Google Play ransomware policy: fixes and checks
By The Draftbit team · Updated
Sources checked
This guide is for Apps that lock a device or its data and demand payment or another action to restore access.
Ransomware takes control of a device or data and makes release conditional on payment or an action. Encryption, device-admin controls, and blocked uninstall paths can all be involved.
What to check
Inspect lock screens, file encryption, payment enforcement, and device-management features. Test what happens when a subscription expires, a payment fails, or the backend is unavailable.
Distinguish restricting access to your paid service from taking control of the user’s device or existing data. A paywall shouldn’t become a device lock.
How to address the rejection
Remove coercive control and restore normal device and data access. Eliminate mechanisms that prevent removal or hold user files hostage.
The policy describes a narrow possible exclusion for qualifying subsidized-device management code distributed with the device, subject to security, disclosure, and consent requirements. Don’t assume a downloaded finance app qualifies.
Provide the exact lock and recovery behavior in your response. Test failure conditions as well as a successful payment so the reviewer can see that access no longer depends on satisfying the prohibited demand.
Official sources
We checked these instructions against the sources below. The console layout may change, and your review decision may call for different steps.
- Google Play: Ransomware Checked 22 September 2026