Appearance
Keryx privacy-safe store screenshot and preview asset kit
Approved: 26 August 2026
This document is the P2-03 screenshot-kit specification for Keryx for SafeCall. It approves required device sizes, screen states, privacy-safe sample data, capture and redaction checklists, bilingual captions, and Play feature-graphic rules for Apple App Store and Google Play.
It does not claim that PNG/JPG exports exist in the repository, that Figma or Sketch sources were produced, that Czech in-app UI was captured, that the #123 reviewer environment is live, or that store consoles contain uploaded assets.
Purpose and non-goals
Purpose
- Define a repeatable, privacy-safe store screenshot kit aligned with P0–P2 identity, listing copy, safety claims, and data classification.
- Specify every required frame (Keryx app and optional SafeCall provisioning), fictional sample content, and pre-export QA so capture can proceed without client data leakage.
- Assign handoffs for live capture, Czech UI, console upload, and design sources.
Non-goals
- Committing final screenshot or feature-graphic binary exports (this close).
- Creating editable marketing design files (Figma/Sketch).
- Capturing from production SafeCall deployments or real client QR payloads.
- Building the isolated reviewer/test environment (#123).
- Pasting assets into App Store Connect or Play Console (#125).
- Localizing Keryx or SafeCall provisioning UI in source (#108).
Device and locale matrix
Re-verify pixel requirements on submission day; platform consoles change slot names occasionally.
Minimum counts
| Store | Minimum screenshots | Notes |
|---|---|---|
| Apple App Store | 3 per required device class | Up to 10 per class; use same narrative order across classes |
| Google Play | 2 phone (required) | Up to 8 phone; tablet slots optional at launch |
Required export slots
| Platform | Device class | Portrait size (px) | Launch requirement |
|---|---|---|---|
| Apple | iPhone 6.9" display (current generation) | 1320 × 2868 | Required |
| Apple | iPad Pro 13-inch (6th gen / M4 class) | 2064 × 2752 | Required (P0-04 iPad support) |
| Google Play | Phone | 9:16 portrait; short side ≥ 320, long side ≤ 3840 | Required |
| Google Play | 7-inch tablet | Same bounds as phone policy | Optional at launch — use if tablet listing enabled |
| Google Play | 10-inch tablet | Same bounds as phone policy | Optional at launch |
| Google Play | Feature graphic | 1024 × 500 (JPG or 24-bit PNG, no alpha) | Required |
Landscape orientations are supported by Keryx on iPad; launch screenshots use portrait unless a later submission adds landscape variants for all locales.
Locales
| Locale | Screenshot set | Caption language | In-app UI for capture |
|---|---|---|---|
| English (primary) | Full shot list below | English | Current English UI acceptable |
| Czech | Full shot list below | Czech | Requires #108 Czech UI before CS capture; captions approved here |
Do not ship Czech store screenshots with English-only in-app chrome unless #108 is explicitly deferred and risk accepted in the roadmap.
Required screen states
Ordered narrative for both stores. Use the same sequence across iPhone, iPad, and Android phone exports (reflow only; do not change story order).
| # | State | Surface | Must show | Must hide |
|---|---|---|---|---|
| 1 | Unconfigured onboarding | Keryx app | Empty-state title; Scan QR code primary action; help that SafeCall generates the QR | ntfy server URL, topic IDs, client server IDs, credentials |
| 2 | QR scan (optional) | Keryx app | Scanner chrome / permission prompt if needed for story | Decodable production QR; real hostnames in any overlay |
| 3 | Active tab | Keryx app | Active tab; supplemental alerts with friendly category labels; badge if used | Raw topic names (TST000-sos), MAC addresses, room/site identifiers tied to real clients |
| 4 | Archive tab | Keryx app | Archive tab; read/archived sample items | Same redactions as Active |
| 5 | Notification detail | Keryx app | Title, body, received time; archive/delete actions if visible | Raw ntfy JSON, debug panels, subscribe_auth, server URL |
| 6 | Settings / Advanced | Keryx app | Pause/resume, scan new QR, reset labels | Transport configuration, topic list, debug toggles |
| 7 | SafeCall provisioning (optional) | SafeCall admin web | Friendly alert-category selection + QR canvas (#keryx-qr-canvas) | Production server hostname in chrome, real client names, privileged credentials |
Frames 1–6 are required for launch evidence. Frame 7 is recommended when one store slot should show administrator QR provisioning; it may be a cropped SafeCall web panel, not a consumer marketing page.
Align friendly category labels with approved examples in keryx.md: panic button, low battery, sensor threshold, device not seen, installation health — using fictional device names only.
Privacy-safe sample data catalog
All capture must use isolated or fictional data. Never use production SafeCall installations, client QR codes, or live alert feeds.
