Privacy-Period-Tracker/docs/qa/ClaudeReport.md

77 lines
3.8 KiB
Markdown

# Claude QA Report — Privacy: Period Tracker
```
Status: Current
Owner: _null
Last reviewed: 2026-08-18
Governs: the QA verdict — build SHAs, round summaries, the overall judgment
Review trigger: Any QA round run
```
> The QA verdict. Companion to [`ClaudeQACoverage.md`](ClaudeQACoverage.md)
> (what each pass reached) and [`ClaudeQAPlan.md`](ClaudeQAPlan.md) (the
> playbook).
>
> **Defects are issues, not entries here.** A defect found in a round is filed
> in the tracker with a severity label, where it can be assigned, closed by a
> commit, and counted. This file keeps the part a tracker is bad at: a judgment
> about whether the thing is fit to ship.
## Current run-state
- **Last QA round:** Round 3 — 2026-08-18, partial (A and B pass; C, D, E, F, G and H partial)
- **Last verified build SHA:** `0451fbe`
- **Last tested device / environment:** emulator `PeriodQA`, API 36, Pixel 6 profile, debug build
- **Overall status:** Five of eight batches are done and the app is a coherent
product: onboarding to a forecast, a Today screen with six honest states,
two-tap logging, a calendar readable in greyscale, insights that decline to
overstate, fertility estimates that refuse to appear when the forecast is too
vague to support them, and discreet reminders. It now wears its real brand,
supplied by the owner. Four instrumented tests assert that nothing about a
period reaches a lock screen in either private mode — but **nobody has yet
looked at an actual locked screen**, and that last mile is the single most
valuable thing left to check, because a notification read over a shoulder is
the likeliest real privacy failure in this product. The other standing gaps
are of the same kind: TalkBack has never been run, text has never been scaled,
and nothing has run at the minimum Android version this app claims to support.
## Open defects
**Do not list them here, and do not read a defect count out of this file.** The
Command Center's docs report parses this document for open `P0` / `P1` / `P2`
counts, and under this convention they are always zero — the defects are in the
tracker, which is the whole point. The zeros here mean *this file does not hold
them*, never *there are none*.
Filed as issues in this repository's tracker, labelled by what they cost:
- **P0** — ships broken, or loses data
- **P1** — materially wrong, but shippable
- **P2** — cosmetic or low impact
- **release-blocker** — a release built today would be *wrong*, not merely
incomplete
Severity is what it costs, not how annoying it is to fix. Every defect needs the
build SHA it was found at — a finding that cannot be re-tested cannot be closed
— so put it in the issue body.
## Round notes
One entry per round, the verdict only. What each pass reached, and what it could
not, lives in [`ClaudeQACoverage.md`](ClaudeQACoverage.md) and is deliberately
not repeated here.
- **Round 3 — 2026-08-18 at `0451fbe`, partial.** Fertility and reminders landed
and pass F became runnable for the first time. Verdict: fit to keep building,
not fit to ship — the privacy promise is proved against the notification
object and never against a locked screen. Two defects, both in how Android
behaves rather than in the app's logic, and both found by running on a device.
- **Round 2 — 2026-08-18 at `19edf4c`, partial.** Every screen Batch 03 built
was driven by hand. Verdict: the product became coherent, and three defects
surfaced that no unit test would have caught — one of them dark mode, broken
since Batch 01.
- **Round 1 — 2026-08-18 at `adc5075`, partial.** Two passes were all the first
build could support. Verdict: sound enough to keep going, and the first thing
tried by hand crashed the app with 70 unit tests green — which is the argument
for driving it at all.