App
Permissions to check on a Speedwin rummy app before first launch
An app that asks for permissions it does not need is a privacy problem before it is a rummy problem. Refuse what is not required. Re-check the install source after every update.

Five permission checks
How to check the install source
On a phone that lists the publisher and a verified store badge, treat the listing as the source. On a phone that does not list the publisher, treat the package as a sideload and read the APK caution page before continuing.
Where to continue
What a rummy app actually needs
A rummy app needs storage access for card avatars and screenshots. It needs network access for sign-in and table play. It needs notification access for deposit and table alerts. It does not need SMS access to read every message; an OTP app needs SMS access to read the OTP, and a rummy app does not need to read every message.
A rummy app does not need overlay access. Overlay access lets the app draw on top of other apps, which is a privacy problem before it is a rummy feature. Refuse overlay.
A rummy app does not need contacts access. Contacts access lets the app read the reader's contact list, which is a privacy problem before it is a referral feature. Refuse contacts.
After every update
An app update can re-request permissions that were refused in an earlier version. Re-check the permission list after every update, especially after a major version bump. A permission that was refused yesterday and re-requested today is the wrong permission.
An app update can also change the install source. Re-check the publisher and the store badge after every update. An update that arrives from a different source than the install is the wrong update.
What the desk will not invent
This desk does not print a Speedwin version number unless the live listing prints it. This desk does not print a store ID unless the live listing prints it. A version number or a store ID that is copied from a forum is the wrong number.
This desk does not print a checksum. A checksum is a publisher artefact, and the publisher's own site is the source for the checksum.
What a Speedwin rummy app should ask for
A rummy app should ask for storage access for card avatars and screenshots. A rummy app should ask for network access for sign-in and table play. A rummy app should ask for notification access for deposit and table alerts. A rummy app should not ask for SMS access to read every message.
An OTP app reads SMS for the OTP code. A rummy app does not need to read every message. A rummy app that reads every message is reading the reader's private messages; reading the reader's private messages is a privacy problem before it is a rummy feature.
A rummy app should not ask for overlay access. Overlay access lets the app draw on top of other apps. Drawing on top of other apps is a privacy problem before it is a rummy feature.
A rummy app should not ask for contacts access. Contacts access lets the app read the reader's contact list. Reading the reader's contact list is a privacy problem before it is a referral feature.
What to refuse and what to accept
Refuse SMS full access. Accept SMS OTP access. Refuse contacts. Accept storage. Refuse overlay. Accept notifications. Refuse camera access. Accept camera access for KYC only.
A refusal is a refusal. The desk names the difference because the difference is what separates a permission from a privacy problem.
What a Speedwin rummy app should not ask for
A rummy app should not ask for SMS full access. An OTP app reads SMS for the OTP code; a rummy app does not need to read every message. A rummy app that reads every message is reading the reader's private messages; reading private messages is a privacy problem before it is a rummy feature.
A rummy app should not ask for contacts access. Contacts access lets the app read the reader's contact list. Reading the contact list is a privacy problem before it is a referral feature. A rummy app that reads the contact list is selling a referral feature, not a rummy game.
A rummy app should not ask for overlay access. Overlay access lets the app draw on top of other apps. Drawing on top of other apps is a privacy problem before it is a rummy feature.
A rummy app should not ask for camera access for any reason other than KYC. KYC camera access is the right kind of camera access; camera access for marketing avatars is the wrong kind of camera access.
What a reader should refuse
Refuse SMS full access. Refuse contacts. Refuse overlay. Refuse camera access for any reason other than KYC. A refusal is a refusal; the desk names the difference because the difference is what separates a permission from a privacy problem.
What a reader should accept
Accept storage access for card avatars and screenshots. Accept notifications for deposit and table alerts. Accept network access for sign-in and table play. Accept camera access for KYC only.
An acceptance is an acceptance; the desk names the difference because the difference is what separates a permission from a feature.
What a Speedwin app update should not change
A Speedwin app update should not change the publisher name. An update that changes the publisher name is the wrong kind of update. The reader should re-check the publisher name after every update.
A Speedwin app update should not change the install source. An update that arrives from a different source than the install is the wrong kind of update. The reader should re-check the install source after every update.
What a Speedwin app update should change
A Speedwin app update can change the permission list. A permission that was refused yesterday and re-requested today is the wrong kind of permission. The reader should re-check the permission list after every update, especially after a major version bump.
Frequently asked about the Speedwin app
What should I refuse on first install?
SMS full access, contacts, overlay, and camera access for any reason other than KYC. A refusal is a refusal.
What should I re-check after an update?
The permission list, the publisher name, and the install source. An update can re-request permissions that were refused in an earlier version.
Where is the version number?
On the live store listing. The desk does not invent a version number.
Checklist before first launch
- 01
Confirm the publisher name
The publisher name on the listing should match the publisher name in the app's About screen.
- 02
Refuse the four permissions
SMS full access, contacts, overlay, and non-KYC camera.
- 03
Re-check after every update
An update can re-request permissions that were refused in an earlier version.
What an app permission is, in two paragraphs
An app permission is a request the app makes to the operating system. The request can be granted or refused. A grant gives the app access to the named feature; a refusal blocks the app from the named feature. The refusal is the right kind of refusal when the feature is not required for the app's core job.
A rummy app's core job is to deal cards, accept a discard, and read the declare. The core job needs storage access for card avatars and screenshots. The core job needs network access for sign-in and table play. The core job needs notification access for deposit and table alerts. The core job does not need SMS full access, contacts, overlay, or non-KYC camera access.
What a refusal looks like
A refusal appears as a system dialog on first install. The dialog asks whether to grant or refuse the permission. The reader chooses refuse. The app may re-request the permission at a later point; the reader can refuse again. The refusal is the right kind of refusal.
What an update can change
An app update can add a new permission request. A permission that was refused in an earlier version can be re-requested in the new version. The reader should re-check the permission list after every update, especially after a major version bump. A re-request is the right kind of re-check.