Why it's still required
Apple's guideline 5.1.1(i) asks every app for a privacy policy link, and Google Play asks for one from every developer as part of the Data safety process. Neither makes an exception for apps that don't collect data. A short policy that says exactly what happens, and what doesn't, is enough to meet that requirement and tells users you thought about their privacy.
First, check what your app really collects
Many "no data" apps collect something without the developer realizing it. Look for:
- Third-party SDKs: analytics, crash reporting and ad libraries usually collect device identifiers and usage data.
- Your own server: if the app calls an API, your server logs probably record IP addresses.
- Remote content: loading images, fonts or web pages from the internet lets those servers see the device's IP address.
- Purchases: payments go through Apple or Google, but you receive transaction records.
- Push notifications: sending them requires storing a device token.
- Support: people who email you share their address and whatever they write.
If any of these apply, use the full privacy policy template instead, and describe them.
What a no-data policy should say
- who you are and how to contact you;
- that the app doesn't collect, store or share personal information;
- what the app does with data on the device, for example settings saved locally;
- which device permissions it uses, if any, and that the data stays on the device;
- how you'll handle personal information if someone emails you; and
- how you'll announce changes if that ever changes.
Sample no-data privacy policy
Adapt this to your app and remove anything that isn't true for it: