Google Play ransomware policy: fixes and checks

By The Draftbit team · Updated
Sources checked

This guide is for Apps that lock a device or its data and demand payment or another action to restore access.

Ransomware takes control of a device or data and makes release conditional on payment or an action. Encryption, device-admin controls, and blocked uninstall paths can all be involved.

What to check

Inspect lock screens, file encryption, payment enforcement, and device-management features. Test what happens when a subscription expires, a payment fails, or the backend is unavailable.

Distinguish restricting access to your paid service from taking control of the user’s device or existing data. A paywall shouldn’t become a device lock.

How to address the rejection

Remove coercive control and restore normal device and data access. Eliminate mechanisms that prevent removal or hold user files hostage.

The policy describes a narrow possible exclusion for qualifying subsidized-device management code distributed with the device, subject to security, disclosure, and consent requirements. Don’t assume a downloaded finance app qualifies.

Provide the exact lock and recovery behavior in your response. Test failure conditions as well as a successful payment so the reviewer can see that access no longer depends on satisfying the prohibited demand.

Messages this guide can help with

Ransomware; Ransomware policy violation; Ransomware rejection; Ransomware denied

Official sources

We checked these instructions against the sources below. The console layout may change, and your review decision may call for different steps.

Your next stepSubmit a Google Play release with working review access