who_need_help/android/play-store/data-safety.md

93 lines
6.2 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# Google Play Data Safety worksheet
This is a source-backed worksheet for the current Android build, not a submitted
Play Console declaration. Re-check it against the exact release AAB and the
current Play form immediately before submission.
## Form-level answers
- Does the app collect or share required user data types? **Yes, collects.**
- Is all user data encrypted in transit? **Yes.** Production app traffic uses
HTTPS; Firebase Cloud Messaging also uses encrypted transport.
- Can users request deletion? **Yes.**
- In-app path: account menu → account settings → delete-account request.
- External URL: `https://whoneedhelp.com/account/delete`.
- Does the app independently verify its security practices against a qualifying
standard? **No declaration.** Automated security checks are not an
independent certification.
- Does the app contain ads? **No.**
## Collected data types
| Play data type | Required or optional | Purposes | Current behavior/evidence |
| --- | --- | --- | --- |
| Personal info — Name | Required for an account | App functionality; account management; fraud prevention/security | Display name and profile are stored by the account system. |
| Personal info — Email address | Required for email accounts; supplied by Google for Google sign-in | App functionality; account management; security; support communications | Used for authentication, account notices, and support. |
| Personal info — User IDs | Required | App functionality; account management; fraud prevention/security | Internal account ID and connected identity identifiers. Provider access tokens are not persisted. |
| Personal info — Other info | Optional | App functionality; account management | Optional social-profile links and profile settings. |
| Location — Approximate location | Optional | App functionality; fraud prevention/security | Public request/activity location is rounded or hidden according to the user’s visibility choice. |
| Location — Precise location | Optional | App functionality; fraud prevention/security | Exact request/activity meeting point and opt-in live tracking. Exact points are restricted to relevant approved people. The current raw tracking point is deleted when sharing stops; derived evidence can remain. |
| Health and fitness — Health info | Optional, user-provided | App functionality | A medicine-help request can inherently reveal health-related context even though the UI prohibits prescriptions and unnecessary medical information. |
| App activity — App interactions | Required while using the service | App functionality; fraud prevention/security | Requests, matches, handovers, participation decisions, reviews, reports, moderation state, and safety evidence. |
| App activity — In-app search history | Optional; processed transiently | App functionality | Category, area, and map-viewport filters are sent to the server to return results and are not intentionally stored as a search-history profile. Select “processed ephemerally” if the current Play form offers it. |
| User-generated content — Other user-generated content | Optional | App functionality; fraud prevention/security; support | Request/activity descriptions, pickup instructions, private chat, reviews, category proposals, reports, and support messages. |
| Device or other IDs | Automatic for networked app functions | App functionality; fraud prevention/security | Firebase installation ID/FCM registration token, server session/security identifiers, and network identifiers exposed to the configured map-tile provider. No Google Analytics or Crashlytics SDK is included. |
## Data not collected by the current product
- Payment-card, bank-account, purchase-history, or payment-processing data.
Reimbursement happens outside the platform and sensitive payment data is
prohibited in messages.
- Contacts/address book.
- Email-message or mailbox content. The user’s authentication/contact address is
declared under **Personal info — Email address**; the app does not read or
import email messages.
- Photos, videos, audio, files, or documents.
- Advertising data.
- Google Analytics or Firebase Analytics events.
- Crashlytics crash reports.
## Sharing assessment
The current implementation sends data to:
1. The Who Need Help production server and its contracted infrastructure/service
providers to operate the product.
2. Google Firebase Cloud Messaging to deliver notifications.
3. The configured map-tile provider receives the client network request,
including its network identifier and requested tile coordinates.
4. Other users only through explicit product actions and visibility rules, such
as publishing an approximate area, accepting a match, approving an activity
participant, sending a message, or starting live sharing.
Google Play excludes some service-provider transfers and user-initiated sharing
from the “shared” declaration. The production map-tile provider and its
contractual/service-provider status are not yet confirmed, so the exact
top-level “shared” answer is currently **unknown**. Do not submit the form until
the final provider, its terms/data-processing role, and the exact release
network trace have been reviewed against the definitions shown by the current
Play form. If no exemption applies, declare the applicable device/network data
as shared.
## Source checks before every release
1. Compare this worksheet with `android/app/build.gradle.kts` and the resolved
release dependency report.
2. Confirm that Analytics, Crashlytics, ads, and delivery-metrics export remain
absent or update the declaration.
3. Confirm the final map-tile provider, provider agreement, request metadata,
and Play sharing classification.
4. Compare with `/privacy`, `/account/delete`, Android manifest permissions, and
the live-location prominent disclosure.
5. Confirm the external deletion URL loads without authentication and submits a
deletion request.
6. Update the worksheet if media uploads, avatars, payments, analytics, or any
new SDK is introduced.
## Official references
- https://support.google.com/googleplay/android-developer/answer/10787469
- https://support.google.com/googleplay/android-developer/answer/13327111
- https://firebase.google.com/docs/android/play-data-disclosure
- https://firebase.google.com/support/privacy/