play/DECLARATIONS.md (6416 bytes)
1 # App content declarations 2 3 Answers for Play Console > Policy and programs > App content. Each is true of 4 the build tagged `v0.0.4-alpha`; re-check them if the app changes. 5 6 ## Privacy policy 7 8 Required, because the app uses the accessibility API. Host 9 [PRIVACY.md](PRIVACY.md) at a public URL and paste that URL. 10 11 ## Ads 12 13 **No**, the app does not contain ads. 14 15 ## App access 16 17 **All functionality is available without special access.** No login. 18 19 ## Content rating 20 21 Category: **Utility, Productivity, Communication, or other**. Answer **No** to 22 every question about violence, sexuality, language, controlled substances, 23 gambling, user interaction and sharing location. Expected result: Everyone / 24 PEGI 3. 25 26 ## Target audience 27 28 **18 and over.** The app is not designed for children. Choosing adult ages only 29 keeps it out of the Families policy, which it has no reason to be under. 30 31 ## News app / Health / Financial features / Government 32 33 **No** to all. (The "wallet" channel makes AssistKey selectable as the wallet 34 app so that a button press reaches it. It holds no cards and moves no money, 35 so it is not a financial feature.) 36 37 ## Data safety 38 39 | Question | Answer | 40 |---|---| 41 | Does your app collect or share any of the required user data types? | **No** | 42 | Is all of the user data collected by your app encrypted in transit? | Not applicable - nothing is collected | 43 | Do you provide a way for users to request that their data is deleted? | Not applicable | 44 45 Why "No" is accurate: the app holds no `INTERNET` permission 46 (`aapt2 dump badging` on the release shows `WRITE_SECURE_SETTINGS`, 47 `RECORD_AUDIO`, `QUICK_ACCESS_WALLET` and 48 `com.android.vending.BILLING`, none of which is network access). These answers 49 are for the `play` build, which is the only one uploaded. The device report is 50 composed on the device and leaves it only if the user sends it, through their 51 own email or share target. Data that never 52 leaves the device is not "collected" in Play's sense. Purchase handling by 53 Google Play's own billing system does not have to be declared by the app. 54 55 ## Accessibility API declaration 56 57 Play asks this of any app whose manifest declares an accessibility service. 58 59 **Is your app an accessibility tool (built to support people with 60 disabilities)?** No. The manifest does not set `isAccessibilityTool`. 61 62 **What core functionality uses the AccessibilityService API?** 63 64 ``` 65 AssistKey is a hardware key remapper for the Viwoods AiPaper Reader, an e-ink reading device. Remapping hardware keys is the app's only function, and the AccessibilityService API is the only public Android API that can do it. 66 67 The service is used for six things: 68 69 1. Key event filtering (flagRequestFilterKeyEvents / onKeyEvent). The service receives presses of the device's AI key and volume keys, recognises the gesture the user configured - single or multiple taps, press-and-hold, or a combination of keys - and consumes the press so that the user's chosen action runs instead of the default one. 70 71 2. Performing the action the user bound to that gesture: performGlobalAction (Back, Home, Recents, notifications, quick settings, lock screen, screenshot), dispatchGesture (a swipe, used to turn pages in reading apps that accept only touch input), and ACTION_SCROLL_FORWARD / ACTION_SCROLL_BACKWARD on the scrollable node of the active window. 72 73 3. Voice typing, if the user binds that action: the service finds the text field that has input focus and inserts the recognised words at the cursor (ACTION_SET_TEXT, or ACTION_PASTE as the fallback). It never writes into password fields. 74 75 4. Going back to the app that was in use, on Viwoods readers: the service reads the package name of the window in front from window-state events, keeps the latest one in memory only, and uses it to return from the maker's AI screen when the user presses the AI key there. 76 77 5. An on-screen button, if the user binds one: the service draws a small round button in an accessibility overlay window (TYPE_ACCESSIBILITY_OVERLAY). A tap on it runs the action the user chose. The button exists only while it has an action, and it reads nothing from the screen. 78 79 6. Ink Recents in place of the recent apps of the system, if the user has installed Ink Recents and left the switch on: from the same window-state events, the service recognises the recent-apps screen of the system by its package and class name, sends Back, and starts Ink Recents. It reads nothing from that screen. 80 81 Window content is retrieved only in cases 2 and 3: to locate a scrollable node at the moment the user presses a key bound to the Scroll action, and to read the one focused text field at the moment recognised words are inserted into it. No window content, text, or key event is stored, logged or transmitted. The app does not request the INTERNET permission and cannot transmit anything. 82 83 Before the user is sent to the accessibility settings, the app shows a prominent in-app disclosure describing exactly this use, and proceeds only if the user taps Agree. 84 ``` 85 86 **Disclosure evidence.** If the form asks for a video: on the main screen tick 87 *Accessibility key filter*. The disclosure dialog appears before anything else, 88 and only *Agree* continues to Android's settings. Record that on any phone 89 pointed at the reader - the reader cannot capture its own screen. 90 91 ## Permissions a reviewer may ask about 92 93 | Permission | Why | 94 |---|---| 95 | `BIND_ACCESSIBILITY_SERVICE` | Above. | 96 | `WRITE_SECURE_SETTINGS` | Cannot be granted to a Play install; it does nothing unless the owner grants it over adb. It then lets the app switch the firmware's power-button behaviour (short press, hold duration). Declared so that the grant is possible at all. | 97 | `RECORD_AUDIO` | Voice typing only. Requested at run time from the Voice typing screen. The speech recognition app the user chose records the audio; Android requires the calling app to hold the permission too. AssistKey receives text only, and stores and sends nothing. | 98 | `QUICK_ACCESS_WALLET` | Required of any app offered as the wallet app. AssistKey serves an empty card list; it exists so a press of the wallet shortcut reaches the user's chosen action. | 99 | `com.android.vending.BILLING` | Play Billing. | 100 101 The assistant, camera and wallet entry points are disabled in the manifest and 102 are enabled one by one only when the user ticks the matching channel, so an 103 untouched install never appears as a candidate for any of those roles.