Google Play prominent disclosure rejections: how to fix them

If your app collects personal or sensitive data in a way people might not expect, a privacy policy is not enough. Google Play wants an explanation inside the app and an explicit yes before collection starts. Here is what the rejection means and how to build a disclosure that passes review.

Published by Legiflare. General information, not legal advice.

The message

Prominent disclosure issues appear in the rejection email and on the Policy status page in Play Console. The wording names the data Google saw your app collect, for example a message along the lines of "Your app is uploading users' installed application information without a prominent disclosure." The issue falls under Google Play's User Data policy, in the section called Prominent Disclosure & Consent Requirement.

When a disclosure is required

Google requires a prominent disclosure when your app's access, collection, use or sharing of personal and sensitive user data may not be within what a user would reasonably expect. In practice, that usually means:

  • collecting location in the background, or when the feature in use doesn't obviously need it;
  • reading the list of installed apps;
  • uploading contacts, photos, files or call and SMS data to a server;
  • sending data to an SDK for a purpose unrelated to the feature the user is using, such as advertising.

If a photo editor uploads the photo the user just picked to apply a filter, that's expected. If it uploads the whole gallery for analysis, that isn't.

What the disclosure must do

Google's policy lists the rules. The in-app disclosure:

  • must be within the app itself, not only in the app description or on a website;
  • must be displayed in the normal usage of the app and not require the user to navigate into a menu or settings;
  • must describe the data being accessed or collected;
  • must explain how the data will be used and/or shared;
  • cannot only be placed in a privacy policy or terms of service;
  • cannot be included with other disclosures unrelated to personal and sensitive user data collection.

The disclosure has to be followed by a request for consent that:

  • presents the consent dialog clearly and unambiguously;
  • requires affirmative user action, such as tapping to accept or ticking a check box;
  • doesn't treat navigating away, including tapping outside or pressing back or home, as consent;
  • doesn't use auto-dismissing or expiring messages;
  • is granted before your app starts to collect or access the data.

Android's own permission dialog doesn't replace this. It says what the app can access, not why or what happens to the data. Show your disclosure first, then request the permission.

An example that passes

A backup app that uploads photos might show this screen the first time the user turns on backup:

Back up your photos
Photo Backup uploads the photos and videos on this device to your account so you can restore them on another phone. We store them encrypted and don't share them with anyone. You can turn backup off and delete uploaded photos at any time in Settings.
[Turn on backup] [Not now]

It names the data, says what happens to it, appears during normal use, needs a tap to agree, and runs before any upload. Your privacy policy should then describe the same thing in more detail.

Fix checklist

  1. Find the data named in the rejection, and the code or SDK that collects it.
  2. Decide whether you need it. Removing the collection, or the SDK, is often the fastest fix.
  3. If you keep it, add a disclosure screen that meets every rule above, shown before collection starts.
  4. Don't collect anything if the user declines, and let them change their mind later.
  5. Make your privacy policy describe the same data and use. See the privacy policy template.
  6. Update your Data safety form so it matches. See fixing an invalid Data safety form.
  7. If the data is background location, complete the permissions declaration in Play Console. It asks for a short video showing your disclosure and the feature that uses it.
  8. Submit the update and reply to the issue on the Policy status page.

Frequently asked questions

Is a link to my privacy policy enough as a prominent disclosure?

No. Google's policy says the disclosure cannot only be placed in a privacy policy or terms of service. It has to be shown inside the app, during normal use, before the data is collected.

Can I put the disclosure in my onboarding screens?

Yes, if it appears before collection starts, only covers the data collection, and asks for an explicit yes. Mixing it with unrelated onboarding text or terms of service breaks the rule.

Does this apply to data collected by SDKs?

Yes. Google holds you responsible for the data that third-party libraries and SDKs in your app collect, so their collection needs the same disclosure and consent.

Back your disclosure with a clear privacy policy

Describe the same data in your policy and publish it on a permanent link. Free.