|
2 | 2 |
|
3 | 3 | ## Current status |
4 | 4 |
|
5 | | -- **Ready for self-testing and small student/friend testing** with clear disclaimers and privacy instructions. |
6 | | -- **Ready for counselor feedback** on wording, workflows, safe-next-step usefulness, and resource gaps. |
7 | | -- **Not ready for an education-center pilot** until Firebase/rules/security and data governance are validated. |
8 | | -- **Not ready for paid institution use** and must not be marketed as certified fraud detection. |
| 5 | +This product is ready for **self-testing**, **5–10 trusted student/friend testers**, and **counselor feedback** after the QA checklist passes. It is **not ready** for full education-center pilots, paid institution use, or production Firebase dashboards. |
9 | 6 |
|
10 | 7 | ## Who can test now |
11 | 8 |
|
12 | | -- The project owner. |
13 | | -- Trusted friends or students who understand this is an educational MVP under validation. |
14 | | -- Counselors or international-student support staff reviewing content and workflow, not relying on it for operational decisions. |
| 9 | +- The project owner/founder. |
| 10 | +- Trusted international students or recent applicants who understand this is under validation. |
| 11 | +- Parents/friends using synthetic or safely redacted messages. |
| 12 | +- Counselors/advisers reviewing language, workflows, and escalation guidance. |
15 | 13 |
|
16 | 14 | ## Who should not use it yet |
17 | 15 |
|
18 | | -- Students in urgent financial, immigration, housing, safety, or law-enforcement situations without human support. |
19 | | -- Minors unless a trusted adult/counselor is involved. |
20 | | -- Education centers or institutions needing production records, dashboards, retention, deletion, or admin access. |
21 | | -- Paid customers or anyone expecting guaranteed fraud detection. |
| 16 | +- Schools or education centers making operational decisions. |
| 17 | +- Paid institution customers. |
| 18 | +- Minors testing alone without a trusted adult/counselor. |
| 19 | +- Anyone facing immediate financial loss, threats, self-harm risk, immigration deadlines, or account compromise without human support. |
22 | 20 |
|
23 | 21 | ## What testers must be told |
24 | 22 |
|
25 | | -- The checker detects **risk indicators**, not certainty. |
26 | | -- It can miss scams and can over-score legitimate messages. |
27 | | -- It does not replace official university, embassy, bank, police, legal, immigration, or emergency channels. |
28 | | -- The checker runs locally by default, but optional reports are still best-effort redacted and should be reviewed carefully. |
29 | | -- Local reports and feedback in localStorage are browser-only and not encrypted institutional storage. |
| 23 | +- The tool detects **risk indicators**, not certainty. |
| 24 | +- It is educational and under validation. |
| 25 | +- It does not provide legal, immigration, financial, emergency, or law-enforcement advice. |
| 26 | +- Checker analysis runs locally by default. |
| 27 | +- Redacted reporting is best effort and requires preview review. |
| 28 | +- localStorage reports are browser-only, not encrypted, and not institutional records. |
| 29 | +- Firebase dashboard mode is not connected unless a secure Firebase implementation and governance review are completed. |
30 | 30 |
|
31 | | -## What testers must not paste |
| 31 | +## What data testers must not paste |
32 | 32 |
|
33 | | -Tell testers not to paste: |
| 33 | +Do not paste: |
34 | 34 |
|
35 | | -- passport scans or full passport numbers, |
36 | | -- student IDs, |
37 | | -- card or bank-account numbers, |
38 | | -- passwords, OTPs, PINs, recovery codes, or login links, |
39 | | -- exact home addresses, |
40 | | -- private documents or screenshots with personal data, |
41 | | -- names/contact details of real people unless removed first. |
| 35 | +- Passport scans or passport numbers. |
| 36 | +- Student IDs, national IDs, visa numbers, SEVIS/CAS/I-20 identifiers. |
| 37 | +- Card numbers, bank details, CVV, PINs, passwords, OTPs, recovery codes. |
| 38 | +- Exact addresses, phone numbers, personal email addresses, names of minors. |
| 39 | +- Private documents, screenshots with personal data, or legal/immigration files. |
42 | 40 |
|
43 | | -## How to collect feedback safely |
| 41 | +## Safe testing with synthetic messages |
44 | 42 |
|
45 | | -- Prefer structured observations: “Which warning was confusing?” “Did the script help?” “Was the risk level too high/too low?” |
46 | | -- Do not ask testers to send raw suspicious messages in chat, email, forms, or screenshots. |
47 | | -- If examples are needed, ask testers to paraphrase and remove identifiers. |
48 | | -- Summarize trends by category, channel, country/destination context, and risk indicator—not by raw message text. |
| 43 | +- Start with built-in demo messages. |
