← back to Adsense Fleet Viewer
verification/TK-11350/policy-review.md
64 lines
# TK-11350 policy/content review
Status: complete for delegated read-only sample; full rendered consent/ad journeys and Google approval remain unverified. Owner seo-analyzer / policy_content. No project edits, commits, ad clicks, external writes, or deployments. Canonical ticket log appended. Evidence fetched 2026-09-10.
## P1 — Fleet article bodies are not rendered; audit gives false depth assurance
- Local 35 monetize site configs contain **141 articles; all 141 have body and no sections**. Renderer `/Users/macstudio3/Projects/dw-domain-fleet/shared/render.js:1331` reads `a.sections`, then inserts only its generated section markup at line 1353. Example stored article body: `sites/wallpaperweekly.json:122`.
- Confirmed live HTTP 200 pages: https://wallpaperweekly.com/articles/how-to-specify-and-install-wallpaper-weekly-3 and https://fabricfridays.com/articles/how-to-specify-and-install-fabric-fridays-a-comprehensive-gu-3 contain title, deck, byline, and related links, but **no article body**. Saved raw HTML `/tmp/TK-11350-wallpaperweekly.com-article-sample.html` and `/tmp/TK-11350-fabricfridays.com-article-sample.html`; wallpaperweekly body absence visible lines 311–320.
- AdSense script present on these pages. This is direct low-value publisher-content risk; actual ad serving was not exercised. Google's policy disallows ads on screens without publisher content or with low-value content: https://support.google.com/publisherpolicies/answer/11112688?hl=en .
- Manager audit `/Users/macstudio3/.claude/skills/adsense-manager/scripts/audit.mjs:43` counts hub article links; line 51 treats >=3 as sufficient. It never fetches their content. Thus 100% readiness does not establish substantive depth or policy compliance.
- Fix renderer/schema mismatch and validate nonempty substantive main article content at every linked article URL; then perform editorial review before any publication. Count all 141 as locally affected, **only two confirmed live here**, not 141 proven live failures.
## P1 — Privacy disclosure gaps in expanded builds
- `1890swallpaper.com`, `1950swallpaper.com`, `wallpaperdictionary.com`, `wallpaperhistory.com`: homepage HTTP 200 with AdSense; no privacy link in raw HTML; both `/privacy` and `/privacy.html` HTTP 404. Local `public/index.html:4` on each loads AdSense. No privacy text/routes found in corresponding server/header files. These support a missing discoverable policy finding; dynamic external widgets were not rendered.
- `interiordesignershowroom.com/privacy` is HTTP 200, but contains only anonymous click/affiliate-cookie text and omits Google's ad-cookie and opt-out disclosures. Local `server.js:335`; AdSense inclusion `lib/render.js:266`. Directly compare required disclosure guidance https://support.google.com/adsense/answer/1348695?hl=en .
- `chargeandexplore.com/privacy.html` **exists HTTP 200** and discusses AdSense + opt-out; do not report missing policy. Homepage has no privacy anchor in raw HTML; `/privacy` 404. Recommend clear homepage link. Actual repo is `Projects/charge-and-explore`.
- `allnewsdaily.com/privacy`, fleet template privacy, and Beverly Hills Videos privacy provide explicit Google cookie/opt-out information in code/sample. No blanket fleet-wide missing-policy claim.
## P1 — Cookie acknowledgement is not demonstrated consent management
- Fleet `shared/render.js:1523–1540` calls the dismissible bar a consent notice, tells users continued usage means agreement, and stores only `<slug>_cookie_ok=1` on Got it. No reject/settings/revoke flow or TCF signalling in that function. AdSense loads independently at line 1112. Live wallpaperweekly and fabricfridays match.
- None of the ten sampled homepage source documents includes an explicit CMP/TCF marker; eight do not even include a cookie notice. This does **not** prove account-side Google Privacy & messaging is unpublished: region-sensitive/browser-loaded CMP must be inspected in account and rendered geographic tests.
- Current Google documentation says Google-certified TCF CMP is required for **personalized** ads to EEA/UK/Switzerland. It also explicitly says noncertified CMP traffic may be eligible for nonpersonalized/limited ads. Do not describe this as an unconditional prohibition on all European ad serving. Source: https://support.google.com/adsense/answer/13554116?hl=en .
- Broader Google EU consent policy requires consent for cookies/storage where legally required and personalization data; consent records and revocation information: https://www.google.com/about/company/user-consent-policy/ .
- Next verification: read Privacy & messaging console status; test accept/reject/revoke in EEA/UK/CH and inspect consent/ad requests. A Got it localStorage flag alone cannot substantiate compliance.
## P2 — Generated articles contain subject substitutions that need editorial review
- `sites/wallpaperweekly.json:120` title says how to install Wallpaper Weekly; body line 122 treats the editorial publication as a wall material. `sites/fabricfridays.json:120` says install Fabric Fridays. `sites/sheltermagazines.json:120` says install Shelter Magazines. Live article indexes expose these titles.
