Play Hero logoPlay Hero

Google Play Privacy Policy Requirements: URL, Contents, Consistency

Play requires a live, public privacy policy URL in store settings and Data Safety, covering what you collect, why, who you share with, and how to contact you. The policy and your Data Safety answers must describe the same app — contradictions are a top rejection trigger.

Where the URL goes (both places)

Set the URL under Store presence → Store settings and again inside the Data Safety section. Test it in an incognito window before submitting: if it doesn't load for alogged-out reviewer, it doesn't count. Skip the drafting work with our privacy policy generator, which publishes a hosted URL from your AAB analysis.

What reviewers actually check

Contact identity (a real email, not a no-reply black hole), data types tied to purposes, named third parties — Firebase, AdMob, payment processors — retention and deletion wording, and children's provisions if your audience includes them. Compare this against the Data Safety section guide line by line; the two documents are reviewed together.

Keep it current or it rots

Added an analytics SDK two versions ago and never updated the policy? That's a rejection waiting for a review cycle to find it. Regenerate from each new AAB and republish to the same URL — no re-linking in Play Console needed.

Frequently asked questions

Does every app need a privacy policy on Google Play?

Effectively yes: any app that collects, transmits, or shares personal data needs one, and the Data Safety section requires a policy URL. Even minimal apps should publish one — review flags a missing policy faster than anything else.

Where do I put the privacy policy URL?

In two places: Store presence → Store settings → Privacy policy URL, and in the Data Safety section. Both must point to a live, publicly accessible page — no login walls, no PDFs behind forms.

What must the policy contain?

Who you are and how to contact you, what data you collect and why, who you share it with (including SDK providers), retention, deletion options, and children's provisions where applicable. It must agree with your Data Safety answers.

Why was my policy rejected if I have one?

The top causes: a dead or login-walled link, a policy that contradicts the Data Safety form (mentions analytics while the form says no collection), and boilerplate that doesn't describe the actual app.

Keep going

Generate a policy that matches

Drafted from your data profile, hosted URL included.