Android app legal requirements

What Google asks for before an Android app goes live, what the law asks for on top, and which of the two rejects more submissions.

Updated · Written from the same rules terms.gg uses to generate documents

Two sets of rules, not one

An Android app answers to the privacy law of the country you operate from, and separately to Google's own rules. They overlap, but neither is a subset of the other: a policy that satisfies the law can still fail review, and a listing that passes review can still leave you exposed.

What Google checks

What the law asks for on top

Which one rejects more submissions

In practice the store does, because it checks automatically and immediately. The regulator arrives later, on a complaint, and asks harder questions. Passing review is not evidence that the policy is right.

The country you operate from decides the rest

Which law applies, which authority hears complaints, and whether a published legal notice is expected are all set by where you are established.

Keeping it true after launch

A legal page stops being true the moment the product moves past it, usually by adding a payment provider, an analytics SDK or a sign-in. No store re-checks your pages against your build, so the drift is yours to notice.

Common questions

Can I ship an Android app without a privacy policy?

No. The store asks for the URL before the listing goes live, whatever the app does.

Does the policy have to be on my own domain?

No, but it has to be permanent, public and stable. A link that 404s six months later is a listing that gets pulled.