For developers · Checked 27 September 2026

App Store privacy labels and Google Play Data safety: what to declare

Both stores show users a summary of your app’s data practices on the listing, before they install. Apple calls it app privacy details, often called the privacy nutrition label; Google calls it the Data safety section. You write both, they cover your SDKs as well as your own code, and a label that does not match what the app does is a policy problem. This guide covers what each store asks for, quoted from Apple’s and Google’s pages as they read on 27 September 2026.

Privacy labels side by side

From Apple’s app privacy details page and App Store Connect Help, and Google’s Data safety help page.

App StoreGoogle Play
WhereApp Store Connect > App PrivacyPlay Console > App content > Data safety form
Who must complete itrequired to submit new apps and app updatesevery app on Google Play, including closed, open and production testing tracks; internal testing only is exempt
Apps that collect nothinganswer “No, we do not collect data from this app”still complete the form and link a privacy policy
Third-party codeinclude practices of third-party partners whose code you integrateinclude data handled through third-party libraries or SDKs
Changing answersupdate any time, no app update neededreviewed as part of app review; mismatches can lead to enforcement

What counts as collecting data

Apple says “collect” means transmitting data off the device in a way that lets you or your third-party partners access it for longer than needed to serve the request in real time, and that data collected only for app functionality still has to be declared, marked as used for that purpose. Google uses a similar line for ephemeral processing: data processed off the device only in memory and kept no longer than needed for the real-time request must be included in your form, but is not shown in the Data safety section if it meets that standard. Google also says you do not need to declare data from a webview where users browse the open web, only from a webview whose content your app controls.

Your SDKs are on your label

Apple requires the practices of third-party partners whose code you add, which it defines as analytics tools, advertising networks, third-party SDKs and other external vendors. Google requires data collected and handled through third-party libraries or SDKs and points to your SDK providers’ published Data safety guidance and the Google Play SDK Index. In practice, the label is only as accurate as your inventory of SDKs, so list every analytics, ads, crash reporting and login SDK before you answer.

What you may leave out

Apple makes a data type optional to disclose only when all of its criteria are met: it is not used for tracking, not used for third-party advertising, your own advertising or marketing, or other purposes, is collected only in infrequent cases outside the app’s primary functionality and optional for the user, and is provided by the user in the app’s interface with the user’s name or account shown in the submission form. Google does not count some transfers as “sharing”: transfers to a service provider processing data on your behalf and on your instructions, transfers for legal purposes, transfers based on a user-initiated action the user expects or on a prominent in-app disclosure and consent, and fully anonymized data.

Accuracy is on you

Before publishing, Apple asks you to confirm that your answers are accurate, comply with the App Review Guidelines and applicable law, and that you will update them promptly if your practices change; you can change them at any time without an app update. Google reviews the form as part of app review but says only you have the information to complete it, that you alone are responsible for complete and accurate declarations, and that when it finds a discrepancy between app behavior and your declaration it may take enforcement action. On Google Play you also state whether all collected data is encrypted in transit and whether users can request deletion, and you can optionally declare an independent security review done through a Google authorized lab.

Where Censuus fits

A clear label belongs with the rest of a clean listing; see the app launch checklist and the ASO checklist. If your app sends data to an AI provider, Apple’s separate consent rule is covered in how to market an AI app. Censuus ranks apps by the real visit traffic they draw on the web. Adding your app is free on the submit page, and sponsorship raises placement and adds a followed link to your website, see the sponsor page. We do not promise downloads or store rankings, and this guide is not legal advice.

Frequently asked questions

Do I need a Data safety form if my app collects no data?

Yes. Google says even apps that collect no user data must complete the form and provide a link to their privacy policy; the form can state that no data is collected or shared.

Do I have to declare data my analytics SDK collects?

Yes, on both stores. Apple requires the practices of third-party partners whose code you integrate, and Google requires data collected through third-party libraries or SDKs.

Do I need an app update to change my App Store privacy label?

No. Apple says you may update your answers at any time without submitting an app update.

Is sending data to my own backend provider “sharing” on Google Play?

Not when the provider is a service provider processing the data on your behalf and on your instructions; Google lists that among transfers that do not need to be disclosed as sharing.

Guides for app developers

Put your app in the ranking

Censuus ranks apps by the real visit traffic they draw, no bots. Listing is free; sponsorship raises placement.