178 lines
11 KiB
Markdown
178 lines
11 KiB
Markdown
# Google Play Data Safety worksheet
|
||
|
||
This is the source-backed worksheet for the current Android build. Its answers
|
||
were entered into Google Play Console and saved as a draft on 2026-08-09. The
|
||
overall Publishing overview was deliberately **not** sent for review. Re-check
|
||
the worksheet against the exact release AAB and the current Play form before a
|
||
future review submission.
|
||
|
||
## Form-level answers
|
||
|
||
- Does the app collect or share required user data types? **Yes, collects and
|
||
shares.** The conservative sharing declaration is required by the current
|
||
direct OpenStreetMap tile integration described below.
|
||
- Is all user data encrypted in transit? **Yes.** Production app traffic uses
|
||
HTTPS; Firebase Cloud Messaging also uses encrypted transport.
|
||
- Can users request deletion? **Yes.**
|
||
- In-app path: account menu → account settings → delete-account request.
|
||
- External URL: `https://whoneedhelp.com/account/delete`.
|
||
- Does the app independently verify its security practices against a qualifying
|
||
standard? **No declaration.** Automated security checks are not an
|
||
independent certification.
|
||
- Does the app contain ads? **No.**
|
||
|
||
## Collected data types
|
||
|
||
| Play data type | Required or optional | Purposes | Current behavior/evidence |
|
||
| --- | --- | --- | --- |
|
||
| Personal info — Name | Required for an account | App functionality; account management; fraud prevention/security | Display name and profile are stored by the account system. |
|
||
| Personal info — Email address | Required for email accounts; supplied by Google for Google sign-in | App functionality; account management; security; support communications | Used for authentication, account notices, and support. |
|
||
| Personal info — User IDs | Required | App functionality; account management; fraud prevention/security | Internal account ID and connected identity identifiers. Provider access tokens are not persisted. |
|
||
| Personal info — Other info | Optional | App functionality; account management | Optional social-profile links and profile settings. |
|
||
| Location — Approximate location | Optional | App functionality; fraud prevention/security | Public request/activity location is rounded or hidden according to the user’s visibility choice. |
|
||
| Location — Precise location | Optional | App functionality; fraud prevention/security | Exact request/activity meeting point and opt-in live tracking. Exact points are restricted to relevant approved people. The current raw tracking point is deleted when sharing stops; derived evidence can remain. |
|
||
| Health and fitness — Health info | Optional, user-provided | App functionality | A medicine-help request can inherently reveal health-related context even though the UI prohibits prescriptions and unnecessary medical information. |
|
||
| App activity — App interactions | Required while using the service | App functionality; fraud prevention/security | Requests, matches, handovers, participation decisions, reviews, reports, moderation state, and safety evidence. |
|
||
| App activity — In-app search history | Optional; processed transiently | App functionality | Category, area, and map-viewport filters are sent to the server to return results and are not intentionally stored as a search-history profile. Select “processed ephemerally” if the current Play form offers it. |
|
||
| User-generated content — Other user-generated content | Optional | App functionality; fraud prevention/security; support | Request/activity descriptions, pickup instructions, private chat, reviews, category proposals, reports, and support messages. |
|
||
| Device or other IDs | Automatic for networked app functions | App functionality; fraud prevention/security | Firebase installation ID/FCM registration token, server session/security identifiers, and network identifiers exposed to the configured map-tile provider. No Google Analytics or Crashlytics SDK is included. |
|
||
|
||
## Data not collected by the current product
|
||
|
||
- Payment-card, bank-account, purchase-history, or payment-processing data.
|
||
Reimbursement happens outside the platform and sensitive payment data is
|
||
prohibited in messages.
|
||
- Contacts/address book.
|
||
- Email-message or mailbox content. The user’s authentication/contact address is
|
||
declared under **Personal info — Email address**; the app does not read or
|
||
import email messages.
|
||
- Photos, videos, audio, files, or documents.
|
||
- Advertising data.
|
||
- Google Analytics or Firebase Analytics events.
|
||
- Crashlytics crash reports.
|
||
|
||
## Sharing assessment
|
||
|
||
The current implementation sends data to:
|
||
|
||
1. The Who Need Help production server and its contracted infrastructure/service
|
||
providers to operate the product.
|
||
2. Google Firebase Cloud Messaging to deliver notifications.
|
||
3. The configured map-tile provider receives the client network request,
|
||
including its network identifier and requested tile coordinates.
|
||
4. Other users only through explicit product actions and visibility rules, such
|
||
as publishing an approximate area, accepting a match, approving an activity
|
||
participant, sending a message, or starting live sharing.
|
||
|
||
Google Play excludes some service-provider transfers and user-initiated sharing
|
||
from the “shared” declaration. The current default production configuration
|
||
loads raster tiles directly from `tile.openstreetmap.org`; OSMF is an independent
|
||
third party and there is no verified service-provider agreement under which it
|
||
processes data solely on behalf of Who Need Help. OSMF's current privacy policy
|
||
says that requests to its services produce records including IP address,
|
||
browser/device type, operating system, referrer, time, and requested pages.
|
||
At detailed zoom levels, requested tile coordinates can also describe an area
|
||
smaller than 3 km².
|
||
|
||
Until the release uses a separately verified provider relationship, answer the
|
||
top-level sharing question **Yes** and conservatively declare these current
|
||
direct tile transfers:
|
||
|
||
- **Approximate location — shared, optional, app functionality.**
|
||
- **Precise location — shared, optional, app functionality.** This applies when
|
||
a user opens a detailed map around an exact or live point.
