Fill out Google Play's Data safety form

Check whether the form applies, gather the app and SDK data details, and answer from what your app actually does.

By The Draftbit team · Updated
Sources checked

This guide is for Public Google Play apps on closed, open, or production tracks; internal-only testing has a documented exemption.

Play Console wants Data safety answers, even though you don’t think your app collects anything. An app on a covered track still needs the form and a privacy-policy link when it collects no user data. Start with what your app actually does, so you can answer with confidence.

Include its software development kits (SDKs), the libraries added by you or your developer to provide features or connect services.

Check whether your track is covered

Apps used exclusively for internal testing are exempt. Closed testing, open testing, and production releases are covered, with exceptions for the private and system apps described in Google’s guidance.

Gather the data details before answering

List what leaves the device through your code, embedded web experiences you control, and third-party SDKs. Include why the data is used, who it’s shared with, encryption, how long it’s kept, and how it’s deleted.

Ask the developer or SDK provider about anything you can’t establish. An unused-looking library may still send data.

Complete the form in Play Console

  1. Open Data safety in the app’s App content area.
  2. Work through the data types using Google’s definitions of collection and sharing. A service provider acting on your behalf isn’t automatically treated like an independent third party.
  3. Add the privacy-policy URL. Answer security and deletion questions from behavior you’ve implemented.
  4. Compare the disclosure with all relevant distributed versions and regions.
  5. Save the answers, then send changes for review from Publishing overview when required.

Google’s guidance conflicts on ephemeral processing

Ephemeral processing means using data only in memory, for no longer than needed to answer a specific request in real time. As checked on 22 September 2026, Google’s linked page gives two different instructions for this case. Its main definition says qualifying ephemeral off-device processing must be included in the form, though it may be omitted from the public label. A later FAQ says ephemeral use need not be included in the form response.

For this specific case, check the current console wording and seek clarification from Google before answering. Data that’s retained, or used beyond ephemeral processing, still needs to be assessed.

If Google rejects the answers

Compare the rejection with your data list and the SDKs in the build. Correct the app’s behavior or the inaccurate declaration, then resubmit that change.

Use the invalid Data safety form guide for a data-flow inventory and checks before resubmission. For the external deletion link, follow the account-deletion web page guide.

The task is complete when the form is accepted and matches the released app, its integrations, and its privacy policy.

Messages this guide can help with

Data safety rejected; no data collected; ephemeral processing; privacy policy missing

Official sources

We checked these instructions against the sources below. The console layout may change, and your review decision may call for different steps.

Your next stepPrepare sign-in and account deletion for review