Google Play personal and sensitive user data policy: fixes and checks

By The Draftbit team · Updated
Sources checked

This guide is for Google Play apps handling identity, financial, authentication, location, contacts, health, device, or similarly sensitive information.

Sensitive data includes more than a person’s name. Google also includes information such as location, authentication details, installed-app inventory, camera/microphone data, and health records.

Match access to the expected feature

Identify why each data type is needed and who receives it. We’d remove unnecessary fields before improving the disclosure. Collection and sharing must serve permitted purposes users reasonably expect; some service-provider, legal, or corporate-transfer situations have stated conditions.

Protect and disclose the flow

Use secure handling and modern encryption in transit, request available runtime permissions before access, and meet applicable disclosure and consent requirements. Selling personal and sensitive data is prohibited. A genuinely user-initiated transfer has a different treatment from selling data to a third party.

Test permission denial and inspect requests with fictional data. Check SDK recipients and the additional restrictions. Give Google the purpose, corrected access, and evidence that the app behaves as disclosed.

Messages this guide can help with

Personal and sensitive user data; Personal and sensitive user data policy violation; Personal and sensitive user data rejection; Personal and sensitive user data denied

Official sources

We checked these instructions against the sources below. The console layout may change, and your review decision may call for different steps.

Your next stepSubmit a Google Play release with working review access