Privacy Policy URL is a link to the privacy policy document that every app must provide when publishing on Google Play and App Store. Without a working link, app publication is impossible. According to Apple Developer, 2026, more than 15% of app rejections in the App Store are related to the absence or incorrect privacy policy.
Key Takeaways
Privacy Policy URL is a web address where the app's privacy policy document is hosted. Users must be able to read this document before installing the app — the link is displayed on the store page.
The privacy policy is a legally significant document that regulates the relationship between the developer (data operator) and the user (data subject). In most countries, having such a document is mandatory by law, not just per store requirements.
According to GDPR (General Data Protection Regulation), 2018, fines for the absence of a privacy policy in the EU can reach 20 million euros or 4% of the company's annual global turnover. In the US, similar requirements are regulated by state laws, including CCPA in California.
Google Play requires a privacy policy link for all apps that request access to users' personal data. This includes apps working with contacts, geolocation, camera, microphone, photos, and media files.
The link is added in the Store Presence section → Store Listing → Privacy Policy. Google Play does not automatically check the document's content but may request compliance verification with actual data collection during review.
If the app collects sensitive data (medical, biometric, financial), Google Play may require confirmation that the policy complies with the Google Play Developer Program Policies. In this case, the link must lead to a page containing the data operator's contact information.
For apps developed under the Google Play for Education program, additional policy specification is required in a format compliant with FERPA (Family Educational Rights and Privacy Act).
App Store requires a privacy policy for all apps without exception — even if the app does not collect any user data. This is one of Apple's strictest requirements, and violating it leads to build rejection.
The policy link is added in App Store Connect in the App Privacy section. In addition to the link, Apple requires filling out the Privacy Details form — a questionnaire about the types of data collected, their usage, and user linking. This information is displayed on the app page before installation.
Apple verifies compliance between the privacy policy and the app's actual behavior. If a reviewer finds that the app collects data not mentioned in the policy, the build will be rejected with a misrepresentation ruling.
For apps working with children (Kids category), Apple requires an additional section in the policy describing compliance with COPPA (Children's Online Privacy Protection Act) and parental consent procedures.
The privacy policy must be complete, accurate, and reflect actual data processing practices. The minimum set of sections is defined by international GDPR standards and app store recommendations.
The policy language should be understandable to the average user — avoid overly legal wording. It is recommended to supplement the full version with a one-screen summary listing key points in plain language.
Hosting the privacy policy must ensure its constant availability via a direct link. There are several hosting options with different advantages.
| Hosting Method | Advantages | Disadvantages |
|---|---|---|
| Your Own Website | Full control, easy editing, single domain for all apps | Requires hosting and a domain; if the site goes down, the link becomes unavailable |
| Google Drive / Docs | Free, easy editing, automatic versioning | Not an HTTPS URL (if public access is configured); may be blocked by corporate policies |
| Policy Generators | Quick template generation, built-in hosting (App Privacy Policy Generator, iubenda, Termly) | Limited customization, monthly fee for advanced features |
| GitHub Pages | Free hosting, HTTPS, versioning via Git | Requires Git and Markdown skills for editing |
The main requirement — the link must be accessible via HTTPS and lead to a page that does not require authentication to view. The policy page must display correctly on mobile devices.
Updating the privacy policy is not a one-time action but a regular process. Changes in legislation, adding new functionality, or switching analytical services require document review.
With each policy update, the developer must notify users. Notification methods: email newsletters (if the developer has user contacts), pop-ups or banners in the app requesting renewed consent, updating the document date on the policy page.
Special attention is required when changing the types of collected data. If the app starts collecting biometric data, background geolocation, or browser history — it is necessary not only to update the policy but also to obtain explicit user consent through iOS or Android system dialogs.
After updating the policy, update the link in Google Play and App Store consoles — in some cases (with significant changes), Apple may request re-completing the App Privacy Details questionnaire.
Frequently Asked Questions
In the App Store — yes, it is required for all apps. In Google Play — it is required if the app requests data access permissions. Even if the app does not collect data, it is recommended to explicitly state this in the policy.
Yes, generators (iubenda, Termly, App Privacy Policy Generator) are suitable for standard cases. But for apps collecting sensitive data (medical, financial, biometric), it is recommended to hire a lawyer to review the generated document.
Google Play and App Store conduct periodic checks. If the link is unavailable, the app may be blocked or rejected during the next update. In the App Store, a non-working link is one of the common reasons for build rejection during review.
The policy should be updated with every change in data processing practices: adding a new analytics SDK, launching an advertising campaign, changing hosting provider, passing a new privacy law. The minimum cycle is once a year for a relevance review.
Yes, if the app is published for users from different countries. Google Play and App Store recommend publishing the policy in all languages the app supports. The absence of translation does not lead to blocking, but may violate local legislation requirements.
Summary
We will develop a mobile application turnkey
IT Sectr creates iOS and Android applications for startups and businesses since 2017. We will advise you and propose the best solution.
Read also