How to fill in the Data safety form for the SDKs in your app

Updated

The Data safety form looks like a questionnaire about your app. It is really a questionnaire about everything that sends data off the phone, and in most apps the things doing that are SDKs you added for crashes, analytics, ads or sign-in, not code you wrote.

Google is explicit about it: collection includes "user data transmitted off device from your app by libraries and/or SDKs used in your app, irrespective of whether data is transmitted to you or a third-party server." And: "You must reflect data collection or sharing carried out by such third-party code in the Data safety form for your app."

Who has to fill it in?

Every app published on Google Play, including apps on closed, open or production testing tracks. So if you are running your 12-tester closed test, you need it now, not at launch. Only apps active solely on internal testing are exempt, along with system services and private apps.

An app that collects nothing still has to submit the form, and link a privacy policy.

What counts as "collected" and "shared"?

Collected means transmitted off the device. Data that stays on the phone is not collected, however sensitive it is.

One carve-out matters for small apps: data processed ephemerally, held only in memory and only for as long as it takes to serve a request, can be treated as not collected. Google's example is a weather app that sends your location to get the forecast and keeps nothing afterwards. Building an advertising or user profile from the data never qualifies.

Shared means transferred to a third party. Google lists cases that do not count as sharing: sending data to a service provider that processes it on your behalf, transfers for legal reasons, transfers the user starts and would expect (such as sharing a file to another app), and fully anonymised data.

How do I find out which SDKs my app contains?

Your dependency file lists what you added, not what those libraries brought with them. To see the full tree:

  • Native and Flutter (Android side): run ./gradlew app:dependencies in the android folder and read the release runtime classpath.
  • React Native and Expo: your package.json shows the JavaScript packages; the native SDKs they wrap appear in the Gradle dependency tree above.

Then, for each SDK that talks to a server, find what it says it collects.

Where do SDKs say what they collect?

The big providers publish a page written for exactly this form. Two examples:

  • Firebase has one page listing what each of its Android SDKs collects: Crashlytics, for instance, collects stack traces and device metadata when the app crashes; Performance Monitoring collects app start time, network latency and CPU and memory use.
  • The Google Mobile Ads SDK says it collects and shares the IP address, user interactions such as taps and video views, diagnostics, and device identifiers including the advertising ID, "for advertising, analytics, and fraud prevention purposes."

For others, Google Play SDK Index lists widely used commercial SDKs, which permissions they request, and links to each provider's Data safety guidance where the provider has published one.

What does the security practices section ask?

Two questions trip people up:

  • Is data encrypted in transit? Yes if every connection your app and its SDKs make uses HTTPS or TLS. A single plain-HTTP call makes the honest answer "no".
  • Can users request that their data is deleted? You can claim this if you give users a way to ask for deletion, or if collected data is deleted or anonymised automatically within 90 days.

Why does it matter at review?

Google says: "You alone are responsible for making complete and accurate declarations." When it finds a mismatch between your app and your answers, it will require you to fix it, and apps that do not become compliant are "subject to policy enforcement, like blocked updates or removal from Google Play."

One mismatch that is easy to find is between your answers and what is compiled into your build. So work from the build, not from memory: list the SDKs, read each one's disclosure, and answer for what your app and its backend actually do. The pre-launch checklist has the rest of what to check before you apply for production.

Sources

Next steps

Still need testers? Get 12 testers for your closed test through a free test-for-test exchange - you test another developer's app, they test yours, and every opt-in is verified.

Applying for production soon? Check your APK against the Google Play launch checklist - target API, permissions that need a declaration, your Data Safety form and leaked keys. The first check is free.

Common questions

Do I have to fill in the Data safety form if my app collects no data?
Yes. Google says even apps that do not collect any user data must complete the form and provide a link to their privacy policy.
Am I responsible for what an SDK in my app collects?
Yes. Google's rules say data sent off the device by libraries and SDKs in your app counts as your app's collection, and must be reflected in your form.
Does a closed test need the Data safety form?
Yes. Google says apps on closed, open or production tracks must complete it. Only apps active solely on internal testing are exempt.
What happens if my Data safety answers are wrong?
Google says it will require you to fix a misrepresentation, and apps that do not become compliant are subject to enforcement such as blocked updates or removal.

Apps currently in closed testing

Real developers running the test described above. Test one, and get testers for your own app back.

Closed testing

FitLifeApp is a daily habit and goal-tracking app that helps users monitor water intake, step goals, and mood entries. Please test the following: - Set a daily water goal, add water intake, and check whether the totals and remaining amount update correctly. - Set a step goal and check the progress display. - Add mood entries and review previous records. - Close and reopen the app to check whether your saved data is still available. - Use the app on different days to check daily tracking and history. - Check for confusing navigation, overlapping text, or buttons that do not work correctly. Please join the Google Group and the Google Play closed test using the same Google account. Install the app through Google Play and stay enrolled for at least 14 consecutive days, using its features during the testing period. When reporting a problem, include what happened, the steps to reproduce it, your device model, and Android version. Screenshots are welcome. Thank you for helping improve FitLifeApp!

Health & FitnessProductivityLifestyle

Open to testers · 14-day test

Closed testing

Testers must join the Google Group using the same Google account they use on their Android device's Google Play Store. Testers must open the opt-in link, tap Become a tester, and then download the build via the Play Store link provided.

News & Books

Open to testers · 14-day test

Closed testing

Hi! I’m looking for testers for Crew Bites, a Flutter app that helps groups organize food orders, track who ordered what, and calculate the final bill fairly. Please test the main flow: add people, add food orders, select a restaurant/bundle, add tax/service/tip/delivery, review the total, and save or share the result. I’d especially appreciate feedback about usability, layout, performance, and any bugs on your Android device. Thank you!

Food & Drink

Open to testers · 14-day test

Related guides

May we use analytics and ad measurement? Analytics (Vercel, and Ahrefs on our public pages) count page views without cookies. Ad measurement lets Google's tag on our public pages see which visits came from our Google ads, using a Google cookie. The site works the same either way. Cookie Policy · How Google uses data ·