Why every game needs a privacy policy
Both the App Store and Google Play require a privacy policy link for every app, and games are no exception. Even a simple offline puzzle game usually includes an ad SDK or analytics, and those send device identifiers and usage data to third parties. Your privacy policy is where you disclose that.
What mobile games typically collect
- Device and advertising identifiers: the iOS IDFA or IDFV and the Android advertising ID, used by ad networks and analytics
- Gameplay and usage data: levels, session length, events and crash reports, often through Firebase, GameAnalytics or Unity Analytics
- Account and social data: Game Center or Google Play Games profiles, usernames, friends lists and leaderboard scores
- Player-generated content: chat messages, custom names and reports in multiplayer games
- Purchase records: in-app purchase receipts, which you receive from Apple or Google
List the SDKs you use and read their data disclosures. Most ad networks publish a page describing exactly what their SDK collects, which you can summarize in your policy.
Ads, tracking and consent
Ads are the biggest privacy topic for free games:
- iOS: if your game or its ad partners track players across other companies' apps and websites, you must ask for permission with the App Tracking Transparency prompt before any tracking happens.
- EU and UK: personalized ads generally need the player's consent first. Google requires apps that show its ads to users in the EEA and the UK to use a Google-certified consent management platform.
- California: sharing data with ad networks for cross-context behavioral advertising is "sharing" under the CCPA, which has to be disclosed and allow an opt-out if the law applies to you.
Your policy should name your ad partners or link to a list of them, explain personalized and non-personalized ads, and tell players how to change their choice.
Children and family games
If your game is directed at children, or you know that children play it, stricter rules apply. In the US, COPPA requires verifiable parental consent before collecting personal information from children under 13, and that includes persistent identifiers used for behavioral ads. Apple's Kids category and Google Play's Families policy restrict third-party analytics and advertising in apps for children, and Google Play only allows ad SDKs that are certified for families. In your policy, say who the game is for and how you handle children's data.
In-app purchases
Payments for in-app purchases are processed by Apple or Google, so you usually don't receive card details. You do receive purchase records and transaction IDs. Say that in your policy and point players to the store for refunds, since the stores handle those under their own rules.
Checklist for your game's policy
- Every ad, analytics and multiplayer SDK is covered.
- Personalized ads and tracking consent are explained.
- The target age of the game is clear, and children's data is handled accordingly.
- Chat and user-generated content, if any, are covered, including moderation and reporting.
- Players can find out how to delete their data or account.
- The same URL is in App Store Connect, the Play Console and the game's settings screen.
Frequently asked questions
Does an offline game need a privacy policy?
Yes. The app stores require one for every app, and most offline games still include ad or analytics SDKs that collect data when the device is online.
Do I have to list every ad network?
You should tell players which partners receive their data. Many developers name the main networks in the policy and link to a longer, regularly updated list of mediation partners.
My game is rated for everyone. Is it a children's game?
Not necessarily. What matters is who the game is directed at, based on things like its art style, characters and marketing. If children are part of your target audience, the children's privacy rules apply.