Deployment fiction
| Field | Approved sample (EN) | Approved sample (CS) |
|---|---|---|
| Deployment / site label | Demo Site North | Demo lokality Sever |
| Administrator context | SafeCall administrator test device | Testovací zařízení správce SafeCall |
Friendly category labels (visible in UI)
| Internal topic pattern (hidden) | Friendly label (EN) | Friendly label (CS) |
|---|---|---|
TST000-sos | Panic button alerts | Poplachové tlačítko |
TST000-batteries | Low battery alerts | Slabá baterie |
TST000-sensors | Sensor threshold alerts | Prah senzoru |
TST000-notseen | Device not seen alerts | Zařízení neviděno |
TST000-health | Installation health alerts | Stav instalace |
Topic IDs and server URLs exist in config only — they must not appear in ordinary UI or screenshots (see keryx/test/widget_test.dart).
Sample alert messages (Active / Archive / detail)
Use operational wording without MACs, real floor plans, or credentials.
| # | Title (EN) | Body (EN) | Title (CS) | Body (CS) |
|---|---|---|---|---|
| A1 | Panic button alerts | Demo panic button pressed at Demo Site North | Poplachové tlačítko | Demo stisk na Demo lokality Sever |
| A2 | Low battery alerts | Demo sensor battery below threshold | Slabá baterie | Demo baterie senzoru pod prahem |
| A3 | Sensor threshold alerts | Demo temperature reading outside range | Prah senzoru | Demo teplota mimo rozsah |
| A4 | Device not seen alerts | Demo device has not reported recently | Zařízení neviděno | Demo zařízení dlouho nehlásilo |
| A5 | Installation health alerts | Demo notification pipeline test succeeded | Stav instalace | Demo test oznámení úspěšný |
Timestamps: use a fixed fictional time (e.g. 2026-08-26 10:15) across a set for visual consistency.
QR and transport fiction
| Field | Approved value | Rule |
|---|---|---|
| Mock server URL (config only) | https://notify.example/ | Never visible in screenshots |
| QR payload | Isolated #123 reviewer QR or non-production mock | Blur/replace if URL or token decodable |
subscribe_auth | Test-only credential in isolated env | Never visible |
Preferred capture source when available: #123 isolated HTTPS ntfy + SafeCall-style reviewer page.
Interim spec validation: local dev build with mock SharedPreferences seeding matching test patterns — not a substitute for #123 before store submission.
Redaction and pre-export QA checklist
Complete before any export leaves the capture workstation. Map to data classification and threat model.
- [ ] No real client or building names
- [ ] No MAC addresses, serial numbers, or device IDs from production
- [ ] No real room, floor, or GPS-style location strings
- [ ] No ntfy topic names or server URLs in visible UI
- [ ] No QR codes that decode to production hosts or live credentials
- [ ] No
subscribe_auth, API keys, or debug JSON on screen - [ ] No generic ntfy branding as the primary product story
- [ ] No “guaranteed”, “always on”, “never miss”, emergency dispatch, or medical iconography
- [ ] Status bar: no personal notifications, carrier name ok, consistent time
- [ ] No third-party apps or unrelated content in multitasking previews
- [ ] SafeCall web frame (if used): no logged-in admin username from production
- [ ] File names and metadata reviewed (some tools embed paths)
If any check fails, re-capture or redact; do not ship the export.
Capture procedure
Environment priority
- Preferred: #123 isolated test ntfy + durable reviewer QR page with safe sample categories and messages.
- Interim (spec / dev only): local Keryx build with seeded notification store and mock config (
notify.example, hidden topics, visible friendly labels). - Never: production SafeCall client data, production QR, or manual topic setup shown as an administrator step.
Tooling
| Platform | Tool | Device profile |
|---|---|---|
| iOS / iPadOS | Xcode Simulator or physical device on supported OS | iPhone 16 Pro Max class; iPad Pro 13-inch (M4) |
| Android | Android Emulator or physical Google Play-certified device | Phone API 31+; optional tablet API 31+ |
Example dev paths (interim only):
bash
cd keryx
flutter run
# Seed state via isolated QR scan or test harness; do not photograph production QR.Status bar and theme hygiene
- Use full battery and stable time (e.g. 09:41 iOS convention or fixed 10:15).
- Disable personal notification banners before capture.
- Launch uses the app default theme (light unless product later standardizes dark).
- Re-capture all locales if theme or major UI changes.
Export steps
- Navigate to each required state with approved sample data loaded.
- Run pre-export QA checklist.
- Export at exact pixel sizes from the device matrix (simulator screenshot or
xcrun simctl io booted screenshot/ Android Studio capture). - Name files per Export layout.
- Record commit/build ID and capture date in release evidence (#114).
Caption templates
Store consoles may not show captions on all platforms; keep captions in the content packet for design frames and internal review. Tone: supplemental SafeCall administrator companion; align with store listing copy.
