Google Play phishing policy: fixes and checks
By The Draftbit team · Updated
Sources checked
This guide is for Apps that request credentials or payment details through a claimed trusted identity.
Google treats deceptive collection of login or billing information as phishing. The rule also covers interception of credentials while they’re being transmitted.
What to check
Inspect login screens, embedded websites, OAuth redirects, overlays, and payment forms. Identify who receives each credential. Review SDKs and proxies that can observe authentication traffic.
Check whether copied branding makes your own form look like a bank, social network, or another trusted service. A familiar logo doesn’t authorize your app to collect that service’s password.
How to address the rejection
Remove impersonating forms and credential interception. Use the service’s authorized authentication flow and keep credentials within that flow. Correct misleading branding and validate redirect destinations.
Test login from a fresh install through completion, including failure and cancellation. In your response, show the authentication path and explain what your app receives. Don’t include real passwords or tokens in evidence. A privacy-policy sentence doesn’t make deceptive credential collection acceptable.
Official sources
We checked these instructions against the sources below. The console layout may change, and your review decision may call for different steps.
- Google Play: Phishing Checked 22 September 2026