# Fieldwork checklist

## Before acquisition

- [ ] Inclusion rationale recorded
- [ ] Service owner, store publisher and apparent supplier kept separate
- [ ] Ethical and legal feasibility reviewed
- [ ] Emergency, payment or identity stopping condition defined
- [ ] Research account and synthetic tokens prepared

## Release preservation

- [ ] Package ID and version recorded
- [ ] APK acquired lawfully and SHA-256 calculated
- [ ] Store page preserved
- [ ] Data Safety / privacy label preserved
- [ ] Privacy policy preserved with redirects and hash
- [ ] In-app notices captured

## Static review

- [ ] Manifest and permissions inventory
- [ ] SDK inventory
- [ ] Network-security configuration noted
- [ ] Deep links / exported components noted only for lab safety, not exploitation
- [ ] Known first-party and supplier domains listed

## Runtime

- [ ] Stock lane clean run
- [ ] Instrumented lane clean run
- [ ] Before-choice state
- [ ] Refusal state
- [ ] Acceptance state
- [ ] Withdrawal state
- [ ] Background / relaunch where relevant
- [ ] Service outcome recorded
- [ ] Exact event markers
- [ ] Consequential events repeated

## Analysis

- [ ] App attribution established
- [ ] Destination attribution manually reviewed
- [ ] Payload claim linked to direct evidence
- [ ] Instrumentation effects considered
- [ ] Alternative explanation documented
- [ ] Maximum public wording selected
- [ ] Limitation written

## Publication

- [ ] Second technical reviewer
- [ ] Legal review where legal language appears
- [ ] Security-sensitive detail removed
- [ ] Claim-level right of reply
- [ ] Response incorporated accurately
- [ ] Machine-readable receipt validates
- [ ] Public proof bundle sanitised
- [ ] Raw retention deadline set
