2.3 KiB
2.3 KiB
Google Play review access
The app has public pages, email/passwordless authentication, password authentication, and Google sign-in. Reviewers must be able to inspect restricted functionality without contacting a real requester or sharing real personal/medical information.
Recommended reviewer instructions
- Open the app. The product home, Safety, Privacy, Terms, Support, content reporting, and Account deletion pages are available without a reviewer account. Request, activity, category-proposal, profile, notification, and moderation LiveViews require authentication.
- For authenticated functionality, use the dedicated production reviewer account prepared immediately before submission.
- Expand Use a password instead, then enter the dedicated reviewer email and password supplied in Play Console. Do not use an email link or Google sign-in for review: the supplied password must remain reusable, always available, and independent of a developer mailbox or one-time code.
- Use only the pre-created synthetic requests and activity. Their titles must
start with
Play review. - A second synthetic account must already be assigned as the counterpart so the reviewer can inspect chat, optional tracking controls, handover, withdrawal, reviews, blocking, reporting, support, privacy, and account deletion.
Submission-time values
Do not store credentials here or in Git. Put them only in Play Console’s app access field:
- Reviewer email: create at release time.
- Reviewer password: create at release time and store only in Play Console and the operator-controlled password manager.
- Stable synthetic request URL: create at release time.
- Stable synthetic activity URL: create at release time.
- Support contact:
contact@whoneedhelp.com.
Verification before submission
- Test the exact instructions in a clean Android install from the Play track.
- Confirm they do not depend on a developer browser session, VPN, localhost, expiring fixture, or test/staging domain.
- Confirm the reviewer account is not a moderator or administrator.
- Confirm all data is synthetic and no real user can be messaged or located.
- Confirm the password works from a clean Play-delivered install without a second factor, one-time code, developer browser session, or location gate.