- Example wallpaperweekly durability body line 128 talks about cleaning and lifespan of Wallpaper Weekly. This is concrete semantic nonsense, independent of authorship technology. Fix by writing to the actual topic/user need and reviewing factual claims, not by inflating word count.
- Restoring missing bodies alone would publish this low-quality copy. Review the 141 records before restoring the whole corpus.
## P2 — All News Daily automated rewriting needs demonstrated editorial value
- `Projects/allnewsdaily/lib/aggregate.js:63–87` rewrites RSS headlines and puts results directly into WIRE. `lib/paraphrase.js:39–45` fallback changes capitalization/prefix to Report; AI prompt approximately lines 50–58 seeks one reworded sentence. No manual review gate shown in inspected route.
- Homepage is a useful linked source directory and the site has news-literacy guides, which are positive differentiation. Nevertheless, headline rewording itself is not original reporting and cannot establish substantial added value. Live source describes the page as continuously rewritten one-line topics.
- Google replicated-content examples include rewriting without added value and automated content without manual review/curation: https://support.google.com/publisherpolicies/answer/11190248?hl=en . Review whether the selection/organization and original context add meaningful value; add evidenced review, source comparison, correction handling. Do not declare Google has rejected this site or that all AI content is forbidden.
## P2 — Manager checklist overstates Google rules
`references/adsense-requirements.md:7–30` and `scripts/audit.mjs:46–59` mix house heuristics with required policy:
- No Google minimum 300 words, three articles, or 150-word guide demonstrated by cited docs. These are internal heuristics. Neither GA4 nor a particular sitemap/robots layout is shown as a universal AdSense approval requirement.
- Privacy disclosures are an explicit requirement; About/Contact aid trust/navigation, but the referenced eligibility/readiness pages do not set universal named-page mandates. Source https://support.google.com/adsense/answer/7299563?hl=en and https://support.google.com/adsense/answer/9724?hl=en .
- ads.txt is strongly recommended, explicitly not mandatory: https://support.google.com/adsense/answer/12171612?hl=en . Site ownership can be verified through code, ads.txt, or meta tag: https://support.google.com/adsense/answer/12131223?hl=en . Existing ads.txt accuracy remains operationally important.
- `Traffic must be organic` is overbroad. Policy-compliant paid promotion is allowed; artificial/incentivized traffic is the relevant concern: https://support.google.com/adsense/answer/1348722?hl=en . No paid traffic performed/recommended here.
- `SKILL.md` says 100% means nothing on our side blocks approval; demonstrably too strong given empty article pages and omitted consent check. Rename score mechanical checks passed and separate editorial, consent, account approval, serving health.
- A sell-domain banner toggle after Ready is not evidence of continued eligibility. Approval is not permission to turn substantive content into a parked/low-value page.
## Sample scope and positives
All ten homepages returned HTTPS HTTP 200: wallpaperweekly, fabricfridays, 1890swallpaper, 1950swallpaper, wallpaperdictionary, wallpaperhistory, interiordesignershowroom, beverlyhillsvideos, allnewsdaily, chargeandexplore (all .com).
Wallpaper Dictionary (~2327 raw visible words) and Wallpaper History (~1315) contain genuine substantial reference material; do not call them thin merely because primarily single-page. The two decade storefronts have JS-driven product grids, so ~180–193 raw words cannot establish thinness. Beverly Hills Videos has original videos plus editorial guide, and sampled Spago listing has contact/menu/map details; 129 raw words alone is not a policy failure. No video ownership/content verification performed.
Raw samples stored under `/tmp/TK-11350-<domain>*.html`. HTTP-only checks do not measure Core Web Vitals, rendered ad density, consent persistence, mobile usability, traffic quality, approval, or earnings. No ad clicks or account mutations. Safest next action: parent independently verify missing-body defect and incorporate findings into scoped local fixes; any deployment remains explicitly gated.
## Follow-up: complete 35-domain article sample
Evidence `/tmp/TK-11350-article-fleet.json` now samples the first configured real article on **every one of 35 monetize domains** using curl GET with concurrency six, no JavaScript/ad execution. Results: **35/35 HTTP 200; 35/35 recognized m-post article shells; 35/35 zero main-body text; zero curl errors**. Main body measured after byline and before related navigation, excluding deck/title/navigation. Renderer does not implement a `.m-post__body` wrapper; that absence is recorded separately, not confused with proof. JSON includes timestamps, URLs, per-response HTML files, HTTP status, source body sizes and inventory count. Source inventory remains 141/141 body-without-sections records across 35 configs. This establishes one live broken article per domain, not every URL live-tested.
Follow-up privacy navigation: fetched all four live `/dw-header.js` files (200). Their dynamic header reads `window.DwHeaderConfig.navLinks`; each live homepage supplies only Home, Collections, About, Care, History (1890s line1309, 1950s line1338, dictionary line925, history line707 in saved homepage HTML). No privacy link exists in these injected header lists. Local corner-nav scripts similarly use supplied/existing links and contain no privacy link. Therefore known site navigation injection does not resolve the privacy gap. External chat/ad widgets remain unexecuted and could contain their own provider policies, which would not itself establish site publisher disclosure.