Every app on Google Play needs a public privacy policy URL, and if your app has users in the EU, UK or California the policy must also meet GDPR, UK GDPR or CCPA basics: say what you collect, why, on what lawful basis, who you share it with, how long you keep it, and how users can access or delete it. For a small app this is a one-page document. You can write it in an hour, publish it as a page on App Builder Agent at a link under appbuilderagent.com/p/your-name/, and paste that link into the Play Console. This guide is general information, not legal advice.
A missing or vague privacy policy is the most common reason a first app is rejected from Google Play, and it is also the first thing a cautious customer looks for. The good news is that a small app does not need a twelve-page legal document. It needs an accurate, plain-language page that matches what the app actually does. Below is what Google requires, what the main privacy laws in the US, UK and EU expect, a checklist you can work through, and the quickest way to get the page online.
What Google Play requires
- A privacy policy URL on the store listing and inside the app, for every app, as of 2026. The URL must be public (no login), on an active page, and not a PDF download.
- Consistency with the Data safety form. The form declares each data type the app collects or shares; the policy must describe the same things. Reviewers compare them.
- Account deletion. Apps with sign-up must let users delete their account and data, inside the app and through a web link that you also provide in the Play Console.
- Disclosure of sensitive permissions. If the app uses location, camera, contacts, microphone or SMS, the policy must say why, and the app must show a purpose before asking.
- Children. If any part of the app is aimed at children, additional rules apply (Families policy, COPPA in the US). Do not target children unless you have read those rules.
The Google Play publishing guide walks through the console forms in order; this guide is about the page they point to.
GDPR and UK GDPR basics for a small app
The EU's GDPR applies when your app processes personal data of people in the EU (including Ireland); UK GDPR is the near-identical UK version enforced by the ICO. Both apply regardless of where you are based, if you offer the app to people there. For a small app the practical requirements come down to a short list.
- A lawful basis for each processing purpose. For most apps this is "performance of a contract" (you need an email to run an account) or "legitimate interests" (basic crash reports). Marketing emails and non-essential tracking need consent, which must be a real opt-in, not a pre-ticked box.
- A privacy notice - the policy itself - given at or before collection, in clear language, naming you as the controller with a contact address.
- Data subject rights - access, correction, deletion, portability and objection. Your notice explains how to make a request and you answer within one month.
- Data minimisation and retention - collect only what the feature needs and say how long you keep it. "Until you delete your account, then 30 days" is a perfectly good answer.
- Processors - any service that handles the data for you (a hosting provider, an email service, an analytics tool, the AI platform running your backend) is a processor, and you should have a data-processing agreement with it. Most providers publish one in their terms; list the categories of processors in your policy.
- International transfers - if data leaves the UK or EU, say so and on what safeguard (standard contractual clauses, adequacy). If your backend runs on servers in Europe or the US, say which region in general terms.
- Security - reasonable measures, such as encryption in transit and access limited to those who need it. You do not need to list technical detail.
Small businesses usually do not need to appoint a data protection officer or register with a regulator, though UK businesses processing personal data generally pay a small annual ICO fee. Check the ICO's own guidance for your case.
CCPA and CPRA basics (California, US)
The California Consumer Privacy Act, as amended by the CPRA, gives California residents the right to know what personal information a business collects, to delete it, to correct it, and to opt out of its sale or sharing for advertising. It applies to businesses above revenue or data-volume thresholds, so many small apps are technically outside it, but the safe habit is to include the rights anyway. Canada's PIPEDA and Australia's Privacy Act follow the same broad pattern: tell people what you collect, why, and how to get at it.
- Add a section titled "Your California privacy rights" listing the rights and a contact method.
- State plainly whether you sell or share personal information. For most small apps the answer is "we do not sell your personal information".
- If you use advertising SDKs, that changes the answer; say so and provide an opt-out.
Checklist: what the policy must cover
- Who you are - your name or business name, country, and an email address for privacy requests.
- What you collect - list each type: account details (email, name), content the user creates, device data, approximate location, purchase history, and anything a third-party SDK collects.
- Why - one purpose per data type, and the lawful basis for EU and UK users.
- Who sees it - categories of processors (hosting, email delivery, analytics, payment provider) and whether any third party receives data for its own use.
- How long you keep it - a retention period per data type or a rule tied to account deletion.
- User rights and how to exercise them - access, deletion, correction, opt-out; in-app Delete account button plus the email address.
- Children - state that the app is not directed at children under 13 (US) or 16 (EU default), unless it is.
- Security and transfers - a sentence each.
- Changes - how you will announce updates, with an "effective date" at the top.
- Contact - repeated at the end.
Write the policy from the Data safety form, not the other way round. Open the form, list every data type you tick, and give each one a purpose and a retention period in the policy. They will match on the first review.
Publish the policy as a page on App Builder Agent
You need a live URL, and a website project on App Builder Agent gives you one in minutes. Websites publish at a link under appbuilderagent.com/p/your-name/; custom domains are not available, but Google Play only needs a public page, and the link is stable for as long as the project exists. If you already have a website elsewhere, the same text works there too. Start a website project with the AI website builder and paste a prompt like this:
Review the generated text line by line and change anything that is not true of your app; the agent writes from your description, not from your code. Then publish, open the link on your phone to confirm it loads without login, and copy the URL.
- Add the same URL inside the app: ask the agent for a Privacy policy link on the About or Settings screen.
- Add a Delete account button in Settings if the app has accounts, and a matching "delete my account" instruction on the policy page.
- If you also want a proper site for the app, the landing page guide shows how to add the policy as a footer link on a full page.
Paste the link into Play Console and keep it accurate
- In the Play Console open your app, go to App content, choose Privacy policy, paste the URL and save.
- Fill in Data safety using the same list of data types. Mark data as deletable if the Delete account button exists.
- If the app has accounts, fill in the Account deletion section with the in-app path and the web URL (your policy page with a "delete my account" section is acceptable).
- Whenever you add a feature that collects something new (a photo upload, location, an analytics SDK), update the policy first, bump the effective date, then update Data safety with the next release.
If you are wondering what the platform itself does with your project data while you build, the data safety guide for App Builder Agent answers that separately from what your app does with your users' data. For examples of clean, minimal business sites that hold a policy page alongside the rest, look at the business and landing sites in the gallery; a short, honest policy in the footer is what customers and reviewers both want to see.
Frequently asked
Does my app need a privacy policy if it does not collect any data?
Yes. Google Play requires a privacy policy URL for every app, as of 2026, even one that stores everything on the device. The policy can simply say that no personal data is collected or sent to a server.
Where can I host my privacy policy for free?
Publish it as a one-page website on App Builder Agent; the page lives at a link under appbuilderagent.com/p/your-name/ and is a valid public URL for the Play Console. You can also put it on any website you already run.
What is the difference between GDPR and UK GDPR?
They are almost identical in substance. UK GDPR is the version retained in UK law after Brexit and is enforced by the ICO; EU GDPR applies to EU and Irish users and is enforced by each member state's authority. One well-written policy can cover both.
Does CCPA apply to my small app?
CCPA/CPRA applies to businesses over certain revenue or data thresholds, so many small apps fall outside it. Stating California residents' rights to know, delete and opt out of sale anyway costs one paragraph and avoids questions later. This is general information, not legal advice.
What must the policy say to match the Data safety form?
The same data types the form declares, the reason each is collected, whether it is shared with any third party, how long it is kept, and how a user can request deletion. If the form says you collect email addresses, the policy must say so too.
Build it now — free to start
Type the idea, sign in, and the agent builds it in your browser. Change anything by describing it.
Open the builder ›