Google Play phishing policy: fixes and checks

By The Draftbit team · Updated
Sources checked

This guide is for Apps that request credentials or payment details through a claimed trusted identity.

Google treats deceptive collection of login or billing information as phishing. The rule also covers interception of credentials while they’re being transmitted.

What to check

Inspect login screens, embedded websites, OAuth redirects, overlays, and payment forms. Identify who receives each credential. Review SDKs and proxies that can observe authentication traffic.

Check whether copied branding makes your own form look like a bank, social network, or another trusted service. A familiar logo doesn’t authorize your app to collect that service’s password.

How to address the rejection

Remove impersonating forms and credential interception. Use the service’s authorized authentication flow and keep credentials within that flow. Correct misleading branding and validate redirect destinations.

Test login from a fresh install through completion, including failure and cancellation. In your response, show the authentication path and explain what your app receives. Don’t include real passwords or tokens in evidence. A privacy-policy sentence doesn’t make deceptive credential collection acceptable.

Messages this guide can help with

Phishing; Phishing policy violation; Phishing rejection; Phishing denied

Official sources

We checked these instructions against the sources below. The console layout may change, and your review decision may call for different steps.

Your next stepSubmit a Google Play release with working review access