Privacy Policy URL — Google Play and App Store Link Requirements and How to Create One

Author: IT Sectr Published: 2026-06-07 Reading time: 8 min

Privacy Policy URL is a link to the privacy policy document that every app must provide when publishing on Google Play and App Store. Without a working link, app publication is impossible. According to Apple Developer, 2026, more than 15% of app rejections in the App Store are related to the absence or incorrect privacy policy.

Key Takeaways

  • Privacy Policy is a legal document that describes what data the app collects, how it processes, stores, and shares it with third parties.
  • Google Play requires a privacy policy link for all apps that collect users' personal data.
  • App Store requires a privacy policy for all apps without exception, even if the app does not collect any data.
  • The link to the privacy policy must be active, accessible via HTTPS, and lead to a page with the full text of the document.
  • Updating the policy is required when the types of collected data change, new analytics tools are added, or new regulatory requirements come into effect.

What Is a Privacy Policy URL

Privacy Policy URL is a web address where the app's privacy policy document is hosted. Users must be able to read this document before installing the app — the link is displayed on the store page.

The privacy policy is a legally significant document that regulates the relationship between the developer (data operator) and the user (data subject). In most countries, having such a document is mandatory by law, not just per store requirements.

According to GDPR (General Data Protection Regulation), 2018, fines for the absence of a privacy policy in the EU can reach 20 million euros or 4% of the company's annual global turnover. In the US, similar requirements are regulated by state laws, including CCPA in California.

Google Play Requirements for Privacy Policy

Google Play requires a privacy policy link for all apps that request access to users' personal data. This includes apps working with contacts, geolocation, camera, microphone, photos, and media files.

The link is added in the Store Presence section → Store Listing → Privacy Policy. Google Play does not automatically check the document's content but may request compliance verification with actual data collection during review.

If the app collects sensitive data (medical, biometric, financial), Google Play may require confirmation that the policy complies with the Google Play Developer Program Policies. In this case, the link must lead to a page containing the data operator's contact information.

For apps developed under the Google Play for Education program, additional policy specification is required in a format compliant with FERPA (Family Educational Rights and Privacy Act).

App Store Requirements for Privacy Policy

App Store requires a privacy policy for all apps without exception — even if the app does not collect any user data. This is one of Apple's strictest requirements, and violating it leads to build rejection.

The policy link is added in App Store Connect in the App Privacy section. In addition to the link, Apple requires filling out the Privacy Details form — a questionnaire about the types of data collected, their usage, and user linking. This information is displayed on the app page before installation.

Apple verifies compliance between the privacy policy and the app's actual behavior. If a reviewer finds that the app collects data not mentioned in the policy, the build will be rejected with a misrepresentation ruling.

For apps working with children (Kids category), Apple requires an additional section in the policy describing compliance with COPPA (Children's Online Privacy Protection Act) and parental consent procedures.

What to Include in the Privacy Policy

The privacy policy must be complete, accurate, and reflect actual data processing practices. The minimum set of sections is defined by international GDPR standards and app store recommendations.

  1. Types of Collected Data — list all categories: name, email, geolocation, device identifiers, purchase history, usage data. Specify whether data is collected automatically (analytics, logs) or provided by the user.
  2. Processing Purposes — what the collected data is used for: functionality, analytics, advertising, personalization. Each purpose must be explicitly stated.
  3. Third-Party Sharing — specify which services get access to the data: Google Analytics, Firebase, Crashlytics, ad networks. For each service, provide its data processing policy.
  4. User Rights — describe how users can request data deletion, data export, and consent withdrawal. Provide a contact email for such requests.
  5. Data Security — describe protection measures: encryption during transmission (TLS), encryption at rest, server access control. Do not disclose specific technical details that could be exploited by attackers.
  6. Policy Changes — specify the procedure for notifying users about changes: email newsletters, in-app notifications, document date updates.

The policy language should be understandable to the average user — avoid overly legal wording. It is recommended to supplement the full version with a one-screen summary listing key points in plain language.

Where to Host the Privacy Policy

Hosting the privacy policy must ensure its constant availability via a direct link. There are several hosting options with different advantages.

Hosting MethodAdvantagesDisadvantages
Your Own WebsiteFull control, easy editing, single domain for all appsRequires hosting and a domain; if the site goes down, the link becomes unavailable
Google Drive / DocsFree, easy editing, automatic versioningNot an HTTPS URL (if public access is configured); may be blocked by corporate policies
Policy GeneratorsQuick template generation, built-in hosting (App Privacy Policy Generator, iubenda, Termly)Limited customization, monthly fee for advanced features
GitHub PagesFree hosting, HTTPS, versioning via GitRequires Git and Markdown skills for editing

The main requirement — the link must be accessible via HTTPS and lead to a page that does not require authentication to view. The policy page must display correctly on mobile devices.

Updating the Privacy Policy

Updating the privacy policy is not a one-time action but a regular process. Changes in legislation, adding new functionality, or switching analytical services require document review.

With each policy update, the developer must notify users. Notification methods: email newsletters (if the developer has user contacts), pop-ups or banners in the app requesting renewed consent, updating the document date on the policy page.

Special attention is required when changing the types of collected data. If the app starts collecting biometric data, background geolocation, or browser history — it is necessary not only to update the policy but also to obtain explicit user consent through iOS or Android system dialogs.

After updating the policy, update the link in Google Play and App Store consoles — in some cases (with significant changes), Apple may request re-completing the App Privacy Details questionnaire.

Frequently Asked Questions

Is a privacy policy required if the app does not collect data?

In the App Store — yes, it is required for all apps. In Google Play — it is required if the app requests data access permissions. Even if the app does not collect data, it is recommended to explicitly state this in the policy.

Can I use a generator to create a privacy policy?

Yes, generators (iubenda, Termly, App Privacy Policy Generator) are suitable for standard cases. But for apps collecting sensitive data (medical, financial, biometric), it is recommended to hire a lawyer to review the generated document.

What happens if the privacy policy link does not work?

Google Play and App Store conduct periodic checks. If the link is unavailable, the app may be blocked or rejected during the next update. In the App Store, a non-working link is one of the common reasons for build rejection during review.

How often should I update the privacy policy?

The policy should be updated with every change in data processing practices: adding a new analytics SDK, launching an advertising campaign, changing hosting provider, passing a new privacy law. The minimum cycle is once a year for a relevance review.

Does the privacy policy need to be in multiple languages?

Yes, if the app is published for users from different countries. Google Play and App Store recommend publishing the policy in all languages the app supports. The absence of translation does not lead to blocking, but may violate local legislation requirements.

Summary

  • Privacy Policy URL is a link to the privacy policy document, mandatory for publishing an app on Google Play and App Store.
  • Google Play requires a policy for apps collecting personal data; App Store requires it for all apps, including those that do not collect data.
  • The policy must include: data types, processing purposes, third-party sharing, user rights, security measures, and change procedures.
  • Hosting can be on your own website, GitHub Pages, Google Docs, or through generators (iubenda, Termly). The link must be HTTPS.
  • Updating the policy is required when data collection practices change — after updating, users must be notified and the link must be updated in store consoles.
  • Lack of a correct policy leads to build rejection, app blocking, and potential fines of up to 20 million euros (GDPR).

We will develop a mobile application turnkey

IT Sectr creates iOS and Android applications for startups and businesses since 2017. We will advise you and propose the best solution.

Discuss the project

Read also