One Question: Mystery Cards

Google Play Readiness

A launch checklist for the public website URLs needed by Google Play. This page is not a legal opinion; it tracks the website-side requirements against official Google Play policy pages.

Launch status

The content structure is prepared, but the Google Play URLs are not ready to submit until the final public domain and working contact emails are added.

Current blockers before Play Console submission:

  • Upload the site to a public HTTPS domain on Hostinger.
  • Verify https://vif-com.org is active and serving these exact pages.
  • Verify eduard@vif-com.org can receive privacy and support email.
  • Confirm the Play Console Data safety form matches the final app build and this policy.

Required Play Console URLs

Use these final public HTTPS URLs in Play Console after the site is uploaded. Local URLs such as http://127.0.0.1:8087/... cannot be used.

https://vif-com.org/legal/one-question/privacy-policy.html https://vif-com.org/legal/one-question/delete-data.html

The Terms page is useful for users, but it is not the main Google Play privacy URL and should not be used as the Privacy Policy URL.

Optional public URLs to keep available

These pages are useful for transparency and support, but they are not replacements for the required Privacy Policy and account/profile deletion URLs.

https://vif-com.org/legal/one-question/terms.html https://vif-com.org/legal/one-question/google-play-readiness.html

Website-side pages covered

Privacy policy

Clearly labeled Privacy Policy for One Question, app-labeled, HTML, public-path ready, and updated with data access, collection, sharing, retention, deletion, SDKs, camera, microphone, local media, ads, billing, analytics, crash reports, and Data Safety alignment.

Account/profile deletion

Dedicated page for deleting the One Question public Circle account/profile and associated public Circle data, with local-device deletion explained separately.

Launch inputs

The final domain and contact email are now inserted. Before Play Console submission, verify the pages load publicly over HTTPS and the contact inbox receives mail.

Deletion wording covered

The deletion page now distinguishes between account/profile deletion and local-device deletion.

  • Deleted or removal started: public Circle display name, profile identifier, invite code, invite relationships, referral connections, leaderboard profile, and public progress profile.
  • Local-device deletion: local answers, custom questions, progress, settings, consent choices, and local media metadata are removed separately inside the app through Erase all local data.
  • May remain where required: Google Play Billing records, Firebase records already processed, AdMob records, Supabase logs/backups, fraud/security/tax/legal records, and content the user already shared or exported.

Data Safety alignment for One Question

The Play Console Data safety form must match the final Android build, SDKs, app behavior, and Privacy Policy. Based on the current One Question project, the form should be checked against these categories before submission:

  • Local-only answers, custom questions, journal entries, and recorded media are processed on device unless the user shares, exports, records, or backs them up.
  • Public Circle features may transmit display name, profile identifier, invite code, invite relationships, referral connections, leaderboard profile, and progress counts to the Supabase-backed service.
  • Google Play Billing may process subscription status, purchase tokens, receipts, refund records, and billing records for Premium verification; the app should not collect payment card details.
  • Firebase Analytics and Crashlytics should remain optional and consent-based, and the Data safety form must reflect any events or diagnostics enabled in production.
  • Google AdMob / Google Mobile Ads SDK may collect ad-related data for rewarded ads, consent/privacy choices, diagnostics, and fraud prevention.
  • Camera and microphone permissions should be requested only when the user chooses to record a response, with app text explaining the purpose.
  • User-initiated sharing to social or messaging apps should be disclosed as user-controlled sharing.
  • Notifications should match the final app behavior and permission prompts.

Before release in Play Console

  • Upload the site to Hostinger and verify public HTTPS access at https://vif-com.org without sign-in, geofencing, robots blocking, or PDF/download-only pages.
  • Verify the package name and release build: com.eduard.onequestion.
  • Add the final Privacy Policy URL in Play Console and inside the app.
  • Add the final account/profile deletion URL if the public Circle profile flow qualifies as account/profile creation.
  • Verify eduard@vif-com.org receives privacy and support messages.
  • Complete the Data safety form from the final app behavior, permissions, SDKs, and service providers.
  • Complete content rating, target audience, ads declaration, app access instructions if needed, and store listing assets.
  • Use Google Play Billing for Premium digital features and avoid external payment links for those features in the Play-distributed Android app.
  • Check rewarded ad copy, consent behavior, and ad placement against the Google Play Ads policy.

Official Google Play sources