Back to Blog
Legal 2026-08-02 15 min read

App Privacy Policy Template 2026 — Annotated, App Store & Google Play Ready

WhixFrame Team

App marketing tools built by developers who've shipped 20+ apps to the App Store and Google Play.

Most privacy policy templates available online are written for websites. They miss the specific clauses that Apple and Google require for app submissions — and those missing sections are exactly why apps get rejected. This article gives you a complete, annotated privacy policy template written specifically for mobile app developers, with every clause explained.

The template covers iOS and Android, GDPR for EU users, CCPA for California users, Firebase and other common SDK disclosures, Apple's App Tracking Transparency requirements, and Google Play's account deletion requirements. Each clause is annotated so you understand what it does and what you need to customize.

This is not legal advice. For apps in regulated industries or with unusual data practices, consult a lawyer. For a standard indie app, this template covers what App Review and Google Play Policy expect to see.

What a Mobile App Privacy Policy Must Include in 2026

Both Apple and Google have explicit requirements. Here are the sections that are non-negotiable:

Apple App Store (Guideline 5.1.1)

  • • Identity of the developer/company
  • • Types of data collected
  • • How data is used
  • • Who data is shared with
  • • Data retention periods
  • • User rights (access, correction, deletion)
  • • Contact information for privacy questions
  • • ATT disclosure if tracking across apps

Google Play User Data Policy

  • • All personal data collected (including via SDKs)
  • • Purpose for each data type collected
  • • Third parties data is shared with
  • • User data deletion process (required since 2023)
  • • How to request data deletion even without app access
  • • Disclosures matching the Data Safety section
  • • Contact information for privacy requests

The Full Annotated Privacy Policy Template

Below is a complete template. Text in [brackets] requires customization. Annotations in italics explain each section's purpose and what App Review looks for.

Section 1: Introduction

Purpose: Identify who controls the data and establish the policy's scope. Apple looks for the developer identity to match App Store Connect account information.

Privacy Policy for [App Name]


Last updated: [Date]


[Developer Name / Company Name] ("we," "our," or "us") operates the [App Name] mobile application (the "App"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our App. Please read this policy carefully. If you disagree with its terms, please discontinue use of the App.

Section 2: Information We Collect

Purpose: Enumerate all categories of data collected. This is the most important section — every data type you collect, including via SDKs, must be listed here. Apple and Google cross-reference this against their internal data categories.

We collect several types of information when you use our App:


Information You Provide Directly:

[Include only the types that apply to your app:]

• Account registration information: email address, display name, profile photo [if your app has accounts]

• Content you create: [notes, tasks, photos, etc. — describe specifically]

• Communications: support emails, feedback forms


Information Collected Automatically:

• Device information: device model, operating system version, unique device identifiers

• Usage data: features accessed, actions taken, session duration, screen views

• Diagnostic data: crash reports, performance data, error logs

[If you use location:] • Location data: [precise/approximate] location [describe why and when]


Information from Third-Party SDKs:

We integrate third-party services that may collect information automatically, including:

• Firebase Analytics (Google LLC): app usage events, session data, device identifiers. See Google's Privacy Policy at policies.google.com/privacy

• Firebase Crashlytics (Google LLC): crash reports including stack traces and device information

[Add other SDKs you use: AdMob, Mixpanel, Amplitude, RevenueCat, etc.]

Section 3: How We Use Your Information

Purpose: State the purpose for each data collection. GDPR requires a stated legal basis for each purpose. App Review checks that stated purposes are plausible for the app's functionality.

We use the information we collect to:

• Provide and maintain the App and its features

• Create and manage your account [if applicable]

• Process in-app purchases [if applicable]

• Send push notifications you have opted into [if applicable]

• Analyze usage patterns to improve App performance and user experience

• Diagnose and fix technical problems through crash reports

• Respond to your support requests and communications

• Comply with legal obligations

[Do not include purposes you do not actually perform — Apple reviewers check for implausible claims]

Section 4: Information Sharing and Disclosure

Purpose: Disclose all third parties with whom data is shared. Critical: "we do not sell your data" must be accurate — if you use advertising SDKs, data may be considered "sold" under CCPA's broad definition.

