The short answer
You need a privacy policy for three separate reasons, and any one of them is enough:
- Stores and platforms won't publish you without one. Apple, Google Play, the Chrome Web Store, Microsoft Store and Meta all have a privacy policy field, and their reviewers check it.
- Privacy laws require it. Laws such as the GDPR, the CCPA and CalOPPA require you to tell people what personal data you collect and what you do with it.
- The services you build on require it. Ad networks, analytics tools and sign-in providers make a privacy policy part of their terms.
"My app doesn't collect anything" doesn't get you out of it. Apple's rule applies to all apps, and Google says even apps that collect no user data must provide a privacy policy link. If that's your situation, see what a no-data privacy policy should say.
Apple App Store warnings
Apple's App Review Guideline 5.1.1(i) is the root of most iOS privacy rejections:
"All apps must include a link to their privacy policy in the App Store Connect metadata field and within the app in an easily accessible manner."
The guideline goes on to say what the policy must cover: what data the app collects, how and why; that third parties you share data with protect it as well as you do; and how long you keep data and how people can withdraw consent or ask for deletion. The warnings you'll see are:
- "Guideline 5.1.1 - Legal - Privacy - Data Collection and Storage". The policy link is missing or broken, or the policy leaves out what Apple asks for. See how to fix a 5.1.1 rejection.
- "Guideline 5.1.2 - Legal - Privacy - Data Use and Sharing". Usually about tracking without App Tracking Transparency, or sharing data without permission. See how to fix a 5.1.2 rejection.
- "ITMS-91053: Missing API declaration" and "ITMS-91061: Missing privacy manifest". Emails sent after you upload a build when your app or an SDK lacks a privacy manifest. See how to fix the privacy manifest emails.
Google Play warnings
Google Play's User Data policy asks every app for a privacy policy link in two places: "in the designated field within Play Console, and a privacy policy link or text within the app itself." The policy must be on an active, public URL that isn't a PDF or geofenced, be labeled as a privacy policy, and name the app or the developer shown on the store listing. The warnings you'll see are:
- "Your APK or Android App Bundle is using permissions that require a privacy policy". Shown when you upload a build that requests a sensitive permission, such as the camera, and no policy is set. See how to fix the permissions warning.
- "Invalid Privacy Policy". The link is broken, points to a PDF or a home page, or the policy doesn't name your app. See how to fix an invalid privacy policy.
- "Invalid Data safety form". What your app sends off the device doesn't match what you declared. See how to fix the Data safety form.
- Prominent disclosure rejections. Your app collects data users wouldn't expect without first explaining it and asking for consent inside the app. See how to fix a prominent disclosure rejection.
Chrome Web Store, Microsoft Store and Meta
- Chrome Web Store: "Purple Lithium" and "Purple Nickel". Purple Lithium means your extension collects user data without a valid privacy policy in the right field. Purple Nickel means it collects data without prominent disclosure and consent. See what both codes mean.
- Microsoft Store: policy 10.5.1. Products that access, collect or transmit personal information need a privacy policy URL in Partner Center, and Win32 and Desktop Bridge apps always need one. See how to fix a 10.5.1 failure.
- Meta: Privacy Policy URL and data deletion. Apps that use Facebook Login or other Meta APIs need a privacy policy that Meta's crawler can open and a way for people to delete their data. See what Meta checks.
- Google sign-in: OAuth verification. If your app asks for access to Google user data, the consent screen needs a privacy policy link, and Google expects it on the same domain as your app's home page. A policy hosted on another site, including Legiflare, won't meet that rule. Host this one on your own domain.
The laws behind it
Store rules are the reason most developers act, but the obligation also comes from privacy law. Which laws apply depends on where your users are, not where you are. The most common ones:
- GDPR (EU) and UK GDPR. When you collect personal data you must tell people who you are, why you process it, the legal basis, who receives it, how long you keep it and what rights they have. A privacy policy is the usual way to do that.
- CCPA/CPRA (California). Businesses that meet its thresholds must publish a privacy policy describing what they collect, sell or share, and how consumers can exercise their rights.
- CalOPPA (California). Commercial websites and online services, including apps, that collect personally identifiable information from California residents must conspicuously post a privacy policy. It has no size threshold.
- PIPEDA (Canada). Organizations must make information about their personal information practices readily available. Quebec's Law 25 adds its own transparency rules.
- COPPA (United States). Apps and sites directed at children under 13, or that knowingly collect their data, need a privacy notice and parental consent.
- Other countries. Brazil's LGPD, Turkey's KVKK and many other laws include similar duties to inform people before you collect their data.
For US and Canadian specifics, see the US and Canadian privacy policy pages.
Services that require one
Even if no store or law applied, the tools inside your app probably would:
- Analytics. Google Analytics' terms require you to have a privacy policy and to disclose that you use Google Analytics.
- Advertising. AdMob and AdSense policies require a privacy policy that discloses how third parties use cookies or device identifiers to serve ads.
- Sign-in. Google's OAuth verification and Meta's app settings both ask for a privacy policy link, as described above.
What happens without one
- Your release is blocked. Play Console won't accept a build that uses sensitive permissions without a policy, and App Store Connect won't let you submit without a policy URL.
- Your updates are rejected. A broken link or a policy that doesn't match your Data safety form or App Privacy answers stops the next update.
- Your app can be removed. Google Play and the Chrome Web Store can take down a live item over user data violations, and Apple says apps that share data without consent may be removed from sale.
- Regulators can fine you. Under the GDPR, the most serious violations can cost up to €20 million or 4% of worldwide annual turnover, whichever is higher.
What to include
Put Apple's, Google's, Microsoft's and Meta's requirements side by side and they ask for almost the same things. A policy that covers this list will pass every store:
- Your name or company name, matching the store listing, and a contact email.
- What data you collect, including data collected by SDKs, and how you collect it.
- Why you collect it and how you use it.
- Who you share it with, such as analytics, advertising and hosting providers, and that they protect it too.
- How you keep it secure.
- How long you keep it and how it's deleted.
- How people can access their data, withdraw consent or ask for deletion.
- Whether the app is meant for children.
- How you'll tell people about changes.
Then publish it on a public page titled "Privacy Policy" that loads without a login and isn't a PDF. The free privacy policy template has a section for each item, and free hosting options compares where to publish it.
Frequently asked questions
Does my app need a privacy policy if it collects no data?
Yes. Apple requires a privacy policy link for all apps, and Google Play requires one even for apps that collect no user data. The policy can be short and simply say that the app doesn't collect personal data.
Can I use one privacy policy for my iOS app, Android app and website?
Yes, as long as it names each app, covers the data each one collects and matches what you declared in each store. Google Play also expects the policy to name your app or the developer shown on its listing.
Do I need my own website to publish a privacy policy?
Not for the app stores. Apple, Google Play, the Chrome Web Store, Microsoft Store and Meta accept any public URL that loads the policy. Google OAuth verification is the exception: it expects the policy on the same domain as your app's home page.
Is a privacy policy generator enough, or do I need a lawyer?
A template is usually enough for a small app with standard SDKs. If you handle health, financial or children's data, or operate at scale, have a lawyer review it.