Google Play permissions and sensitive APIs policy: fixes and checks

By The Draftbit team · Updated
Sources checked

This guide is for Google Play apps requesting access to sensitive user or device information.

A permission needs a current reason users can understand. Google limits sensitive permissions and APIs to implemented, permitted features promoted in the listing. Requesting access for a possible future feature doesn’t meet that test.

Compare the final bundle with the feature list

Inspect the merged manifest, which includes permissions contributed by libraries. For each permission, identify the user-facing task and why a narrower approach won’t work. We’d test the compiled app rather than assume its configuration file is the final result.

Request access in context

Ask when the feature needs it, explain the purpose, and use the data only for the permitted, consented use. A new purpose needs the required new affirmative agreement. Personal or sensitive data obtained this way can’t be sold or shared to enable its sale.

Use the specific permission pages below for additional restrictions. Test refusal and alternative flows, then give Google the corrected permission set, feature, and declaration evidence.

Messages this guide can help with

Permissions and sensitive APIs; Permissions and sensitive APIs policy violation; Permissions and sensitive APIs rejection; Permissions and sensitive APIs denied

Official sources

We checked these instructions against the sources below. The console layout may change, and your review decision may call for different steps.

Your next stepSubmit a Google Play release with working review access