We do not sell your personal information. We may share information with:


Service Providers: Third-party companies that help us operate the App, including Google LLC (Firebase services), [list others]. These providers process data only as instructed by us and under confidentiality obligations.


Legal Requirements: We may disclose information if required by law, court order, or government request, or to protect the rights, property, or safety of our users or the public.


Business Transfers: If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any change in ownership or data practices.


[If you use advertising:] Advertising Partners: [Describe what data is shared with advertising partners, including whether advertising IDs are shared, and for what purpose.]

Section 5: Data Retention

Purpose: State how long data is retained. GDPR requires data not be kept longer than necessary. Google Play's Data Safety section asks you to declare retention periods.

We retain personal information for as long as necessary to provide the App's services and fulfill the purposes described in this policy, unless a longer retention period is required by law.


• Account data: retained while your account is active, deleted within 30 days of account deletion request

• Analytics data: retained for [12/24] months, then automatically deleted

• Crash reports: retained for 90 days

• Support correspondence: retained for 2 years


To delete your account and all associated data, [describe the deletion method: go to Settings → Account → Delete Account, or email us at [contact email]]. We will process deletion requests within 30 days.

Section 6: Your Rights

Purpose: GDPR and CCPA both require a statement of user rights. This section also satisfies Google Play's requirement to disclose the account deletion process.

Depending on your location, you may have the following rights regarding your personal information:

Access: Request a copy of the personal information we hold about you

Correction: Request correction of inaccurate personal information

Deletion: Request deletion of your personal information and account

Portability: Request your personal information in a portable format

Objection: Object to our processing of your personal information


To exercise these rights, contact us at [contact email]. We will respond within 30 days. Note that some rights may not apply in all jurisdictions or may be limited by our legal obligations.


Account Deletion: You can delete your account directly in the App by going to [Settings → Account → Delete Account]. You can also request account deletion by emailing [contact email] with the subject "Account Deletion Request." We will delete your account and associated data within 30 days. Data shared with third-party services (such as analytics providers) may be subject to their own retention policies.

Section 7: Children's Privacy (COPPA)

Purpose: Required if your app is not directed at children (to confirm) or if it is (to explain special protections). Apple reviewers check this against your age rating.

[If your app is NOT for children under 13:] Our App is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If we discover that a child under 13 has provided personal information to us, we will delete it immediately. If you believe a child under 13 has provided us with personal information, contact us at [contact email].


[If your app IS for children or has mixed audience:] Consult with a lawyer regarding COPPA compliance before publishing. This requires significantly more specific disclosures and parental consent mechanisms.

Section 8: Contact Information and Updates

Purpose: GDPR requires a reachable privacy contact. Apple App Review verifies the contact email is functional. Policy must state how users will be notified of changes.

If you have questions or concerns about this Privacy Policy or our data practices, contact us at:

[Developer Name / Company Name]

Email: [privacy@yourdomain.com]

[Optional: Physical address if required in your jurisdiction]


We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last updated" date at the top of this policy, and by providing notice within the App or by email for significant changes. Your continued use of the App after changes become effective constitutes your acceptance of the updated policy.

App-Specific Clauses Most Generic Templates Miss

  • Apple's App Tracking Transparency (ATT) disclosure. If your app requests ATT permission to access the advertising identifier (IDFA), your privacy policy must explicitly state that you collect the advertising identifier, for what purpose (typically advertising or cross-app analytics), and how users can revoke permission. Generic website templates never include this.
  • Account deletion flow disclosure. Since 2023, Google Play requires apps with user accounts to provide an in-app account deletion option AND disclose the deletion process in the privacy policy, including the ability to request deletion via email without having app access. Apple has similar requirements under Guideline 5.1.1. Your policy must state both the in-app method and an email alternative.
  • Apple Privacy Manifest disclosure. Since 2024, Apple requires apps using certain APIs (NSUserDefaults, file timestamp APIs, disk space APIs, and others) to include a Privacy Manifest (PrivacyInfo.xcprivacy) declaring the reason for using each API. Your privacy policy should reference this and be consistent with your manifest declarations.
  • In-app purchase refund policy reference. If your app has in-app purchases, your privacy policy or a linked terms document should reference that refund policy is managed by Apple or Google (not you directly). Apple reviewers sometimes flag apps that promise direct refunds that Apple's system does not allow.
  • SDK-specific third-party disclosures. Generic templates say "we may use third-party services." App Review expects specific named services — Firebase, AdMob, RevenueCat, Mixpanel, Amplitude — not vague collective references. List every SDK that touches user data by name.

