9.7 KiB
Google Play Data Safety worksheet
This is a source-backed worksheet for the current Android build, not a submitted Play Console declaration. Re-check it against the exact release AAB and the current Play form immediately before submission.
Form-level answers
- Does the app collect or share required user data types? Yes, collects and shares. The conservative sharing declaration is required by the current direct OpenStreetMap tile integration described below.
- Is all user data encrypted in transit? Yes. Production app traffic uses HTTPS; Firebase Cloud Messaging also uses encrypted transport.
- Can users request deletion? Yes.
- In-app path: account menu → account settings → delete-account request.
- External URL:
https://whoneedhelp.com/account/delete.
- Does the app independently verify its security practices against a qualifying standard? No declaration. Automated security checks are not an independent certification.
- Does the app contain ads? No.
Collected data types
| Play data type | Required or optional | Purposes | Current behavior/evidence |
|---|---|---|---|
| Personal info — Name | Required for an account | App functionality; account management; fraud prevention/security | Display name and profile are stored by the account system. |
| Personal info — Email address | Required for email accounts; supplied by Google for Google sign-in | App functionality; account management; security; support communications | Used for authentication, account notices, and support. |
| Personal info — User IDs | Required | App functionality; account management; fraud prevention/security | Internal account ID and connected identity identifiers. Provider access tokens are not persisted. |
| Personal info — Other info | Optional | App functionality; account management | Optional social-profile links and profile settings. |
| Location — Approximate location | Optional | App functionality; fraud prevention/security | Public request/activity location is rounded or hidden according to the user’s visibility choice. |
| Location — Precise location | Optional | App functionality; fraud prevention/security | Exact request/activity meeting point and opt-in live tracking. Exact points are restricted to relevant approved people. The current raw tracking point is deleted when sharing stops; derived evidence can remain. |
| Health and fitness — Health info | Optional, user-provided | App functionality | A medicine-help request can inherently reveal health-related context even though the UI prohibits prescriptions and unnecessary medical information. |
| App activity — App interactions | Required while using the service | App functionality; fraud prevention/security | Requests, matches, handovers, participation decisions, reviews, reports, moderation state, and safety evidence. |
| App activity — In-app search history | Optional; processed transiently | App functionality | Category, area, and map-viewport filters are sent to the server to return results and are not intentionally stored as a search-history profile. Select “processed ephemerally” if the current Play form offers it. |
| User-generated content — Other user-generated content | Optional | App functionality; fraud prevention/security; support | Request/activity descriptions, pickup instructions, private chat, reviews, category proposals, reports, and support messages. |
| Device or other IDs | Automatic for networked app functions | App functionality; fraud prevention/security | Firebase installation ID/FCM registration token, server session/security identifiers, and network identifiers exposed to the configured map-tile provider. No Google Analytics or Crashlytics SDK is included. |
Data not collected by the current product
- Payment-card, bank-account, purchase-history, or payment-processing data. Reimbursement happens outside the platform and sensitive payment data is prohibited in messages.
- Contacts/address book.
- Email-message or mailbox content. The user’s authentication/contact address is declared under Personal info — Email address; the app does not read or import email messages.
- Photos, videos, audio, files, or documents.
- Advertising data.
- Google Analytics or Firebase Analytics events.
- Crashlytics crash reports.
Sharing assessment
The current implementation sends data to:
- The Who Need Help production server and its contracted infrastructure/service providers to operate the product.
- Google Firebase Cloud Messaging to deliver notifications.
- The configured map-tile provider receives the client network request, including its network identifier and requested tile coordinates.
- Other users only through explicit product actions and visibility rules, such as publishing an approximate area, accepting a match, approving an activity participant, sending a message, or starting live sharing.
