docs(play): add privacy policy, data-safety mapping, and permissions justification #97

Merged
JMR-dev merged 3 commits from feat-play-compliance into main 2026-07-02 03:52:21 +00:00
JMR-dev commented 2026-07-02 02:53:19 +00:00 (Migrated from github.com)

Part of #17 — the repo-actionable half of the Google Play compliance work. Console/form submission stays with the maintainer; these docs make those steps mechanical. Every claim is verified against the code, the merged release manifest, and the built release AAB.

Deliverables → issue checklist

#17 checklist item Delivered here
Data safety form + privacy policy PRIVACY.md (link this URL in the Console) + docs/play-data-safety.md (category-by-category answers with code evidence; recommends "no data collected/shared" with a conservative fallback; dependency audit shows no ads/analytics SDKs and no AD_ID)
Permissions justification docs/play-permissions.md — full merged-manifest audit (incl. WorkManager-injected WAKE_LOCK/RECEIVE_BOOT_COMPLETED), paste-ready justifications for READ_CONTACTS (on-device autocomplete only), POST_NOTIFICATIONS, and the FOREGROUND_SERVICE_DATA_SYNC Console declaration + demo-video script
Target API / 16 KB / AAB docs/play-compliance.md §1–3 — targetSdk 37 (requirement: 35+, PASS); 16 KB PASS, verified empirically: all packaged .so (sqlcipher-android 4.16.0, androidx graphics-path, datastore 1.2.1) have PT_LOAD p_align=0x4000 on all 4 ABIs; :app:bundleRelease produces the AAB (signing = human step, debug-key fallback documented)
OAuth / CASA docs/play-compliance.md §4 — verified in source: Gmail is app-password IMAP (no Google OAuth client/scopes anywhere) → no Google restricted-scope verification / CASA; Outlook OAuth is Microsoft/Azure-side only. README privacy section now links PRIVACY.md + states this; fuller README pass remains #20
Content rating, listing assets, account deletion docs/play-compliance.md §5 — IARC draft answers (expected Everyone / Users Interact), asset spec + drafted short/full descriptions, and the truthful account-deletion position (no developer accounts → Play deletion-URL requirement n/a; documented what deleteAccount actually removes)

Remaining human console steps (detailed in docs/play-compliance.md §5)

  1. Developer account + create app (Free, Communication).
  2. Store listing: 512×512 icon, 1024×500 feature graphic, 2–8 screenshots; paste drafted descriptions; set privacy-policy URL to PRIVACY.md.
  3. App content forms: data safety (per docs/play-data-safety.md), FGS dataSync declaration + demo video (per docs/play-permissions.md), content rating, target audience 13+, ads = No, app-access test account.
  4. Create the upload keystore, fill secrets.properties, rebuild, enroll in Play App Signing, upload to Internal testing, check App bundle explorer (16 KB verdict) + pre-launch report.

Findings needing maintainer attention (docs/play-compliance.md §6)

  1. "Push mail" defaults ON (SettingsRepository.kt:41) while the manifest comment/README call it opt-in — flip the default or fix the comments; the drafted FGS declaration describes actual behavior.
  2. README says minSdk 33; build is 29 (#20).
  3. README advertises a biometric app lock that isn't in the code yet — PRIVACY.md deliberately doesn't claim it (#20).
  4. Release builds fall back to the debug key without secrets.properties — fine for CI, not for the Play upload.

🤖 Generated with Claude Code

Part of #17 — the repo-actionable half of the Google Play compliance work. Console/form submission stays with the maintainer; these docs make those steps mechanical. Every claim is verified against the code, the merged release manifest, and the built release AAB. ## Deliverables → issue checklist | #17 checklist item | Delivered here | |---|---| | Data safety form + privacy policy | `PRIVACY.md` (link this URL in the Console) + `docs/play-data-safety.md` (category-by-category answers with code evidence; recommends "no data collected/shared" with a conservative fallback; dependency audit shows no ads/analytics SDKs and no `AD_ID`) | | Permissions justification | `docs/play-permissions.md` — full merged-manifest audit (incl. WorkManager-injected `WAKE_LOCK`/`RECEIVE_BOOT_COMPLETED`), paste-ready justifications for `READ_CONTACTS` (on-device autocomplete only), `POST_NOTIFICATIONS`, and the `FOREGROUND_SERVICE_DATA_SYNC` Console declaration + demo-video script | | Target API / 16 KB / AAB | `docs/play-compliance.md` §1–3 — **targetSdk 37** (requirement: 35+, PASS); **16 KB PASS**, verified empirically: all packaged `.so` (sqlcipher-android 4.16.0, androidx graphics-path, datastore 1.2.1) have `PT_LOAD p_align=0x4000` on all 4 ABIs; `:app:bundleRelease` produces the AAB (signing = human step, debug-key fallback documented) | | OAuth / CASA | `docs/play-compliance.md` §4 — verified in source: Gmail is app-password IMAP (no Google OAuth client/scopes anywhere) → **no Google restricted-scope verification / CASA**; Outlook OAuth is Microsoft/Azure-side only. README privacy section now links `PRIVACY.md` + states this; fuller README pass remains #20 | | Content rating, listing assets, account deletion | `docs/play-compliance.md` §5 — IARC draft answers (expected Everyone / Users Interact), asset spec + drafted short/full descriptions, and the truthful account-deletion position (no developer accounts → Play deletion-URL requirement n/a; documented what `deleteAccount` actually removes) | ## Remaining human console steps (detailed in `docs/play-compliance.md` §5) 1. Developer account + create app (Free, Communication). 2. Store listing: 512×512 icon, 1024×500 feature graphic, 2–8 screenshots; paste drafted descriptions; set privacy-policy URL to `PRIVACY.md`. 3. App content forms: data safety (per `docs/play-data-safety.md`), FGS dataSync declaration + demo video (per `docs/play-permissions.md`), content rating, target audience 13+, ads = No, app-access test account. 4. Create the upload keystore, fill `secrets.properties`, rebuild, enroll in Play App Signing, upload to Internal testing, check App bundle explorer (16 KB verdict) + pre-launch report. ## Findings needing maintainer attention (`docs/play-compliance.md` §6) 1. **"Push mail" defaults ON** (`SettingsRepository.kt:41`) while the manifest comment/README call it opt-in — flip the default or fix the comments; the drafted FGS declaration describes actual behavior. 2. README says minSdk 33; build is 29 (#20). 3. README advertises a biometric **app lock that isn't in the code yet** — `PRIVACY.md` deliberately doesn't claim it (#20). 4. Release builds fall back to the **debug key** without `secrets.properties` — fine for CI, not for the Play upload. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
Sign in to join this conversation.