Chrome Web Store Purple Lithium and Purple Nickel: what they mean and how to fix them

Chrome Web Store rejection emails name the broken rule with a code made of a color and an element. Purple Lithium and Purple Nickel both come from the User Data policy: one is about your privacy policy, the other about asking users before you collect anything.

Published by Legiflare. General information, not legal advice.

How the codes work

When the Chrome Web Store rejects or removes an extension, the email includes a violation reference ID such as "Purple Lithium". Each ID maps to one policy, and the Chrome Web Store troubleshooting page lists them all. The purple codes cover the User Data policy, which applies to every extension that collects user data.

Purple Lithium: privacy policy and disclosure

Purple Lithium is about making sure users know what data is collected and how it's collected, used and shared. Google lists these common reasons for it:

  • the extension collects user data but has no privacy policy;
  • the privacy policy isn't in the designated field, often because it was put in the description instead;
  • the privacy policy URL doesn't work, isn't accessible, or doesn't lead to a privacy policy;
  • the policy doesn't talk about user data collection, usage, handling or sharing.

To fix it:

  1. Publish a privacy policy that covers what data your extension collects, how it uses and handles it, and who it shares it with. Include data sent to your own servers and to analytics or error-reporting services.
  2. Make sure the URL loads publicly, without a login, and goes straight to the policy rather than a home page.
  3. In the Chrome Web Store Developer Dashboard, open your item, go to the Privacy tab and paste the link in the privacy policy field.
  4. Check that your data use answers on the same tab match the policy.

Purple Nickel: prominent disclosure and consent

Purple Nickel means the extension collects data without telling users clearly and getting their consent first. Google's common reasons are that the extension isn't prominently disclosing how user data is used, and that consent isn't obtained before collection.

A privacy policy alone doesn't fix Purple Nickel. You need a disclosure inside the extension:

  1. Show a clear notice of what data you collect and how you'll handle it, for example on an onboarding page that opens after install or in the popup before the feature runs.
  2. Collect nothing until the user agrees with an explicit action, such as clicking "Allow".
  3. Give users a way to opt out later, for example in the extension's options page.
  • Purple Copper: user data isn't transmitted securely. Use HTTPS for everything.
  • Purple Magnesium: the extension collects web browsing activity it doesn't need, or publicly discloses personal information.
  • Purple Potassium: the extension requests permissions it doesn't use or need. Remove unused entries from manifest.json.

Extensions that handle user data also have to follow the Limited Use rules. See the Chrome extension privacy policy guide for details.

Resubmitting or appealing

Fix the issue, then submit a new version for review. If you've made the changes and still believe the verdict is wrong, Google suggests using the appeal button on the item's page in the dashboard to appeal or ask for clarification. Say exactly where the privacy policy link and the disclosure are.

Frequently asked questions

Can I put my privacy policy in the extension description?

No. Google lists this as a common cause of Purple Lithium. The link has to go in the privacy policy field on the Privacy tab of the Developer Dashboard.

What is the difference between Purple Lithium and Purple Nickel?

Purple Lithium is about your privacy policy: whether it exists, is in the right field, works and covers user data. Purple Nickel is about the in-extension notice and consent before data is collected.

My extension only stores settings locally. Do I need a privacy policy?

The requirement applies to extensions that collect user data. If you also use analytics, error reporting or remote sync, you collect data. Publishing a short policy that says what stays on the device avoids rejections either way.

Get a privacy policy URL for your extension

Publish a complete policy on a permanent link and paste it in the Developer Dashboard. Free.