Google Play non-Android Threat policy: fixes and checks

By The Draftbit team · Updated
Sources checked

This guide is for Apps that package or distribute components harmful to other operating systems.

Code doesn’t need to harm Android to violate this rule. Google can reject an Android app that contains a threat aimed at another platform.

What to check

Inspect bundled archives, desktop companion installers, sample files, downloaded tools, and content supplied by dependencies. A file that Android never executes may still be dangerous when copied to a computer.

Check the actual release artifact and server-hosted resources. Source-code review alone can miss files added during packaging or fetched after installation.

How to address the rejection

Remove the harmful component and replace compromised distribution sources. Verify the files you intend to ship against trusted originals and investigate the packaging step that introduced the threat.

If the flag concerns a benign research sample, explain its exact contents and intended handling in your appeal; don’t assume a research label creates an exemption. Give reviewers enough detail to assess the flagged file. Saying the app runs normally on your Android phone doesn’t address a threat aimed at a different system.

Messages this guide can help with

Non-Android Threat; Non-Android Threat policy violation; Non-Android Threat rejection; Non-Android Threat denied

Official sources

We checked these instructions against the sources below. The console layout may change, and your review decision may call for different steps.

Your next stepSubmit a Google Play release with working review access