Google Play excludes some service-provider transfers and user-initiated sharing
from the “shared” declaration. The current default production configuration
loads raster tiles directly from tile.openstreetmap.org; OSMF is an independent
third party and there is no verified service-provider agreement under which it
processes data solely on behalf of Who Need Help. OSMF's current privacy policy
says that requests to its services produce records including IP address,
browser/device type, operating system, referrer, time, and requested pages.
At detailed zoom levels, requested tile coordinates can also describe an area
smaller than 3 km².
Until the release uses a separately verified provider relationship, answer the top-level sharing question Yes and conservatively declare these current direct tile transfers:
- Approximate location — shared, optional, app functionality.
- Precise location — shared, optional, app functionality. This applies when a user opens a detailed map around an exact or live point.
- Device or other IDs — shared, required while maps are used, app functionality. This is the conservative classification for the network and browser/application identifiers recorded by OSMF.
This is a disclosure choice, not permission to send private request text, messages, email, handover codes, or raw live-location API payloads to the tile provider; the current tile requests must remain limited to standard tile coordinates and ordinary HTTP request metadata.
Source checks before every release
- Compare this worksheet with
android/app/build.gradle.ktsand the resolved release dependency report. - Confirm that Analytics, Crashlytics, ads, and delivery-metrics export remain absent or update the declaration.
- Confirm the final map-tile provider, provider agreement, request metadata, and Play sharing classification. If the direct OSMF integration remains, keep the conservative sharing declarations above.
- Compare with
/privacy,/account/delete, Android manifest permissions, and the live-location prominent disclosure. - Confirm the external deletion URL loads without authentication and submits a deletion request.
- Update the worksheet if media uploads, avatars, payments, analytics, or any new SDK is introduced.
2026-07-31 release-candidate verification
releaseRuntimeClasspathcontains Firebase Cloud Messaging 25.1.1 and its Firebase Installations dependency. It does not contain the Firebase Analytics, Crashlytics, Performance Monitoring, or advertising SDKs.- The manifest keeps FCM auto-initialization and Firebase Analytics collection disabled. Push registration is enabled only after the user requests it in the product UI.
- No call enabling BigQuery message-delivery export was found in the Android source.
- Firebase's current Android disclosure reference says FCM automatically collects the app version and Firebase user agent, while Firebase Installations generates and collects a per-installation FID. The device-ID row above conservatively accounts for the installation identifier.
- The exact dependency report is generated locally during release validation and intentionally is not treated as a permanent substitute for re-checking the final AAB and current Google Play form.
2026-08-08 pre-submission re-check
- The current Android source fingerprint is still
f2f281210d11465d8f7fda20a78d1ed2527660d2e8a10a29ed31bf031a29ce43, which exactly matches the source-bound release candidate inandroid/dist-release-20260803-162910/. - A fresh
releaseRuntimeClasspathreport resolvesfirebase-messaging:25.1.1andfirebase-installations:19.1.2. It does not resolve Firebase Analytics, Crashlytics, Performance Monitoring, an ads SDK, or another product-analytics SDK. firebase-measurement-connector:19.0.0is present only as a transitive dependency offirebase-messaging:25.1.1; GradledependencyInsightconfirms that it was not added by an Analytics dependency.- The public production pages
/privacy,/terms, and/account/deletereturned HTTP 200 without authentication. The published Privacy Policy describes FCM/Firebase Installations, direct OpenStreetMap tile requests, foreground live-location sharing, retention, and account-deletion controls. https://whoneedhelp.com/.well-known/assetlinks.jsoncurrently publishes the upload-certificate SHA-256 only. Re-run this worksheet after the separate Google Play App Signing certificate is added and before submitting the Play Data Safety form.
Official references
- https://support.google.com/googleplay/android-developer/answer/10787469
- https://support.google.com/googleplay/android-developer/answer/13327111
- https://firebase.google.com/docs/android/play-data-disclosure
- https://firebase.google.com/support/privacy/
- https://operations.osmfoundation.org/policies/tiles/
- https://osmfoundation.org/wiki/Privacy_Policy