who_need_help/android/play-store/release-checklist.md

7.7 KiB
Raw Blame History

Google Play release checklist

External account gate

  • Google Play developer identity verification approved.
  • Contact phone verification completed.
  • Play Console enables Create app.

App identity and signing

  • Create Android app Who Need Help with package org.whoneedhelp.mobile.
  • Default language: English (United States).
  • App: not a game; free; no ads.
  • Accept Play App Signing.
  • Record the upload-certificate SHA-1 and SHA-256 with the source-bound candidate.
  • Record every Play App Signing SHA-1 and SHA-256 displayed by Play after the first AAB upload makes Play generate its signing identities and before any tester rollout. Do not assume that a new app has only one Play certificate: current Play quantum-ready hybrid signing can expose multiple classical/post-quantum identities for different Android generations. The protected identity document records all three Play identities shown for version 0.1.0 (1) plus the independent upload identity; no certificate values are stored in this public checklist.
  • Add every applicable Play App Signing SHA-1/SHA-256 identity to the production Google/Firebase Android configuration. A freshly downloaded production client configuration was validated after the import.
  • Publish and verify https://whoneedhelp.com/.well-known/assetlinks.json for the Play certificate identities used to sign delivered APKs. Use scripts/import-play-android-config.sh in plan mode first, then --apply; it must match every Play SHA-1 to the production Firebase Android OAuth client and preserve the upload identity.

Build

  • Freeze the exact internal-release identity and localized release notes in internal-release-v1.md; final save/publish remains a separate explicit external action.
  • Build from the exact committed candidate with the validated Android allow-list read from the production checkout’s single .env.
  • Run scripts/android-release-build.sh.
  • Verify source fingerprint, signing certificate, bundletool validation, lint, package name, version code/name, target SDK, and production origin.
  • Install the release APK generated from the same source-bound build on the authorized physical phone and run the release smoke test.
  • Save and publish the source-bound AAB currently uploaded to the internal testing draft. Do not mark this complete until Play Console shows one accepted artifact and the internal release is available to testers. The exact 0.1.0 (1) release is active only on the Internal testing track; no Closed or Production rollout was started.

Production capability gate

  • On 2026-08-08, run the current candidate validator against the live production .env with --require-server-release: all twelve capability checks reported READY, with zero blocking items and zero local-only warnings. The validator did not print secret values and did not modify production.
  • Pass the stricter --require-release gate. On 2026-08-09 the live production .env reported all twelve capabilities READY, with zero blocking items and zero local-only warnings after the Play identities were imported.

Store presence

  • 512×512 Play icon prepared.
  • 1024×500 24-bit PNG feature graphic prepared.
  • Four current 1080×1920 physical-phone screenshots captured and reviewed.
  • English, Ukrainian, and Russian listing copy prepared.
  • Alt-text copy (≤140 characters) prepared in store-assets/README.md.
  • Enter the prepared alt text when the assets are uploaded in Play Console.
  • Choose category/tags in the current Console options.

App content

  • Privacy policy URL saved as https://whoneedhelp.com/privacy.
  • Ads declaration saved: no ads.
  • Both App access accounts and both sides of the reviewer instructions tested from a clean Play-delivered install.
  • Target audience/adult-only positioning saved as 18 and over.
  • Content rating questionnaire completed and saved truthfully. The current Console result is BR 12+, North America Teen, Europe parental guidance, Germany 12+, and 12+ in the other displayed regions; this is a Console result, not a product age-verification claim.
  • Local Data Safety worksheet reconciled with the source-bound candidate, a fresh resolved release dependency report, and the published privacy and account-deletion pages.
  • Enter and review those reconciled answers in the current Play Console Data Safety form. The form was saved on 2026-08-09, and the overall Publishing overview was deliberately not sent for review.
  • Account deletion questions and external URL completed.
  • Government, financial, and health declarations saved from actual app behavior: not a government app, no financial features, and Healthcare services and management only. The app is not described as a medical service.
  • Complete the mandatory Play Console foreground-service declaration for the location service used by the exact AAB.
  • Upload the unlisted demonstration video showing the user-triggered start, prominent disclosure, Android permission, persistent notification, minimized-app operation, and Stop action.
  • Reconcile any target-SDK-37 persistent precise-location declaration shown by Play Console with the exact artifact. The app uses a user-started location foreground service and does not declare ACCESS_BACKGROUND_LOCATION; do not answer that it requests the background-location runtime permission.
  • Use and verify the prepared declaration copy in location-and-fgs-declaration.md.

Testing

  • Internal track smoke test passed. Before exercising product flows, run scripts/verify-play-installed-android.sh with the protected Play identity document, physical-device serial, and exact expected version. It must confirm the Google Play installer, Play signing identity, verified production App Link, and MainActivity resolution. The 2026-08-09 physical-device replay passed that verifier, Google sign-in, production App Link routing, Android notification permission, production FCM receipt and notification-tap routing. The same Play-delivered build then passed the separate consent-driven foreground location flow: explicit disclosure, Android permission, persistent notification, minimized-app sampling, notification Stop cleanup, offline/reconnect, and stopped-process recreation without sticky tracking. This verifies observed app behavior; it does not complete the separate Play Console policy declarations above.
  • Closed track created and opt-in link tested.
  • At least 12 testers continuously opted in for 14 days.
  • Tester feedback and fixes documented.
  • Production-access questionnaire completed from actual evidence.

Publishing

  • Managed publishing enabled if desired.
  • Countries/regions and support contact reviewed.
  • Production submission reviewed for accidental test URLs or credentials.
  • Rollback and support/incident response are ready.

Official references: