From 64da9cb9c3a6635bf262bf416e62edc3a88365f7 Mon Sep 17 00:00:00 2001 From: Claude Date: Mon, 21 Sep 2026 22:10:09 +0000 Subject: [PATCH] fix(health): make the permission rationale argue the use case we declared Google rejected the Health Connect declaration a second time with the same code as the first: "Use of permission is not a permitted/valid use case ... or potentially engages in a prohibited use." The declaration was not what failed. The My Fitness pivot rewrote docs/health-connect-play-declaration.md and PRIVACY.md but never touched the strings behind HealthConnectRationaleScreen - the screen the declaration points the reviewer at, and the one Health Connect itself opens for ACTION_SHOW_PERMISSIONS_RATIONALE. It still carried the rejected first submission verbatim: "Amethyst reads finished workouts so it can pre-fill a workout post for you ... so the people who follow you can see what you did." That is the prohibited "publicly displaying or socially sharing sensitive data", presented in-app as the official justification for the permission. Three further contradictions on the same screen: every per-permission bullet justified the data type by what it puts in the post rather than by the statistic My Fitness renders; it claimed a 7-day window and "only while the Workouts composer is open" against the 28 days and My Fitness the declaration claims (WorkoutStats.WINDOW_DAYS = 28 drives the dashboard, LOOKBACK_DAYS = 7 only ever drove the composer); and My Fitness was not named anywhere on it. The composer's permission card had the same problem - it was titled "Share your workouts". Both surfaces now tie every permission to a statistic the dashboard shows the user, state the 4-week window and both screens that read, name My Fitness, and describe publishing only under "What Amethyst does not do" as an optional, per-item, explicitly-confirmed action. The translated copies of the 13 changed strings are deleted so every locale falls back to the corrected English until Crowdin re-translates, rather than keeping the rejected wording live in 7 languages. Also records the root cause in the declaration doc, and fixes the reviewer walkthrough to log a workout before opening the dashboard - a review device's Health Connect database is empty, and an empty dashboard demonstrates none of the statistics these permissions serve. Verified: the merged playRelease manifest declares exactly the 7 android.permission.health.* entries and no ACTIVITY_RECOGNITION or BODY_SENSORS leaked in from any dependency, so this was never a manifest/declaration mismatch. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01TPShPiTfg16yesupcLgyqf --- .../values-ar-rSA/strings.xml | 2 - .../values-bn-rBD/strings.xml | 2 - .../composeResources/values-cs/strings.xml | 13 ---- .../values-de-rDE/strings.xml | 13 ---- .../composeResources/values-de/strings.xml | 2 - .../values-el-rGR/strings.xml | 2 - .../values-eo-rUY/strings.xml | 2 - .../composeResources/values-eo/strings.xml | 2 - .../values-es-rES/strings.xml | 2 - .../values-es-rMX/strings.xml | 2 - .../values-es-rUS/strings.xml | 2 - .../composeResources/values-es/strings.xml | 2 - .../values-fa-rIR/strings.xml | 2 - .../composeResources/values-fa/strings.xml | 2 - .../values-fi-rFI/strings.xml | 2 - .../values-fr-rCA/strings.xml | 2 - .../values-fr-rFR/strings.xml | 2 - .../composeResources/values-fr/strings.xml | 2 - .../values-hi-rIN/strings.xml | 13 ---- .../values-hu-rHU/strings.xml | 13 ---- .../values-in-rID/strings.xml | 2 - .../composeResources/values-in/strings.xml | 2 - .../values-it-rIT/strings.xml | 2 - .../values-ja-rJP/strings.xml | 2 - .../composeResources/values-ja/strings.xml | 2 - .../values-ko-rKR/strings.xml | 2 - .../values-lv-rLV/strings.xml | 2 - .../values-nl-rBE/strings.xml | 2 - .../values-nl-rNL/strings.xml | 2 - .../composeResources/values-nl/strings.xml | 2 - .../values-pl-rPL/strings.xml | 13 ---- .../values-pt-rBR/strings.xml | 13 ---- .../values-pt-rPT/strings.xml | 2 - .../values-ru-rRU/strings.xml | 2 - .../values-ru-rUA/strings.xml | 2 - .../composeResources/values-ru/strings.xml | 2 - .../values-sl-rSI/strings.xml | 2 - .../values-sr-rSP/strings.xml | 2 - .../values-sv-rSE/strings.xml | 13 ---- .../composeResources/values-sw/strings.xml | 2 - .../values-ta-rIN/strings.xml | 2 - .../composeResources/values-ta/strings.xml | 2 - .../values-th-rTH/strings.xml | 2 - .../composeResources/values-th/strings.xml | 2 - .../values-tr-rTR/strings.xml | 2 - .../composeResources/values-tr/strings.xml | 2 - .../values-uk-rUA/strings.xml | 2 - .../composeResources/values-uk/strings.xml | 2 - .../values-uz-rUZ/strings.xml | 2 - .../values-vi-rVN/strings.xml | 2 - .../values-zh-rCN/strings.xml | 2 - .../values-zh-rHK/strings.xml | 2 - .../values-zh-rSG/strings.xml | 2 - .../values-zh-rTW/strings.xml | 2 - .../composeResources/values-zh/strings.xml | 2 - .../composeResources/values/strings.xml | 26 ++++---- docs/health-connect-play-declaration.md | 63 ++++++++++++++++--- 57 files changed, 69 insertions(+), 207 deletions(-) diff --git a/commonsUI/src/commonMain/composeResources/values-ar-rSA/strings.xml b/commonsUI/src/commonMain/composeResources/values-ar-rSA/strings.xml index 5a78b0c742..26a62096ee 100644 --- a/commonsUI/src/commonMain/composeResources/values-ar-rSA/strings.xml +++ b/commonsUI/src/commonMain/composeResources/values-ar-rSA/strings.xml @@ -440,8 +440,6 @@ ساعات دقائق ثوانٍ - شارك تمارينك - اسمح لـ Amethyst بقراءة التمارين المكتملة من Health Connect (Samsung Health أو Google Fit أو Fitbit أو Garmin…) واقتراح منشور. ربط %1$s كم من Health Connect diff --git a/commonsUI/src/commonMain/composeResources/values-bn-rBD/strings.xml b/commonsUI/src/commonMain/composeResources/values-bn-rBD/strings.xml index 8350369fdc..158b2047ca 100644 --- a/commonsUI/src/commonMain/composeResources/values-bn-rBD/strings.xml +++ b/commonsUI/src/commonMain/composeResources/values-bn-rBD/strings.xml @@ -429,8 +429,6 @@ ঘণ্টা মিনিট সেকেন্ড - আপনার ওয়ার্কআউট শেয়ার করুন - Amethyst-কে Health Connect (Samsung Health, Google Fit, Fitbit, Garmin…) থেকে সম্পন্ন ওয়ার্কআউট পড়তে এবং একটি পোস্ট পরামর্শ দিতে দিন। সংযোগ করুন %1$s কিমি Health Connect থেকে diff --git a/commonsUI/src/commonMain/composeResources/values-cs/strings.xml b/commonsUI/src/commonMain/composeResources/values-cs/strings.xml index 4a37728eff..d75ad3b7f3 100644 --- a/commonsUI/src/commonMain/composeResources/values-cs/strings.xml +++ b/commonsUI/src/commonMain/composeResources/values-cs/strings.xml @@ -653,27 +653,14 @@ Hodiny Minuty Sekundy - Sdílejte své tréninky - Nechte Amethyst číst dokončené tréninky z Health Connect (Samsung Health, Google Fit, Fitbit, Garmin…) a navrhnout příspěvek. Připojit %1$s km Z Health Connect Co Amethyst čte Health Connect a Amethyst - Amethyst čte dokončené tréninky, aby za vás mohl předvyplnit příspěvek o tréninku. - Amethyst je sociální klient sítě Nostr. Jeho sekce Tréninky vám umožňuje zveřejnit souhrn dokončeného tréninku na relaye Nostr, které si zvolíte, aby lidé, kteří vás sledují, viděli, co jste dělali. Místo ručního vypisování každého čísla může Amethyst načíst trénink, který vaše hodinky nebo fitness aplikace už uložily do Health Connect, a příspěvek předvyplnit. Předvyplněný příspěvek vždy uvidíte a sami rozhodnete, zda ho zveřejníte. Co Amethyst čte a proč - Cvičení · jakou aktivitu jste dělali, kdy začala a jak dlouho trvala — to je samotný trénink a zároveň název a doba trvání příspěvku. - Vzdálenost · jak daleko jste se dostali, zobrazená jako vzdálenost běhu, jízdy, chůze nebo plavání. - Aktivní a celkové kalorie · energie spálená při tréninku. Aktivní kalorie se použijí, pokud je váš zdroj zaznamenává; celkové kalorie jsou náhradou pro zdroje, které zaznamenávají pouze celkovou energii. - Tepová frekvence · průměrná a maximální tepová frekvence během tréninku, běžné měřítko náročnosti. - Kroky · počet kroků při běhu, chůzi nebo turistice. - Převýšení · kolik jste nastoupali, což odlišuje rovinatou jízdu od kopcovité. Co Amethyst nedělá - Čte pouze tréninky dokončené za posledních 7 dní, a to jen když je otevřený editor Tréninků. Na pozadí nečte nikdy. Nikdy nic nezapisuje do Health Connect a nikdy nežádá o trasu vašeho cvičení, polohu ani jiný typ zdravotních údajů. - Nic neopustí váš telefon, dokud sami neklepnete na návrh a příspěvek nezveřejníte. Amethyst nemá žádný server: příspěvek jde na relaye Nostr, které jste nastavili. - Celá funkce je volitelná. Vypnete ji v Nastavení → Nastavení editoru, nebo kdykoli odeberete oprávnění v Health Connect — zbytek Amethystu funguje dál. Přečíst si celé zásady ochrany soukromí diff --git a/commonsUI/src/commonMain/composeResources/values-de-rDE/strings.xml b/commonsUI/src/commonMain/composeResources/values-de-rDE/strings.xml index 6a9ae6c681..d699de9154 100644 --- a/commonsUI/src/commonMain/composeResources/values-de-rDE/strings.xml +++ b/commonsUI/src/commonMain/composeResources/values-de-rDE/strings.xml @@ -643,27 +643,14 @@ Stunden Minuten Sekunden - Teile deine Workouts - Lass Amethyst abgeschlossene Workouts aus Health Connect (Samsung Health, Google Fit, Fitbit, Garmin…) lesen und einen Beitrag vorschlagen. Verbinden %1$s km Aus Health Connect Was Amethyst liest Health Connect und Amethyst - Amethyst liest abgeschlossene Workouts, um einen Workout-Beitrag für dich vorauszufüllen. - Amethyst ist ein sozialer Nostr-Client. Im Bereich Workouts kannst du eine Zusammenfassung eines abgeschlossenen Workouts an die Nostr-Relays deiner Wahl veröffentlichen, damit die Leute, die dir folgen, sehen können, was du gemacht hast. Statt jede Zahl von Hand einzutippen, kann Amethyst das Workout lesen, das deine Uhr oder Fitness-App bereits in Health Connect gespeichert hat, und den Beitrag vorausfüllen. Du siehst den vorausgefüllten Beitrag immer und entscheidest, ob du ihn veröffentlichst. Was Amethyst liest und warum - Übung · welche Aktivität du gemacht hast, wann sie begann und wie lange sie dauerte — das ist das Workout selbst sowie Titel und Dauer des Beitrags. - Distanz · wie weit du gekommen bist, angezeigt als Distanz des Laufs, der Fahrt, des Spaziergangs oder des Schwimmens. - Aktive und gesamte Kalorien · die beim Workout verbrannte Energie. Aktive Kalorien werden verwendet, wenn deine Quelle sie aufzeichnet; gesamte Kalorien sind der Ersatz für Quellen, die nur die Gesamtenergie aufzeichnen. - Herzfrequenz · die durchschnittliche und maximale Herzfrequenz während des Workouts, das übliche Maß für die Anstrengung. - Schritte · die Schrittzahl eines Laufs, Spaziergangs oder einer Wanderung. - Höhenmeter · wie viel du gestiegen bist, was eine flache Fahrt von einer hügeligen unterscheidet. Was Amethyst nicht tut - Liest nur Workouts, die in den letzten 7 Tagen beendet wurden, und nur während der Workout-Editor geöffnet ist. Im Hintergrund wird nie gelesen. Schreibt nie etwas in Health Connect und fragt nie nach deiner Trainingsroute, deinem Standort oder anderen Gesundheitsdaten. - Nichts verlässt dein Telefon, bis du auf einen Vorschlag tippst und den Beitrag selbst veröffentlichst. Amethyst hat keinen Server: Der Beitrag geht an die Nostr-Relays, die du eingerichtet hast. - Die gesamte Funktion ist optional. Schalte sie unter Einstellungen → Editor-Einstellungen aus oder entziehe die Berechtigungen jederzeit in Health Connect — der Rest von Amethyst funktioniert weiter. Vollständige Datenschutzerklärung lesen diff --git a/commonsUI/src/commonMain/composeResources/values-de/strings.xml b/commonsUI/src/commonMain/composeResources/values-de/strings.xml index 12d3a459bb..e349a96d83 100644 --- a/commonsUI/src/commonMain/composeResources/values-de/strings.xml +++ b/commonsUI/src/commonMain/composeResources/values-de/strings.xml @@ -419,8 +419,6 @@ anz der Bedingungen ist erforderlich Stunden Minuten Sekunden - Teile deine Workouts - Lass Amethyst abgeschlossene Workouts aus Health Connect (Samsung Health, Google Fit, Fitbit, Garmin…) lesen und einen Beitrag vorschlagen. Verbinden %1$s km Aus Health Connect diff --git a/commonsUI/src/commonMain/composeResources/values-el-rGR/strings.xml b/commonsUI/src/commonMain/composeResources/values-el-rGR/strings.xml index 48e9fc105e..0bbd04a76a 100644 --- a/commonsUI/src/commonMain/composeResources/values-el-rGR/strings.xml +++ b/commonsUI/src/commonMain/composeResources/values-el-rGR/strings.xml @@ -428,8 +428,6 @@ Ώρες Λεπτά Δευτερόλεπτα - Μοιραστείτε τις προπονήσεις σας - Αφήστε το Amethyst να διαβάσει ολοκληρωμένες προπονήσεις από το Health Connect (Samsung Health, Google Fit, Fitbit, Garmin…) και να προτείνει μια ανάρτηση. Σύνδεση Από το Health Connect diff --git a/commonsUI/src/commonMain/composeResources/values-pt-rPT/strings.xml b/commonsUI/src/commonMain/composeResources/values-pt-rPT/strings.xml index d6c5be536e..bd744eaca9 100644 --- a/commonsUI/src/commonMain/composeResources/values-pt-rPT/strings.xml +++ b/commonsUI/src/commonMain/composeResources/values-pt-rPT/strings.xml @@ -424,8 +424,6 @@ Horas Minutos Segundos - Compartilhe seus treinos - Permita que o Amethyst leia treinos concluídos do Health Connect (Samsung Health, Google Fit, Fitbit, Garmin…) e sugira uma publicação. Conectar Do Health Connect diff --git a/commonsUI/src/commonMain/composeResources/values-sw/strings.xml b/commonsUI/src/commonMain/composeResources/values-sw/strings.xml index 037e3b8aae..9d328c4743 100644 --- a/commonsUI/src/commonMain/composeResources/values-sw/strings.xml +++ b/commonsUI/src/commonMain/composeResources/values-sw/strings.xml @@ -426,8 +426,6 @@ Masaa Dakika Sekunde - Shiriki mazoezi yako - Ruhusu Amethyst kusoma mazoezi yaliyokamilika kutoka Health Connect (Samsung Health, Google Fit, Fitbit, Garmin…) na kupendekeza chapisho. Unganisha Kutoka Health Connect