Why Your Data Safety Form and Privacy Policy Must Say the Same Thing
Google's review process compares your Data Safety declarations against your linked privacy policy for consistency, and a mismatch between the two is a documented, common rejection cause. If your form says you collect location but your policy never mentions location, that gap gets flagged.
This most often happens when the privacy policy was written once early in development and never updated as SDKs were added — while the Data Safety form gets filled out closer to submission, reflecting the current build.
The fix
Fix: treat your privacy policy as a living document tied to your dependency list, not a one-time launch task.
The same check runs automatically when you upload your bundle to the AAB analyzer — permissions, SDK fingerprints, and version info in one pass, free.
Keep going
Run this check on your own AAB
Free analysis, exports when you need them.
