14 KiB
Google Play release checklist
External account gate
- Google Play developer identity verification approved.
- Contact phone verification completed.
- Play Console enables Create app.
App identity and signing
- Create Android app
Who Need Helpwith packageorg.whoneedhelp.mobile. - Default language: English (United States).
- App: not a game; free; no ads.
- Accept Play App Signing.
- Record the upload-certificate SHA-1 and SHA-256 with the source-bound candidate.
- Record every Play App Signing SHA-1 and SHA-256 displayed by Play after
the first AAB upload makes Play generate its signing identities and
before any tester rollout. Do not assume that a new app has only one
Play certificate: current Play quantum-ready hybrid signing can expose
multiple classical/post-quantum identities for different Android
generations. The protected identity document records all three Play
identities shown for version
0.1.0 (1)plus the independent upload identity; no certificate values are stored in this public checklist. - Add every applicable Play App Signing SHA-1/SHA-256 identity to the production Google/Firebase Android configuration. A freshly downloaded production client configuration was validated after the import.
- Publish and verify
https://whoneedhelp.com/.well-known/assetlinks.jsonfor the Play certificate identities used to sign delivered APKs. Usescripts/import-play-android-config.shin plan mode first, then--apply; it must match every Play SHA-1 to the production Firebase Android OAuth client and preserve the upload identity.
Build
- Freeze the exact internal-release identity and localized release notes in
internal-release-v1.md; final save/publish remains a separate explicit external action. - Build from the exact committed candidate with the validated Android
allow-list read from the production checkout’s single
.env. - Run
scripts/android-release-build.sh. - Verify source fingerprint, signing certificate, bundletool validation, lint, package name, version code/name, target SDK, and production origin.
- Install the release APK generated from the same source-bound build on the authorized physical phone and run the release smoke test.
- Save and publish the source-bound AAB currently uploaded to the internal
testing draft. Do not mark this complete until Play Console shows one
accepted artifact and the internal release is available to testers. The
exact
0.1.0 (1)release is active only on the Internal testing track; no Closed or Production rollout was started. - Build and locally validate source-bound candidate
0.1.2 (3)from commitcd15476; release tests, lint, signing, bundle validation, App Links validation and API 37 instrumentation passed. The candidate is documented ininternal-release-v3.md; its subsequent Internal-track upload and Play-delivered verification are recorded in the next item. - Upload the exact recorded
0.1.2 (3)AAB to Internal testing, install it through Google Play and repeat the strict physical-device verification. Play Console showed release0.1.2 Location consent clarityavailable to internal testers on 2026-08-10 with one version code and no Closed or Production rollout. The installed package was delivered bycom.android.vending; its Play signing identity, version, verified production App Link, andMainActivityresolution passed the strict verifier. - Record and verify Internal release
0.1.3 (4). Play Console showed0.1.3 Reliable notificationsavailable to internal testers on 2026-08-25. The retained AAB SHA-256, Android source fingerprint, provenance limitation, and strict Play-delivered phone verification are recorded ininternal-release-v4.md. No Closed or Production release was created by this verification. A fresh read-only Console inspection on 2026-08-26 again showed version code4, version name0.1.3, target SDK 37, and status Available to internal testers on the Internal testing track.
Production capability gate
- On 2026-08-08, run the current candidate validator against the live
production
.envwith--require-server-release: all twelve capability checks reportedREADY, with zero blocking items and zero local-only warnings. The validator did not print secret values and did not modify production. - Pass the stricter
--require-releasegate. On 2026-08-09 the live production.envreported all twelve capabilitiesREADY, with zero blocking items and zero local-only warnings after the Play identities were imported.
Store presence
Complete the mandatory foreground-service declaration under App content before attempting to publish Store Presence changes. The current Play Help states that an unresolved permissions declaration for an active bundle can block publishing changes, including Store Listing, Pricing, and Distribution.
- 512×512 Play icon prepared.
- 1024×500 24-bit PNG feature graphic prepared.
- Four current 1080×1920 physical-phone screenshots captured and reviewed.
- English, Ukrainian, and Russian listing copy prepared.
- Alt-text copy (≤140 characters) prepared in
store-assets/README.md. - Revalidate the exact prepared listing text and visual assets immediately before Console entry. On 2026-08-10 the repository validator passed all three localized text limits, the 512×512 icon, the 1024×500 RGB feature graphic, and all four 1080×1920 RGB phone screenshots.
- Enter the prepared alt text if the current asset editor exposes that field. The read-only Dashboard summary does not expose saved per-asset alt text, so this detail remains unknown even though the overall Store listing task is complete.
- Choose category in the current Console options. Social was saved; tags were deliberately left empty rather than adding an inaccurate tag.
- Complete Select an app category and provide contact details in Play
Console. Read-only Store settings inspection on 2026-08-25 showed
category Social and public contact email
contact@whoneedhelp.com; phone and website were empty. A controlled inbound routing message sent to that address was observed once in the operator Gmail Inbox with theProjects/WhoNeedHelplabel. This proves the tested inbound forwarding route; it does not prove a standalone mailbox or reply-from identity. - Complete Set up your store listing in Play Console using the prepared copy and assets. A read-only Dashboard inspection on 2026-08-14 showed overall app setup at 10 of 11 tasks and marked this task complete.
- If the truthful category remains Social, publish and verify the
/child-safetystandards, select a monitored child-safety point of contact, verify that contact can access the urgent queue, and complete the Play child-safety self-certification only from observed operational evidence. Adult-only positioning does not remove this requirement for an app declared as Social. A repeated public check on 2026-08-10 returned200fromhttps://whoneedhelp.com/child-safetyafter production was observed on local revisiondafcdb36. The frozen hackathon test remains intentionally unchanged and returns404. The public page is only one gate: do not self-certify until the monitored contact and real escalation workflow are also verified. On 2026-08-26 the authenticated App content overview showed exactly one item under Need attention: Child safety standards. The declaration itself was still blank and its Save action was disabled. A simultaneous public request returned200and displayed the CSAE/CSAM standards and dedicated reporting path, but that technical evidence does not authorise the separate legal-compliance attestation.
App content
- Privacy policy URL saved as
https://whoneedhelp.com/privacy. - Ads declaration saved: no ads.
- Both App access accounts and both sides of the reviewer instructions tested from a clean Play-delivered install.
- Target audience/adult-only positioning saved as 18 and over.
- Content rating questionnaire completed and saved truthfully. The current Console result is BR 12+, North America Teen, Europe parental guidance, Germany 12+, and 12+ in the other displayed regions; this is a Console result, not a product age-verification claim.
- Local Data Safety worksheet reconciled with the source-bound candidate, a fresh resolved release dependency report, and the published privacy and account-deletion pages.
- Enter and review those reconciled answers in the current Play Console Data Safety form. The form was saved on 2026-08-09, and the overall Publishing overview was deliberately not sent for review.
- Account deletion questions and external URL completed.
- Government, financial, and health declarations saved from actual app behavior: not a government app, no financial features, and Healthcare services and management only. The app is not described as a medical service.
- Complete the mandatory Play Console foreground-service declaration for
the
locationservice used by the exact AAB. The authenticated form was saved with User-initiated location sharing. A saved declaration is submission evidence, not evidence of Google approval. - Upload the unlisted demonstration video showing the user-triggered start,
prominent disclosure, Android permission, persistent notification,
minimized-app operation, and Stop action. The final 21.379802-second
Play-delivered evidence file was visually and server-side verified,
hosted as an unlisted YouTube Short at
https://youtube.com/shorts/UZh_QBdlbBc, and saved in the declaration. Its retained path and checksum are recorded inlocation-and-fgs-declaration.md. Immediately before upload on 2026-08-10 the exact final file was revalidated as H.264, 720×1600, 21.379802 seconds, SHA-2563c5f52019bf8a42ff42e1d9232afc126b62627390d74eed75084d82ecb33ac56; a fresh contact-sheet review still showed the disclosure, Android prompt, minimized persistent notification with Stop, and returned stopped state. - Reconcile the target-SDK-37 location declaration with the exact artifact.
The saved use case is user-initiated location sharing. The app uses a
user-started location foreground service and does not declare
ACCESS_BACKGROUND_LOCATION; the form was not answered as if it requests the background-location runtime permission. - Use and verify the prepared declaration copy in
location-and-fgs-declaration.md.
Testing
- Internal track smoke test passed.
Before exercising product flows, run
scripts/verify-play-installed-android.shwith the protected Play identity document, physical-device serial, and exact expected version. It must confirm the Google Play installer, Play signing identity, verified production App Link, andMainActivityresolution. The 2026-08-09 v2 physical-device replay passed that verifier, Google sign-in, production App Link routing, Android notification permission, production FCM receipt and notification-tap routing. The same Play-delivered build then passed the separate consent-driven foreground location flow: explicit disclosure, Android permission, persistent notification, minimized-app sampling, notification Stop cleanup, offline/reconnect, and stopped-process recreation without sticky tracking. On 2026-08-10 the Play-delivered v3 install passed the strict delivery-boundary verifier and a new production fixture replay observed the disclosure, Android runtime prompt, active in-app state, minimized foreground-service notification, 41 server samples, notification Stop, and zero retained raw positions after Stop. The run-scoped fixture was then deleted and both production and frozen-test readiness remained healthy. This verifies observed app behavior; it does not complete the separate Play Console policy declarations or the final video above. The strict verifier passed again on 2026-08-10 after the physical phone was reconnected: Google Play installer, version0.1.2 (3), Play signing identity, verified production App Link, andMainActivityresolution all matched the protected production identity record. On 2026-08-25 the strict verifier also passed for the current Play-delivered0.1.3 (4)install: Google Play installer, a protected Play signing identity, verified production App Link, andMainActivityresolution all matched. The exact artifact record isinternal-release-v4.md. - Closed track created and opt-in link tested.
- At least 12 testers continuously opted in for 14 days.
- Tester feedback and fixes documented.
- Production-access questionnaire completed from actual evidence.
On 2026-08-25 the existing Closed testing - Alpha track was inactive with zero of four setup tasks complete. Countries and testers were not selected, and the track had no release. The current official requirement for this personal developer account was rechecked again on 2026-08-26 as at least 12 testers continuously opted in for at least 14 days before applying for Production access. No Closed or Production release was created during this inspection.
Publishing
- Managed publishing enabled if desired.
- Countries/regions and support contact reviewed.
- Production submission reviewed for accidental test URLs or credentials.
- Rollback and support/incident response are ready.
Official references:
- https://support.google.com/googleplay/android-developer/answer/9859152
- https://support.google.com/googleplay/android-developer/answer/9842756
- https://support.google.com/googleplay/android-developer/answer/9866151
- https://support.google.com/googleplay/android-developer/answer/9859455
- https://support.google.com/googleplay/android-developer/answer/10787469
- https://support.google.com/googleplay/android-developer/answer/13327111
- https://support.google.com/googleplay/android-developer/answer/14151465