App Store vs Google Play: Where to Add Your Privacy Policy URL

Apple App Store Connect

  1. Go to App Store Connect → Your App → App Information
  2. Find the "Privacy Policy URL" field
  3. Paste your hosted privacy policy URL
  4. The URL must work without a login or redirect
  5. Also add a link to your privacy policy inside the app itself (Settings or About section)

Google Play Console

  1. Go to Play Console → Your App → Policy
  2. Select "App content" → Privacy Policy
  3. Paste your privacy policy URL
  4. Also complete the Data Safety section accurately
  5. The policy must match the Data Safety declarations

Where to Host Your Privacy Policy (Free Options)

  • GitHub Pages. Create a public repository, add an index.html file with your policy content, enable GitHub Pages in Settings → Pages. You get a permanent URL like yourusername.github.io/app-privacy. Free forever, no expiry. Recommended for most indie developers.
  • Notion. Write your privacy policy in Notion, share it publicly (Share → Publish to web). Use the published URL. Fast to set up but Notion URLs can change if you restructure your workspace. Save the exact URL you use in App Store Connect and do not change it.
  • Google Sites. Create a free Google Site, add a page with your privacy policy text. Hosted at sites.google.com with a permanent URL. Simple and reliable.
  • Your app's own website. If you have a landing page for your app, add a /privacy path with your policy. This is the most professional option and what users expect for established apps.
  • What not to use. Do not host your privacy policy on a service that adds ads or a paywall in front of it. Do not use a URL shortener — App Review validates the full URL. Do not use a file attachment (Google Drive PDF, Dropbox link) — the policy must be a proper webpage.

Generate a Customized App Privacy Policy Free

Enter your app name, select the SDKs you use, choose your compliance regions, and download a ready-to-host privacy policy. No signup, no watermark, no credit card.

Generate Free Policy

Generate a Customized Version Free

The template above is a starting point. WhixFrame's free privacy policy generator customizes this template for your specific app — choosing the right clauses based on:

  • Which data collection categories your app uses
  • Which third-party SDKs you integrate (Firebase, AdMob, RevenueCat, etc.)
  • Which compliance regions apply (GDPR for EU, CCPA for California, COPPA for children's apps)
  • Whether your app has user accounts with in-app deletion support
  • Whether your app uses Apple's App Tracking Transparency

The generator produces a complete HTML file you can host directly on GitHub Pages, plus a plain text version for easy editing. No account required, completely free, no watermark on the output.

Go to whixframe.com/tools/privacy-policy-generator to generate yours.

Frequently Asked Questions

How long should a mobile app privacy policy be?

Long enough to cover all required disclosures, but not artificially padded. A well-structured policy for a typical indie app covers the required sections in 800–1,500 words. Very simple apps (no accounts, no analytics, no permissions) can be shorter. Apps with many SDKs, accounts, payments, and location data will naturally be longer. Length should follow content, not the other way around.

My app is still in development. Do I need a privacy policy before submitting to TestFlight or Google Play internal testing?

For TestFlight (Apple's beta testing platform), a privacy policy URL is required when you invite external testers (not internal testers who are your own team). For Google Play open and closed testing tracks, a privacy policy is required. For internal testing tracks, it is technically not required but recommended as it becomes required when you promote to production.

What happens if my privacy policy URL goes down?

Apple may flag the issue during a future review cycle or in response to a user complaint. Google Play may send a policy violation notice. Your store listing could be taken down if the URL remains inaccessible for an extended period. Use a hosting solution that you can commit to maintaining — GitHub Pages with a permanent repository is the most reliable free option.

Do I need a privacy policy in multiple languages?

Not required for App Store submission. Apple displays your privacy policy URL to users regardless of their language, and they navigate to your hosted version. Google Play similarly accepts a single URL. However, if your app targets specific non-English markets significantly (especially EU markets where GDPR applies), having the policy available in the local language is best practice and builds user trust.

Last updated: 2026-08-02 · Written by the WhixFrame team based on first-hand experience shipping apps to both stores.