SMS and Call Log permissions on Google Play

Checked against Google's policy pages on .

  • android.permission.READ_SMS
  • android.permission.RECEIVE_SMS
  • android.permission.SEND_SMS
  • android.permission.READ_CALL_LOG
  • android.permission.WRITE_CALL_LOG
  • android.permission.PROCESS_OUTGOING_CALLS

What does it allow?

These permissions let an app read, receive or send text messages, and read or change the call history. They expose some of the most personal data on a phone, which is why Google Play treats them as its most restricted group.

Which apps does Google Play allow to use it?

Google's rule: "Apps must be actively registered as the default SMS, Phone, or Assistant handler before prompting users to accept any of SMS or Call Log permissions."

Google lists exceptions for specific cases, among them caller ID and spam detection, backup and restore, companion apps for connected devices, cross-device sync, enterprise management, emergency alerts and SMS-based financial transactions. Each still needs a declaration and review.

Why is it in my app?

An OTP or phone-verification library that reads the incoming code is the usual source when an app that is not a messaging app ends up with RECEIVE_SMS or READ_SMS.

To see every permission in your build and which ones may need a declaration, paste your merged manifest into the Play Console permission declaration checker.

What can I use instead?

For one-time codes, Google points to the SMS Retriever API, which lets your app receive the verification SMS automatically without any SMS permission. To send a message, hand it to the user's SMS app with an intent instead of sending it yourself.

How do I remove it?

Add it to your own manifest with tools:node="remove". The manifest merge then leaves it out, whichever library declared it. In Flutter and React Native the file is android/app/src/main/AndroidManifest.xml.

<manifest xmlns:android="http://schemas.android.com/apk/res/android"
    xmlns:tools="http://schemas.android.com/tools">
    <uses-permission android:name="android.permission.READ_SMS" tools:node="remove" />
    <uses-permission android:name="android.permission.RECEIVE_SMS" tools:node="remove" />
    <uses-permission android:name="android.permission.SEND_SMS" tools:node="remove" />
    <uses-permission android:name="android.permission.READ_CALL_LOG" tools:node="remove" />
    <uses-permission android:name="android.permission.WRITE_CALL_LOG" tools:node="remove" />
    <uses-permission android:name="android.permission.PROCESS_OUTGOING_CALLS" tools:node="remove" />
</manifest>

In Expo, block it in your app config instead:

{
  "expo": {
    "android": {
      "blockedPermissions": [
        "android.permission.READ_SMS",
        "android.permission.RECEIVE_SMS",
        "android.permission.SEND_SMS",
        "android.permission.READ_CALL_LOG",
        "android.permission.WRITE_CALL_LOG",
        "android.permission.PROCESS_OUTGOING_CALLS"
      ]
    }
  }
}

Then test the feature the library provides: if it needed the permission, that feature may stop working.

How do I declare it if I keep it?

If your app is a default handler or fits one of the exceptions, declare the permissions through the Permissions Declaration Form in Play Console. Google says apps that do not meet the policy or lack the form may be removed from Google Play.

Common questions

Can I read SMS to auto-fill a login code?
Not with READ_SMS unless your app is the default SMS handler. Use the SMS Retriever API, which delivers the code to your app without the permission.
Can my app send SMS without SEND_SMS?
Yes: open the user's messaging app with an intent pre-filled with the number and text, and let them press send.

Sources

May we use analytics and ad measurement? Analytics (Vercel, and Ahrefs on our public pages) count page views without cookies. Ad measurement lets Google's tag on our public pages see which visits came from our Google ads, using a Google cookie. The site works the same either way. Cookie Policy · How Google uses data ·