Meta App Review: privacy policy URL and data deletion requirements

Apps that use Facebook Login, Instagram or other Meta APIs need a privacy policy URL that Meta’s crawler can open, plus a way for people to delete their data. A broken or blocked link can hold your app back before a reviewer even looks at it. Here is what Meta checks and how to set it up.

Published by Legiflare. General information, not legal advice.

Where Meta asks for it

In the Meta App Dashboard, open your app and go to App settings > Basic. Three fields matter here:

  • Privacy Policy URL: the privacy policy that applies to your app's users.
  • Terms of Service URL: Meta requires this one to switch your app to Live mode.
  • User data deletion: a data deletion instructions URL or a data deletion callback URL.

What Meta checks

Meta's developer policies say every app must link a privacy policy that explains what data is collected and how it's used, the purposes for processing it, and how users can request deletion. The URL must be:

  • live and publicly available, with no login;
  • not geo-blocked;
  • reachable by Meta's automated crawler;
  • clearly marked as a privacy policy;
  • your organization's own policy, not another company's.

Meta treats broken privacy policy links as violations that are subject to enforcement, so a link that breaks after approval can still cause problems later.

Data deletion options

Apps that access Meta user data must give people a way to delete it. You have two options:

  • Data deletion instructions URL. A page that tells users how to request deletion, for example by emailing you or using a button in the app. It can be a section of your privacy policy, linked with an anchor such as #delete-your-data.
  • Data deletion callback URL. An endpoint on your server. When someone removes your app in their Facebook settings and asks for their data to be deleted, Meta sends a signed request to it. Your endpoint deletes the data and responds with a status URL and a confirmation code the user can check.

Instructions are simpler to set up. A callback is better when users sign in only with Facebook and have no other way to contact you.

Why the URL check fails

  1. Bot protection blocks the crawler. A firewall, captcha or challenge page answers Meta's crawler instead of the policy.
  2. The page needs a login or sits on a password-protected staging site.
  3. The link redirects to a home page or a page that isn't the policy.
  4. The page returns an error or is blocked in some countries.
  5. The policy belongs to someone else, for example a template copied with another company's name still in it.

Fix checklist

  1. Publish your privacy policy on a public HTTPS page titled "Privacy Policy" that names your app and company.
  2. Add a section on how users can delete their data, and link it as your data deletion instructions URL, or set up a callback.
  3. Paste both URLs, plus your terms of service, in App settings > Basic.
  4. Check the URL with Meta's Sharing Debugger, which shows the response code Meta's crawler gets.
  5. Open the link in a private window and from a mobile network to confirm it loads without a login or redirect.

If you also use Sign in with Google, note that Google's OAuth verification expects the privacy policy on your own domain. Meta's requirements don't ask for that.

Frequently asked questions

Can I use the same privacy policy as my App Store and Google Play listings?

Yes, if it also covers the data you get from Meta, such as profile information from Facebook Login, and explains how users can request deletion.

Does my privacy policy have to be on my own domain for Meta?

Meta's requirements don't mention the domain. They ask for a public, working URL that is clearly marked as your privacy policy. A hosted policy page meets that as long as it names your app and organization.

Can the data deletion instructions be part of my privacy policy?

Yes. Meta allows the data deletion instructions URL to point to the relevant section of your privacy policy.

Get a privacy policy URL Meta can read

Publish your policy on a public, permanent HTTPS link. Free.