What Counts as "Data Collection" Under Google Play's Data Safety Rules
Google's definition is broader than most developers expect: data safety collection includes anything your app or an SDK inside it transmits off-device — even if you never store it, even if it's anonymized, even if it only happens once at install.
The mistake we see most often: developers only declare data they can query in their own backend. But Firebase Analytics, Crashlytics, and most ad SDKs collect and transmit data before your code ever touches it. If the SDK is in your AAB and it phones home, it counts.
The fix
Fix: don't audit your database schema — audit your dex file for SDK signatures, then cross-reference each one against Google's own published list of what that SDK collects. That's the only order that catches everything.
The same check runs automatically when you upload your bundle to the AAB analyzer — permissions, SDK fingerprints, and version info in one pass, free.
Keep going
Run this check on your own AAB
Free analysis, exports when you need them.
