Make a screen list

For each screen, list visible fields, capture need, and platform control. A receipt may need sharing, while an OTP or recovery code should have no share path. Check app switcher thumbnails, screen recording, remote support, and OS screenshots. Android and iOS offer different capture controls, so verify the result on real supported devices. Where blocking is incomplete, mask the field or shorten its display time.

Test the whole capture path

Use fake recovery, account, and receipt values. For each screen, take a screenshot, start a screen recording before opening it, record while it is open, and view the app-switcher preview. Repeat on supported Android and iOS versions. A receipt can often support safe sharing after masking private fields. A recovery code needs a stricter rule. Capture controls differ by platform, so save the tested device and OS with the policy instead of claiming one setting works everywhere.

Test cases and proof

Use test accounts and test data
CaseExpected resultProof to keep
Card or recovery secret on screenHide in captures where supportedScreenshot file
App enters switcherMask sensitive previewSwitcher image
Receipt screenAllow safe sharing under policyExported image

Run a capture matrix on real devices

Use fake OTP 123456 and fake receipt R-101. On each supported Android and iOS version, open the OTP screen, start recording before and after it appears, take a screenshot, and open the app switcher. Then repeat for the receipt share view. Record which pixel data is present in each capture. Android FLAG_SECURE can block screenshots for a window; iOS can report an active capture session through scene capture state so the app can hide fields. That signal does not stop a screenshot taken before the app reacts. Save the OS build and capture files. Mask secrets before the app backgrounds and keep receipts shareable with private fields removed. (Android FLAG_SECURE; Apple scene capture state).

Record capture and preview results separately

Use a screen inventory with a row for screenshot, active recording, app-switcher image, and receipt export. For each row, save the actual pixels and OS build. A blank recording does not prove that the app-switcher image is blank. On iOS, test the capture-state signal for recording or sharing, and separately test the background transition that masks the preview. A screenshot notification received after capture cannot remove pixels already saved. Use the platform-supported behavior and record its limits. Keep private values out of notifications shown over a safe receipt screen, and test that receipt export uses the masked share view rather than a raw screen image.

Check a new window and a restored screen

On Android, open the sensitive test screen in the main activity, then open its dialog or second activity. Inspect the capture result for each window that shows private fields; the main window’s flag does not prove another window uses the same rule. Background the app while the screen is open, stop the process, and restore it from the task switcher. The preview must follow the masking policy before fresh authentication. Repeat while a recording is already active. For the receipt flow, export its approved share layout and compare the fields with the raw screen. A masked account number in the UI must not become a full account number in the exported image.

Related reading

Source