Google Play spyware policy: fixes and checks

By The Draftbit team · Updated
Sources checked

This guide is for Apps or SDKs that collect or transmit data outside policy-compliant functionality.

A spyware finding can come from unexpected data collection inside an SDK. Google looks at whether collection serves allowed functionality and whether users receive adequate notice and consent.

What to check

Map audio, call recordings, device information, app data, and other sensitive information from access through transmission. Compare destinations and purposes with what users are told.

Inspect startup and background traffic. A permission granted for one feature doesn’t authorize unrelated collection for a different purpose.

How to address the rejection

Remove unauthorized collection and affected dependencies. Limit remaining access to the data your allowed feature needs, and provide the required disclosure and consent before collection.

Verify the corrected build with denied permissions and declined consent. Check that data doesn’t leave through logs, analytics, or a second SDK. Explain the original data path and the code or configuration change that closes it. Updating Data safety answers alone won’t fix spying behavior in the binary.

Messages this guide can help with

Spyware; Spyware policy violation; Spyware rejection; Spyware denied

Official sources

We checked these instructions against the sources below. The console layout may change, and your review decision may call for different steps.

Your next stepSubmit a Google Play release with working review access