| 44 | +- Create synthetic examples by scenario: scholarship fee, visa threat, fake housing deposit, bank/card phishing, testing score upgrade. |
| 45 | +- Do not use real names, exact institutions, or real account numbers. |
| 46 | +- Record only category, risk level, whether the explanation made sense, and next-step clarity. |
49 | 47 |
|
50 | | -## How to handle suspicious real messages |
| 48 | +## Safe testing with real messages after redaction |
51 | 49 |
|
52 | | -1. Ask the tester to stop before paying, clicking, replying, or sending documents. |
53 | | -2. Have them verify through a published official channel typed manually or a saved official app/bookmark. |
54 | | -3. If money, credentials, card data, documents, or OTPs were already shared, direct them to the relevant bank/payment provider, real institution, counselor, and appropriate local reporting channel. |
55 | | -4. If the situation involves immediate danger, coercion, or a minor, stop product testing and involve a trusted adult, counselor, emergency service, or local authority as appropriate. |
| 50 | +- Remove names, IDs, exact URLs, account numbers, addresses, phone numbers, and institution-specific identifiers before testing. |
| 51 | +- Prefer summarizing the scenario instead of pasting full text. |
| 52 | +- Use the report page only after reviewing the redacted preview. |
| 53 | +- If redaction misses something, stop and clear the form/local data. |
56 | 54 |
|
57 | | -## When to stop testing |
| 55 | +## How to collect feedback without raw messages |
| 56 | + |
| 57 | +- Use the anonymous feedback controls in the result card. |
| 58 | +- Use `docs/FEEDBACK_ANALYSIS_TEMPLATE.md` for sessions. |
| 59 | +- Store categories and structured observations only. |
| 60 | +- Never paste raw messages into docs, issues, pull requests, emails, spreadsheets, or chat. |
58 | 61 |
|
59 | | -Stop the beta session if: |
| 62 | +## When to stop testing |
60 | 63 |
|
61 | | -- a tester is distressed, pressured, or in immediate danger, |
62 | | -- a tester starts sharing private documents or secrets, |
63 | | -- the app gives confusing guidance for a high-stakes issue, |
64 | | -- Firebase/dashboard behavior appears connected when it is not, |
65 | | -- localStorage contains raw message text unexpectedly, |
66 | | -- a counselor identifies unsafe or misleading wording. |
| 64 | +Stop immediately if: |
67 | 65 |
|
68 | | -## When counselor review is needed |
| 66 | +- A tester pastes highly sensitive data. |
| 67 | +- A tester is scared, pressured, or confused about a real deadline. |
| 68 | +- A result appears to encourage unsafe action. |
| 69 | +- A legitimate message scores high/critical and the user may ignore an important official deadline. |
| 70 | +- A high-risk message scores low and the tester might proceed unsafely. |
| 71 | +- localStorage or Firebase behavior is unclear. |
69 | 72 |
|
70 | | -Counselor/international-office review is needed before using examples or guidance for: |
| 73 | +## When to involve a counselor/adult |
71 | 74 |
|
72 | | -- visa or immigration deadlines, |
73 | | -- tuition/payment diversion, |
74 | | -- housing deposits, |
75 | | -- scholarship/admission claims, |
76 | | -- minors or vulnerable students, |
77 | | -- country-specific official resources, |
78 | | -- escalation paths after money or documents are shared. |
| 75 | +Involve a counselor, trusted adult, bank, official school office, or relevant authority when: |
79 | 76 |
|
80 | | -## How to summarize results without raw messages |
| 77 | +- Money, deposits, tuition, refunds, cards, bank accounts, passwords, OTPs, or identity documents are involved. |
| 78 | +- A student is a minor. |
| 79 | +- The message threatens visa cancellation, deportation, admission loss, account closure, or housing loss. |
| 80 | +- The student already clicked, paid, or shared data. |
| 81 | +- The student feels afraid or pressured. |
81 | 82 |
|
82 | | -Use aggregate, non-identifying notes such as: |
| 83 | +## How to summarize feedback safely |
83 | 84 |
|
84 | | -- “3 testers found the verification script useful.” |
85 | | -- “2 testers were confused by local vs Firebase dashboard mode.” |
86 | | -- “Scholarship-fee examples were understood; housing-deposit examples need clearer next steps.” |
87 | | -- “One custom message triggered high risk due to urgency + payment + sensitive-data requests.” |
| 85 | +Use broad categories: |
88 | 86 |
|
89 | | -Do not include raw messages, names, exact phone numbers, email addresses, URLs, passport/student IDs, card/bank details, or screenshots in beta summaries. |
| 87 | +- Scenario category, not message text. |
| 88 | +- Expected/actual risk level. |
| 89 | +- Whether next steps were understood. |
| 90 | +- Whether wording felt too scary, too certain, or unclear. |
| 91 | +- False-positive/missed-risk notes without identifiers. |
| 92 | +- Privacy concerns and feature requests. |
0 commit comments