|
||
- **Device or other IDs — shared, required while maps are used, app
|
||
functionality.** This is the conservative classification for the network and
|
||
browser/application identifiers recorded by OSMF.
|
||
|
||
This is a disclosure choice, not permission to send private request text,
|
||
messages, email, handover codes, or raw live-location API payloads to the tile
|
||
provider; the current tile requests must remain limited to standard tile
|
||
coordinates and ordinary HTTP request metadata.
|
||
|
||
## Source checks before every release
|
||
|
||
1. Compare this worksheet with `android/app/build.gradle.kts` and the resolved
|
||
release dependency report.
|
||
2. Confirm that Analytics, Crashlytics, ads, and delivery-metrics export remain
|
||
absent or update the declaration.
|
||
3. Confirm the final map-tile provider, provider agreement, request metadata,
|
||
and Play sharing classification. If the direct OSMF integration remains,
|
||
keep the conservative sharing declarations above.
|
||
4. Compare with `/privacy`, `/account/delete`, Android manifest permissions, and
|
||
the live-location prominent disclosure.
|
||
5. Confirm the external deletion URL loads without authentication and submits a
|
||
deletion request.
|
||
6. Update the worksheet if media uploads, avatars, payments, analytics, or any
|
||
new SDK is introduced.
|
||
|
||
## 2026-07-31 release-candidate verification
|
||
|
||
- `releaseRuntimeClasspath` contains Firebase Cloud Messaging 25.1.1 and its
|
||
Firebase Installations dependency. It does not contain the Firebase
|
||
Analytics, Crashlytics, Performance Monitoring, or advertising SDKs.
|
||
- The manifest keeps FCM auto-initialization and Firebase Analytics collection
|
||
disabled. Push registration is enabled only after the user requests it in the
|
||
product UI.
|
||
- No call enabling BigQuery message-delivery export was found in the Android
|
||
source.
|
||
- Firebase's current Android disclosure reference says FCM automatically
|
||
collects the app version and Firebase user agent, while Firebase
|
||
Installations generates and collects a per-installation FID. The device-ID
|
||
row above conservatively accounts for the installation identifier.
|
||
- The exact dependency report is generated locally during release validation
|
||
and intentionally is not treated as a permanent substitute for re-checking
|
||
the final AAB and current Google Play form.
|
||
|
||
## 2026-08-08 pre-submission re-check
|
||
|
||
- The current Android source fingerprint is still
|
||
`f2f281210d11465d8f7fda20a78d1ed2527660d2e8a10a29ed31bf031a29ce43`,
|
||
which exactly matches the source-bound release candidate in
|
||
`android/dist-release-20260803-162910/`.
|
||
- A fresh `releaseRuntimeClasspath` report resolves
|
||
`firebase-messaging:25.1.1` and `firebase-installations:19.1.2`. It does not
|
||
resolve Firebase Analytics, Crashlytics, Performance Monitoring, an ads SDK,
|
||
or another product-analytics SDK.
|
||
- `firebase-measurement-connector:19.0.0` is present only as a transitive
|
||
dependency of `firebase-messaging:25.1.1`; Gradle `dependencyInsight`
|
||
confirms that it was not added by an Analytics dependency.
|
||
- The public production pages `/privacy`, `/terms`, and `/account/delete`
|
||
returned HTTP 200 without authentication. The published Privacy Policy
|
||
describes FCM/Firebase Installations, direct OpenStreetMap tile requests,
|
||
foreground live-location sharing, retention, and account-deletion controls.
|
||
- `https://whoneedhelp.com/.well-known/assetlinks.json` currently publishes the
|
||
upload-certificate SHA-256 only. Re-run this worksheet after the separate
|
||
Google Play App Signing certificate is added and before submitting the Play
|
||
Data Safety form.
|
||
|
||
## 2026-08-09 Play Console draft
|
||
|
||
- The Console draft records that the app collects and shares data, encrypts
|
||
data in transit, supports account creation through password/other
|
||
authentication and OAuth, and accepts deletion requests at
|
||
`https://whoneedhelp.com/account/delete`.
|
||
- The saved draft contains all twelve selected data types documented in this
|
||
worksheet: four Personal info types, two Location types, Health info, Other
|
||
in-app messages, three App activity types, and Device or other IDs.
|
||
- Approximate location, Precise location, and Device or other IDs are the only
|
||
types conservatively marked as shared. The sharing purpose is App
|
||
functionality.
|
||
- In-app search history is marked as optional and processed ephemerally. The
|
||
other selected types use the collection, optionality, retention, and purpose
|
||
answers documented in the tables above.
|
||
- The Console preview showed the expected collected/shared categories,
|
||
encryption statement, deletion URL, and Privacy Policy URL. The final form
|
||
save succeeded and Play directed the operator to Publishing overview.
|
||
- The operator chose **Not now**. This records a saved declaration draft; it is
|
||
not evidence of Google review or approval.
|
||
|
||
## Official references
|
||
|
||
- https://support.google.com/googleplay/android-developer/answer/10787469
|
||
- https://support.google.com/googleplay/android-developer/answer/13327111
|
||
- https://firebase.google.com/docs/android/play-data-disclosure
|
||
- https://firebase.google.com/support/privacy/
|
||
- https://operations.osmfoundation.org/policies/tiles/
|
||
- https://osmfoundation.org/wiki/Privacy_Policy
|