The message
Play Console shows it when you upload an APK or app bundle, and names the permission that triggered it in brackets:
"Your APK or Android App Bundle is using permissions that require a privacy policy: (android.permission.CAMERA)."
Older apps may see the shorter "Your APK is using permissions that require a privacy policy". Both mean the same thing: your build asks for access to sensitive data and Google can't find a privacy policy for the app.
Why Google asks for a policy
Google Play's User Data policy says apps that access personal and sensitive user data must explain what they collect and why. Permissions such as the camera, microphone, location and contacts give your app access to exactly that kind of data, so Play Console checks for a policy as soon as it sees them in your manifest.
Today Google goes further: every app must link a privacy policy in Play Console, and even apps that collect no data must provide one with their Data safety form. The permissions warning is simply the first place many developers run into the rule.
Permissions that commonly trigger it
android.permission.CAMERAandroid.permission.RECORD_AUDIOandroid.permission.ACCESS_FINE_LOCATIONandACCESS_COARSE_LOCATIONandroid.permission.READ_CONTACTSandGET_ACCOUNTSandroid.permission.READ_PHONE_STATEandroid.permission.READ_SMSandREAD_CALL_LOG, which also fall under Google's separate SMS and Call Log policy- Storage and media permissions such as
READ_EXTERNAL_STORAGEandREAD_MEDIA_IMAGES
Permissions you didn't add yourself
It's common to see a permission in the warning that you never wrote in your manifest. Libraries and plugins bring their own manifests, and Gradle merges them into yours at build time. A QR scanner adds the camera, a voice feature adds the microphone, an old analytics SDK adds phone state.
Open AndroidManifest.xml in Android Studio and switch to the Merged Manifest tab to see every permission in the final build and which library added it. If you don't need one, remove it in your own manifest:
<manifest xmlns:android="http://schemas.android.com/apk/res/android"
xmlns:tools="http://schemas.android.com/tools">
<uses-permission android:name="android.permission.READ_PHONE_STATE"
tools:node="remove" />
</manifest>
Test the feature that relied on the library afterwards. Removing a permission a library really needs will make that feature fail.
Fix checklist
- Keep only the permissions you need. Remove the rest as shown above. Fewer permissions also means a simpler Data safety form.
- Publish a privacy policy on a public URL. It must load without a login, not be a PDF, be titled "Privacy Policy" and name your app or the developer on your Play listing. See free hosting options.
- Explain each sensitive permission in the policy. Say what the app does with the camera, location or contacts, and whether that data leaves the device.
- Add the URL in Play Console. Go to Policy and programs > App content > Privacy policy, paste the link and save.
- Link the policy inside the app, for example from Settings or the About screen. Google requires both links.
- Check your Data safety form. If the camera or location data leaves the device, it has to be declared there too. See fixing an invalid Data safety form.
- Upload the build again and roll out the release.
Frequently asked questions
Why does the warning name a permission my app doesn't use?
A library or plugin added it to the merged manifest. Check the Merged Manifest tab in Android Studio to find which one, then remove the permission with tools:node="remove" if you don't need it.
Do I need to rebuild the app after adding the privacy policy URL?
Not for the URL itself, which lives in Play Console rather than in the app. You only need a new build if you remove permissions or add the in-app link to the policy.
Can I put the privacy policy in my store listing description instead?
No. Google wants a link in the privacy policy field in Play Console and a link or the text inside the app. A description doesn't count.