GENERAL INFORMATION · JULY 21, 2026
Three surfaces, one product
An app can have elegant legal language and still create risk if its store disclosures describe something different. The working set is the live product, the privacy policy, and each platform disclosure. A change to an SDK, account flow, permission, or business model can affect all three.
Build one data inventory
Track each data category, collection source, purpose, recipient, retention period, user control, and linked SDK. Use that inventory to answer the platform questions and draft the policy. Separate spreadsheets assembled by different people invite drift.
Do not forget third-party code
Both platforms expect developers to account for relevant third-party partner and SDK behavior. “We do not look at it” is different from “the app does not transmit it.” Review configured SDK features, not just vendor marketing pages.
Recheck before every meaningful release
- New account or login method.
- New analytics, advertising, attribution, AI, payment, or support provider.
- New device permission or user-generated content feature.
- New audience, geography, subscription model, or deletion path.
Use the platforms’ current instructions: Apple App Privacy, Google Play Data safety, and Google Play’s privacy-policy requirements.
Have both final documents? Begin the private Focused Review →