who_need_help/docs/google-play-pre-upload-audit-2026-08-03.md

4.6 KiB

Google Play pre-upload audit — 2026-08-03

This audit separates verified repository/device facts from actions that still require Play Console. It contains no account credentials or signing keys.

Verified locally

  • The selected upload artifact and its checksum are recorded in docs/google-play-release-candidate-2026-08-03.md.
  • Package org.whoneedhelp.mobile, version code 1, version name 0.1.0, minimum SDK 24, and target SDK 37 were verified from the release build.
  • Release unit tests, lint, R8, signing verification, and bundletool validation passed. The release lint report contains no errors or warnings.
  • The native disclosure appears before the location permission flow and explicitly describes precise-location collection and transmission, background use while minimized or not in use, persistent notification, stopping, raw-location deletion, and retained summary evidence.
  • English, Russian, and Ukrainian disclosure and store-listing text describe the same behavior.
  • The public Privacy page identifies Firebase Cloud Messaging and Firebase Installations, the current OpenStreetMap Foundation tile service, and the Android foreground location service behavior.
  • Public Privacy, Terms, Safety, Support, content-reporting, and account-deletion routes exist in the product. Reviewer guidance is recorded in android/play-store/review-access.md.
  • The release APK was installed on the authorised Android 16 physical device. The production home and Safety pages rendered, the production App Link opened MainActivity, and Android reported whoneedhelp.com as verified.
  • The clean PID-scoped application log contains no application crash, AndroidRuntime, TLS/SSL, or WebView load error.
  • No analytics SDK is declared as active in the Android application. Data Safety answers must still describe the behavior of Firebase Messaging/Installations and the app's own server communication.

Verified Play Console state

  • The personal developer identity and contact phone are verified.
  • The Play application exists as app ID 4972430103169452589, package org.whoneedhelp.mobile; it is a free app, not a game, with no ads.
  • Play App Signing was accepted.
  • The exact version-code 1 release AAB is retained in an internal-testing draft. The internal release is not yet available to testers, so its Play-generated signing identity and Play-delivered behavior remain unknown.

Required before Play review

  • Register and confirm two dedicated non-staff production review accounts with fixed, reusable passwords: one requester/organizer and one helper/participant. Put both credential pairs only in Play Console App access and the operator-controlled password manager.
  • Create their stable synthetic Play review request and activity using scripts/prepare-play-review.sh. Verify both roles and every reviewer instruction from a clean Play-delivered installation.
  • Complete App content: App access, Ads, Content rating, Target audience, News-app declaration, Data Safety, foreground-service location declaration, any target-SDK-37 persistent precise-location declaration actually presented by Play, and the account-deletion URL. Use android/play-store/location-and-fgs-declaration.md; do not claim the app requests ACCESS_BACKGROUND_LOCATION.
  • Record and upload the foreground-service demonstration video from the exact candidate using the prepared evidence script.
  • Recheck the store listing, screenshots, support contact, and privacy-policy URL in Play Console against the prepared files under android/play-store/.

Required immediately after the internal release is accepted

  • Record the Google Play App Signing SHA-1 and SHA-256. These are different from the upload-certificate fingerprints documented for the local artifact.
  • Add the Play App Signing fingerprints to the production Firebase Android app and production App Links association, then recheck domain verification.
  • Install the Play-delivered build from the internal-testing opt-in link and repeat production-origin, sign-in, push-notification, foreground/background location, stop-sharing, and App Link smoke tests.
  • Only after the Play-delivered build passes, prepare the closed test with at least 12 continuously opted-in testers for at least 14 days before requesting production access.

Scope protection

  • Do not upload an older candidate or rebuild after choosing the upload AAB without recording a new source fingerprint and SHA-256.
  • Do not put reviewer passwords, service-account JSON, signing keys, .env files, or Play Console tokens in Git.
  • Do not update or restart the frozen hackathon test project as part of the Play release workflow.