English
| # | Caption |
|---|---|
| 1 | Scan a SafeCall-generated QR on your own device to connect Keryx for SafeCall. |
| 2 | Optional: grant camera access to scan your deployment QR securely. |
| 3 | View supplemental operational alerts on the Active tab. |
| 4 | Review read alerts in Archive when you are done. |
| 5 | Open alert details for title, message, and time received. |
| 6 | Pause, scan a replacement QR, or reset from Settings when needed. |
| 7 | In SafeCall, select alert categories and generate the administrator QR. |
Czech
| # | Caption |
|---|---|
| 1 | Naskenujte QR vygenerované SafeCall na vlastním zařízení pro Keryx pro SafeCall. |
| 2 | Volitelně: povolte fotoaparát pro bezpečný sken QR nasazení. |
| 3 | Doplňková provozní upozornění na záložce Aktivní. |
| 4 | Přečtená upozornění v Archivu po vyřízení. |
| 5 | Detail upozornění se jménem, textem a časem přijetí. |
| 6 | Pozastavení, nový QR nebo reset v Nastavení podle potřeby. |
| 7 | Ve SafeCall vyberte kategorie upozornění a vygenerujte QR pro správce. |
Feature graphic specification (Google Play)
Required size: 1024 × 500 px, JPG or 24-bit PNG without alpha.
| Element | Rule |
|---|---|
| Background | Solid #003087 field or clean gradient using approved palette from visual identity |
| Mark | Canonical megaphone icon from keryx/assets/icon/keryx_icon.png; no wordmark baked into icon |
| Title text | Keryx for SafeCall (EN) / Keryx pro SafeCall (CS) — text overlay, not baked into icon |
| Subordinate line | Short companion phrase, e.g. “SafeCall administrator companion” / “Doplněk pro správce SafeCall” |
| Prohibited | Emergency siren hero imagery, “100% reliable”, medical crosses, standalone consumer positioning, ntfy logo as hero |
| Safe area | Keep critical text and mark inside center 90% width; Play may crop edges on some surfaces |
Czech variant: separate feature-graphic-cs-1024x500.png when CS listing is enabled.
Optional Apple app preview video: deferred unless submission policy requires it; if added later, use the same sample data and redaction rules.
Export layout, naming, and versioning
Planned repository location (exports not committed in P2-03 Scope A):
keryx/store-assets/
screenshots/
{platform}-{locale}-{state}-{width}x{height}.png
feature-graphic/
feature-graphic-{locale}-1024x500.png
README.mdExample names:
ios-en-01-onboarding-1320x2868.pngios-cs-03-active-1320x2868.pngipad-en-03-active-2064x2752.pngandroid-en-06-settings-1080x1920.pngfeature-graphic-en-1024x500.png
| Topic | Rule |
|---|---|
| Owner / approver | Thomas Minitsios (P0-05 RACI) |
| Revision | Bump documented date + short note when shots change |
| Sources | Editable design files (if any) live outside Git or in controlled design storage — not claimed here |
| Console upload | #125 records which revision was pasted |
Accessibility and brand QA
- If marketing frames add text overlays, meet P0-04 contrast guidance (4.5:1 normal text).
- Captions must remain readable at phone thumbnail size.
- Show Keryx as a SafeCall companion, not a standalone consumer emergency app.
- Use approved names from visual identity; do not use lowercase
keryxas sole public chrome in frames. - Emoji tags (e.g. 🚨) may appear as in app; do not imply guaranteed emergency response.
Compliance cross-check (P1-10)
| Rule | Kit enforcement |
|---|---|
| Supplemental, not sole alarm channel | Captions and visible alerts use “supplemental” / “demo” framing; no sole-channel visuals |
| No guaranteed delivery | No “always on” or “never miss” overlay copy |
| No medical / emergency product | No medical iconography or dispatch imagery |
| No Critical Alerts promise | Do not show Critical Alerts UI or copy |
| SafeCall required | Onboarding + optional SafeCall frame show QR from SafeCall |
| No ntfy as administrator product | ntfy not in user-facing screenshot story |
| QR ≠ purchase | No price tags, checkout, or unlock visuals on QR frames |
Evidence handoffs
| Work | Owner |
|---|---|
| PNG/JPG export capture | Later implementation using this kit + #123 |
| Isolated reviewer QR / test ntfy | #123 |
| Czech in-app + provisioning UI | #108 |
| Public web pages (if web frame hosted) | public-web-pages.md (P2-04); HTTPS deploy |
| Store console upload | #125 |
| Release evidence archive | #114 |
| Adaptive icon QA in status bar | P2-01 megaphone adaptive kit is in source; confirm in live captures |
Explicit non-claims
Closing #106 approves this kit specification. It does not:
- claim screenshot or feature-graphic files are committed or uploaded;
- claim Figma/Sketch or other editable sources exist;
- claim Czech UI screenshots were captured;
- claim #123 reviewer environment is live;
- claim store listings display final graphics;
- claim adaptive/monochrome launcher icons pass QA in captures.
Review record
- Status: approved as the P2-03 privacy-safe store screenshot and preview asset kit specification.
- Date: 26 August 2026.
- Approver: Thomas Minitsios under the P0-05 RACI.
- Depends on: P0-02 locales, P0-04 devices, P1-05 data classification, P1-10 safety claims, P2-01 visual identity, P2-02 store listing copy, keryx-publishing.md.
- Version: 1.0 (kit date 26 August 2026).