What Google checks
Google Play's User Data policy expects your privacy policy to be:
- linked in the Play Console and inside the app;
- on an active, publicly accessible URL that isn't geofenced, so it opens from any country;
- a web page, not a PDF, and not editable by visitors;
- clearly labeled as a privacy policy;
- about your app and the developer or company named on your store listing; and
- complete: what personal and sensitive data the app accesses, collects, uses and shares, who it's shared with, how it's protected, and how long it's kept and how it's deleted.
Common causes and how to fix them
| Cause | Fix |
|---|---|
| The link returns an error, redirects to a home page or needs a login | Use a stable public page and test it in a private window |
| The policy is a PDF or a file download | Publish it as a web page |
| Visitors can edit the document | Use a read-only published page, not a shared editing link |
| The page is titled "Legal", "Privacy notice" or similar | Title it "Privacy Policy" |
| The developer name doesn't match the store listing | Use the same developer or company name as your Play listing |
| Sensitive permissions aren't mentioned | Describe each one the app uses, such as location, camera, contacts or microphone, and why |
| The policy and the Data safety form disagree | Update whichever is wrong so they match, including data collected by SDKs |
| The page is blocked in some regions or by bot protection | Make sure it loads from any country and for automated checks |
After you fix it
- In the Play Console, open Policy and programs > App content > Privacy policy and confirm the URL.
- If the in-app link was missing or wrong, release an update that fixes it.
- Update your Data safety answers if anything changed.
- Send the changes for review from the Publishing overview page.
If you need a reliable public URL, compare free hosting options or publish the privacy policy template on Legiflare.
Frequently asked questions
Can I use the same privacy policy for several apps?
Only if it accurately covers each app. Google expects the policy to apply to the specific app, so a separate page per app is usually clearer.
My app has no account and collects nothing. Why was it flagged?
Every app needs a valid privacy policy, and many libraries collect data you may not know about, such as advertising IDs or crash reports. See privacy policies for apps that collect no data.
Does the privacy policy need to be in every language my app supports?
It's good practice to offer it in the languages of your main audiences. You can host one page per language and link the right one from each store listing.