who_need_help/docs/google-play-child-safety-audit-2026-08-26.md

66 lines
4.4 KiB
Markdown

# Google Play child-safety audit, 2026-08-26
This note compares the current Google Play Child Safety Standards policy with
the release candidate, the deployed production site, and the Play-delivered
Android build. It records technical evidence only. It does not replace the
operator's legal review or authorize submitting the Play Console declaration.
## Official requirements
Who Need Help is in scope because its Play Console category is Social. The
policy still applies when an app is adults-only. Google requires an in-scope
app to:
1. publish globally accessible standards that prohibit child sexual abuse and
exploitation;
2. provide a reporting or feedback mechanism that users can reach without
leaving the app;
3. act on child sexual abuse material after obtaining actual knowledge of it;
4. maintain a process for reporting confirmed CSAM to NCMEC or the relevant
regional authority as required by applicable law; and
5. name an individual in Play Console who can explain and act on the app's
child-safety procedures.
Google says the public standards must load, cover CSAE or child safety, and
name the app or developer shown on the store listing. Google accepts an
in-app report flow, support email, or chat channel as the feedback mechanism
provided the user can reach it without leaving the app.
Primary sources:
- [Google Play Child Endangerment policy](https://support.google.com/googleplay/android-developer/answer/9878809?hl=en)
- [Google Play Child Safety Standards guidance](https://support.google.com/googleplay/android-developer/answer/14747720?hl=en)
- [Google Play policy update announced 15 July 2026](https://support.google.com/googleplay/android-developer/answer/17134731?hl=en)
## Observed product evidence
| Requirement | Evidence observed on 2026-08-26 | Result |
| --- | --- | --- |
| Public standards | `https://whoneedhelp.com/child-safety` returned HTTP 200. The page names Who Need Help, explicitly prohibits CSAE and CSAM, describes prohibited conduct, explains reporting, and links to the report form. | Technical requirement present |
| In-app feedback | The footer exposes Child safety and Report content on every application page. On the physical device `72551e60`, the Play-delivered `org.whoneedhelp.mobile` version `0.1.3 (4)` opened Child safety inside `MainActivity`. Tapping Report child-safety content opened the same-origin report form inside the app. | Technical requirement present |
| Report classification | The report form opened with Sexual material involving a minor selected. `ContentRemoval.create_notice/3` assigns an anonymous report in this category the `urgent_review` status. The form does not accept an evidence upload. | Technical requirement present |
| Content and account action | Staff permissions and audited operations can hide reported requests or activities, restrict access, and suspend accounts. The published standard says automated signals can prioritize a case but do not prove it. | Technical controls present |
| Authority reporting process | `docs/trust-safety.md` instructs the responsible operator to report confirmed CSAM to NCMEC or the relevant regional authority when applicable law requires it. The public standard states the same process. | Written process present, legal review still required |
| Child-safety contact | The protected support and legal queues exist, but Play requires the developer to name a real individual who can receive Google's notices, explain the procedures, and take action. Code cannot select or attest for that person. | Operator action required |
No report or support request was submitted during the device check. The app
remained the foreground activity throughout the navigation.
## What remains before self-certification
Do not submit the Play declaration until the operator has done all of the
following:
- selected a real, monitored child-safety contact and entered that person's
name and contact details in Play Console;
- confirmed that the person can open the urgent legal queue and suspend or
restrict an account through the staff workspace;
- tested inbound mail from Google Play to the selected address;
- reviewed the reporting authority and mandatory reporting procedure for each
launch jurisdiction; and
- personally reviewed the declaration wording before submitting the legal
self-certification.
The software and deployed reporting path are ready for that review. Legal
compliance and the truth of the Play self-certification remain human decisions.