files so cleanup can be resumed after a container restart.

Run the read-only plan first from /srv/who_need_help-production:

./scripts/production-play-physical-fixture.sh \
  plan HELPER_EMAIL --check-only whoneedhelp.com .env

Prepare the recording fixture only when the helper is signed into the exact Play-delivered build:

./scripts/production-play-physical-fixture.sh \
  prepare HELPER_EMAIL --confirm whoneedhelp.com .env

Use the printed temporary requester email and password in the recipient browser. Do not copy those credentials into documentation, Play Console, chat, email, or the recording. After location sharing starts, verify the server-side active state; after using the notification Stop action, verify deletion:

./scripts/production-play-physical-fixture.sh \
  verify-active --confirm whoneedhelp.com .env

./scripts/production-play-physical-fixture.sh \
  verify-stopped --confirm whoneedhelp.com .env

Always remove the fixture immediately after the recording, including after an aborted take:

./scripts/production-play-physical-fixture.sh \
  cleanup --confirm whoneedhelp.com .env

Cleanup stops an exact still-active fixture session before deleting its current raw position, tracking session, messages, notifications/jobs, assignment, request, temporary tokens/rate-limit buckets, and requester. It then verifies that the three primary fixture records were deleted and removes the local runtime state. Never delete the runtime manifest manually while its fixture may still exist.

Pre-submission evidence

  • Run ./scripts/android-play-policy-check.sh.
  • Run the signed release build and retain its manifest/package/signing reports.
  • Repeat start, Home/minimize, notification, Stop, and raw-position deletion on a Play-delivered internal-test install after Play App Signing is available.
  • Confirm the Privacy Policy, Data Safety form, store listing, disclosure, and Play Console declaration all describe the same behavior.

Foreground-service references rechecked on 2026-08-09:

The Play Help page was rechecked again on 2026-08-10. It still requires a video link for each declared foreground-service feature and recommends keeping the demonstration at 30 seconds or less. The final edit must therefore retain the user trigger, prominent disclosure, runtime prompt, minimized persistent notification, and notification Stop action while removing only idle time.

Play-delivered evidence take on 2026-08-10

The exact Play-delivered 0.1.2 (3) build produced a long evidence take at:

/g/home/Downloads/Who-Need-Help-Play-Console-location-sharing-FINAL-v4.mp4

Its SHA-256 is 56608ca3e2e1aafd7a85c325109581c379d4cb714794ba4c6c414706d451ff96. The file is 177.864689 seconds, H.264, and 720×1600. Visual review confirms the in-app trigger, prominent disclosure, Android runtime prompt, active in-app state, Home/minimized operation, and persistent notification with the visible Stop action. It contains no account email, fixture credentials, precise map, medical information, chat, or handover code.

This take is retained only as source evidence. The recorder reached its time limit before the notification Stop tap and stopped in-app state were captured, so it must not be submitted to Play Console as the final demonstration. The Stop action was performed immediately afterward: server verification observed 41 samples and zero retained raw positions, and exact fixture cleanup passed. A new concise take must visibly include Stop and the stopped state.

Final Play-delivered demonstration

The final concise demonstration was recorded on 2026-08-10 from the exact Google Play Internal-testing install 0.1.2 (3) and saved as:

output/android/play-console/wnh-fgs-review-final-v5.mp4

It is 21.379802 seconds, H.264, 720×1600, and its SHA-256 is 3c5f52019bf8a42ff42e1d9232afc126b62627390d74eed75084d82ecb33ac56. Visual review confirms that it shows the in-app trigger and prominent disclosure, Android location prompt, active sharing state, minimized-app persistent notification, visible notification Stop action, and the returned stopped state with Share location available again. It contains no account email, fixture credentials, precise map, medical information, chat, or handover code.

Server-side verification for the same take observed active tracking with a retained current position, then stopped tracking with zero retained raw positions. Exact cleanup deleted the run-scoped request, assignment, tracking session, and temporary requester; the protected runtime state and prepare log were removed. Production readiness remained healthy. The retained operator copy has the same SHA-256 and is stored at /home/simple/Downloads/Who-Need-Help-Google-Play-FGS-location-review.mp4.

The video was hosted as an unlisted YouTube Short at https://youtube.com/shorts/UZh_QBdlbBc. The authenticated Play Console foreground-service form was saved with User-initiated location sharing and this URL. This records the submitted form state; it is not a claim that Google has approved the declaration.

The remaining Play policy references were rechecked on 2026-08-10. The current Play Help still requires a video demonstration for the declared permission and accepts a YouTube link (preferred) or a cloud-hosted common video file. It also states that an unresolved declaration for an active bundle can prevent publishing other changes, including Store Presence. Refresh the pages again immediately before submitting because Play Help can change independently of the Android platform documentation: