Understand Your AAB Analysis: Permissions, SDKs, Versions
Your AAB's manifest determines half your Play submission: merged permissions become Data Safety answers, SDKs become disclosures, and version codes gate every upload. Read the analysis before Play reads the binary for you.
Versions: the two numbers that gate uploads
Bump versionCode on every release upload, keep versionName human-meaningful, and verify both in analysis before generating anything — CSVs, policies, and listings are all recorded against a specific version. Run your own build through the AAB analyzer and confirm what you're about to ship.
Permissions you didn't write
Merged library manifests are the number-one source of "where did that come from" moments: POST_NOTIFICATIONS from a messaging SDK, SCHEDULE_EXACT_ALARM from a scheduler, location from an ads SDK. Each unexpected permission is a Data Safety row you now owe Play an answer for — map them with the Data Safety generator instead of discovering them in review.
SDK fingerprints are leads, not verdicts
firebase-analytics in the file list suggests app-interactions collection; it doesn't prove it. Check what you actually call, confirm against the SDK's data practices, and declare exactly that. Full mapping method lives in the Data Safety section guide.
Frequently asked questions
What is the difference between versionName and versionCode?
versionName (e.g. 2.4.1) is the human label users see; versionCode (e.g. 41) is the integer Play uses to order releases. Every upload to a track needs a higher versionCode than the last — bumping the name without the code is the classic failed-upload mistake.
Why does my app request permissions I never declared?
Library manifests merge into yours at build time. An SDK can contribute permissions — location, notifications, exact alarms — that you never wrote. The analyzer surfaces the merged list so nothing reaches review as a surprise.
What are minSdk and targetSdk, and why does Play care?
minSdk is the oldest Android version you support; targetSdk declares which API behavior you've adapted to. Play requires new apps to target a recent API level — publishing against an old targetSdk blocks submission outright.
How do I check which SDKs are inside my AAB?
Upload it to the AAB analyzer: it fingerprints known SDKs from the file list and dex references, showing the evidence for each match. Confirm each fingerprint before it becomes a Data Safety declaration.
Keep going
Read your bundle before Play does
Free analysis with evidence on every finding.
