Google Play riskware policy: fixes and checks

By The Draftbit team · Updated
Sources checked

This guide is for Apps that disguise potentially harmful functionality through evasion techniques.

Riskware uses techniques such as cloaking or dynamic loading to make potentially harmful behavior look like an ordinary app. The concern is what the concealment enables, not merely whether your build uses code obfuscation.

What to check

Inspect conditional behavior by device, region, account, time, and review environment. Trace remote modules and server flags that substantially change the app after installation.

Review third-party libraries that obscure their own behavior. Standard build minification doesn’t explain an SDK that serves a harmless screen to reviewers and harmful content to users.

How to address the rejection

Remove the harmful feature and the evasion mechanism. Make legitimate conditional functionality clear in the listing and accessible in review. Keep the submitted configuration representative of the user experience.

Test the conditions identified in the notice and provide the exact dependency or component changes. If the flag appears to involve ordinary protection of your code, explain that implementation without dismissing the reported behavior. A renamed package or newly created account doesn’t resolve the underlying finding.

Messages this guide can help with

Riskware; Riskware policy violation; Riskware rejection; Riskware denied

Official sources

We checked these instructions against the sources below. The console layout may change, and your review decision may call for different steps.

Your next stepSubmit a Google Play release with working review access