Does your Android app need a privacy policy?
Yes. Google Play asks every developer to provide a privacy policy, as part of the same process as the Data safety section, whether or not the app collects user data. Apps that access personal or sensitive data, such as location, contacts, the camera or account information, get extra scrutiny, and an app without a valid privacy policy can be rejected or removed.
Where to add the privacy policy link
- Play Console: open your app, go to Policy and programs > App content and enter the URL under Privacy policy.
- Inside the app: link to the same page from a settings, about or sign-up screen.
Google's policy says the privacy policy must be on an active, publicly accessible, non-geofenced URL, that it must not be a PDF, and that it must not be editable by others. A normal web page that loads without a login meets those rules. A hosted Legiflare page does, and its URL stays the same when you update the text.
What Google requires the policy to include
Google Play's User Data policy lists what the privacy policy has to cover, together with any disclosures inside the app:
- the developer's name and a privacy point of contact, or a way to submit questions;
- the types of personal and sensitive user data your app accesses, collects, uses and shares, and the types of parties you share it with;
- how you handle data securely;
- your data retention and deletion policy; and
- a clear label that it is a privacy policy, for example a title such as "Privacy Policy".
If your users are in the EU, the UK or California, the GDPR and the CCPA add requirements of their own, such as the legal basis for processing and users' rights. The privacy policy template covers these sections.
Your privacy policy and the Data safety form
The Data safety section on your Play Store listing shows users what you collect and share. It is filled in by you in the Play Console, and Google expects it to be accurate and consistent with your privacy policy. When you add or remove a feature or an SDK, update both.
A useful way to write the policy is to start from your Data safety answers: for each data type you declared, say why you collect it, whether it is shared and with whom, whether it is optional, and how users can ask for it to be deleted.
Permissions and third-party SDKs
Your policy has to cover data collected by libraries you include, not just by your own code. Typical examples in Android apps:
- Analytics and crash reporting: Firebase Analytics, Firebase Crashlytics, Sentry
- Advertising: Google AdMob and mediation partners, which use the Android advertising ID
- Sign-in: Google Sign-In, Firebase Authentication
- Payments: Google Play Billing, or providers such as Stripe for physical goods
Sensitive permissions such as precise location, contacts, SMS or the microphone need a clear reason. If you collect personal or sensitive data in a way users wouldn't reasonably expect, Google also requires a prominent disclosure and consent inside the app, not only in the policy.
Account deletion
If your app lets people create an account, Google Play requires a way to request account deletion both inside the app and through a web link that you declare in the Play Console. Describe that process in your privacy policy, including which data is deleted and what you keep for legal reasons.
Checklist before you publish
- The policy is titled "Privacy Policy" and names you as the developer.
- It lists the data your app and its SDKs collect and who it is shared with.
- It matches your Data safety answers.
- It explains security, retention and deletion, including account deletion.
- The URL is public, not a PDF, and entered in the Play Console.
- The same link is reachable from inside the app.
Frequently asked questions
My app collects no data. Do I still need a privacy policy?
Yes. Google Play asks for a privacy policy for every app. It can be short and state that the app doesn't collect personal data, but check your SDKs first, because analytics and ad libraries usually do.
Can I upload my privacy policy as a PDF?
No. Google Play's policy says the privacy policy must be on a publicly accessible web page, and PDFs are not accepted.
Can I use a Google Doc as my privacy policy?
It's risky. The page must be public and must not be editable by others, and shared documents can easily break those rules or change address. A dedicated web page is safer.
Can my iOS and Android apps share one privacy policy?
Yes, as long as the policy accurately covers both versions, including any SDKs that only one of them uses.