How to fill in the Data safety form for the SDKs in your app
Updated
The Data safety form looks like a questionnaire about your app. It is really a questionnaire about everything that sends data off the phone, and in most apps the things doing that are SDKs you added for crashes, analytics, ads or sign-in, not code you wrote.
Google is explicit about it: collection includes "user data transmitted off device from your app by libraries and/or SDKs used in your app, irrespective of whether data is transmitted to you or a third-party server." And: "You must reflect data collection or sharing carried out by such third-party code in the Data safety form for your app."
Who has to fill it in?
Every app published on Google Play, including apps on closed, open or production testing tracks. So if you are running your 12-tester closed test, you need it now, not at launch. Only apps active solely on internal testing are exempt, along with system services and private apps.
An app that collects nothing still has to submit the form, and link a privacy policy.
What counts as "collected" and "shared"?
Collected means transmitted off the device. Data that stays on the phone is not collected, however sensitive it is.
One carve-out matters for small apps: data processed ephemerally, held only in memory and only for as long as it takes to serve a request, can be treated as not collected. Google's example is a weather app that sends your location to get the forecast and keeps nothing afterwards. Building an advertising or user profile from the data never qualifies.
Shared means transferred to a third party. Google lists cases that do not count as sharing: sending data to a service provider that processes it on your behalf, transfers for legal reasons, transfers the user starts and would expect (such as sharing a file to another app), and fully anonymised data.
How do I find out which SDKs my app contains?
Your dependency file lists what you added, not what those libraries brought with them. To see the full tree:
- Native and Flutter (Android side): run
./gradlew app:dependenciesin theandroidfolder and read the release runtime classpath. - React Native and Expo: your
package.jsonshows the JavaScript packages; the native SDKs they wrap appear in the Gradle dependency tree above.
Then, for each SDK that talks to a server, find what it says it collects.
Where do SDKs say what they collect?
The big providers publish a page written for exactly this form. Two examples:
- Firebase has one page listing what each of its Android SDKs collects: Crashlytics, for instance, collects stack traces and device metadata when the app crashes; Performance Monitoring collects app start time, network latency and CPU and memory use.
- The Google Mobile Ads SDK says it collects and shares the IP address, user interactions such as taps and video views, diagnostics, and device identifiers including the advertising ID, "for advertising, analytics, and fraud prevention purposes."
For others, Google Play SDK Index lists widely used commercial SDKs, which permissions they request, and links to each provider's Data safety guidance where the provider has published one.
What does the security practices section ask?
Two questions trip people up:
- Is data encrypted in transit? Yes if every connection your app and its SDKs make uses HTTPS or TLS. A single plain-HTTP call makes the honest answer "no".
- Can users request that their data is deleted? You can claim this if you give users a way to ask for deletion, or if collected data is deleted or anonymised automatically within 90 days.
Why does it matter at review?
Google says: "You alone are responsible for making complete and accurate declarations." When it finds a mismatch between your app and your answers, it will require you to fix it, and apps that do not become compliant are "subject to policy enforcement, like blocked updates or removal from Google Play."
One mismatch that is easy to find is between your answers and what is compiled into your build. So work from the build, not from memory: list the SDKs, read each one's disclosure, and answer for what your app and its backend actually do. The pre-launch checklist has the rest of what to check before you apply for production.