What the rejection typically looks like
Issue found: Data deletion questions in your Data safety form
Your app allows users to create an account, but the account deletion web resource you provided does not meet our requirements. The link must load without errors, reference your app or developer name as shown on Google Play, and prominently show how users can request deletion of their account and associated data without reinstalling the app.
Action required: Update the delete account URL in your Data safety form (Policy and programs > App content > Data safety), make sure the app offers an in-app path to account deletion, and submit your changes for review.
Paraphrased example – the exact wording in your message may differ.
What the Google Play account deletion requirement says
The rule is the Account Deletion Requirement in Google Play's User Data policy: "Users must have a readily discoverable option to initiate app account deletion from within your app and outside of your app." In practice that means three deliverables:
- An in-app path to delete the account and associated data, placed prominently, for example in account settings. Google allows this path to be a link to your web deletion page.
- A web resource where people can request account and data deletion without the app. Its URL goes into the designated field in Play Console.
- Completed Data deletion questions in the Data safety form. Your answers and links feed the data deletion badge and the Data deletion area on your store listing.
Deletion must be real: temporary deactivation, disabling or "freezing" an account "does not qualify as account deletion". The policy also lists "hidden patterns or undue rigor" in the deletion process as a don't. You may keep some data for security, fraud prevention or regulatory compliance if you clearly disclose it, for example in your privacy policy.
Timeline and scope
Google announced the requirement in April 2023. The Data deletion questions became mandatory on December 7, 2023, with an optional extension to May 31, 2024, and the new deletion details started showing on store listings in early 2024. Since then, new apps and updates can't be published while those answers are incomplete or have unaddressed issues, and non-compliant apps risk further enforcement up to removal. The requirement is still part of the User Data policy as of this guide's update date.
- In scope: any app account, including ones verified by phone OTP, biometrics or SSO such as Sign in with Google. It also applies when the app sends users to a website to sign up, and when an account is optional for some features.
- Out of scope: accounts created and operated offline. Permanently private apps and enterprise device management apps are exempt. Apps in highly regulated industries (such as healthcare, utilities or financial services) may add extra steps to complete a deletion request, but still need both paths.
- Non-mobile surfaces such as Wear OS or Android TV need only the web resource and its URL in Play Console.
Common reasons apps fail the account deletion review
1. The web link only points back to the app
A page saying "Open the app and go to Settings → Delete account" fails, as does one that needs a session that only exists in the app. Google's help article says the web resource must let users request deletion "without sending the user back to the app and requiring them to re-download it".
2. The link is broken or unreachable
Typical causes: a 404 after a website relaunch, an expired TLS certificate, a staging or localhost URL, a redirect to the homepage, or geoblocking and bot protection that block the reviewer. Google's own list of don'ts includes "broken or outdated links".
3. The page is too generic
Your homepage, a generic contact page or a privacy policy with deletion buried in paragraph 14 fails the "prominently featured and easily discoverable" test. The page must also reference the app or developer name as it appears on your store listing, which white-label apps and apps with a different brand on the website often miss.
4. Deactivation instead of deletion
"Pause my account", soft-delete flags that keep data forever, and support flows that never delete anything don't count. A short, disclosed grace period after which the data is actually deleted is a different thing and is compatible with the rule.
5. No in-app path, or a hidden one
Some apps provide only the web page. Others bury the option several screens deep in an in-app FAQ, add needless hurdles, or show it only in some countries.
6. Wrong Data safety answers or no reviewer access
The form says the app doesn't allow account creation, but the reviewer sees a sign-up screen or a Sign in with Google button. Or the reviewer has no working test account and can't reach the in-app option.
Rejected or stuck? Talk to an App Specialist – for free.
Book a free consultation call: we look at your rejection or setup, explain the fastest way forward and tell you honestly whether you need us. Prefer to hand it off? Book our AI-powered + human-powered service and we take care of it.
How to fix the rejection step by step
- Read the issue details. In Play Console, open Policy status and the enforcement email. Note whether the form, the link or the app is the problem, and which version codes are affected.
- Confirm scope. List every way an account can come into existence: in-app sign-up, SSO, phone login, guest accounts synced to your server, or a website sign-up linked from the app.
- Add the in-app path. Put a clearly labeled Delete account entry in Settings or Profile → Account: a confirmation screen explaining what gets deleted and kept, re-authentication, the backend call, then sign-out, cleared local data and a confirmation with the timeline. Opening your web deletion page from this entry is an accepted alternative.
- Make the backend delete for real. Remove the user record and the associated data you declared in the Data safety form: profile, uploads, messages, location history, push tokens and sessions. Google's help article says that if service providers process the data, you should delete it from your own servers and request the service provider to do the same. Let backups expire on a schedule you disclose.
- Publish the web resource described in the next section.
- Update the Data safety form and privacy policy to match, including retention rules.
- Give the reviewer access. Add a working test account under Policy and programs → App content → Sign-in details. Google requires these details to be reusable and valid at all times, and a reviewer may delete the account while testing, so recreate demo accounts automatically, for example with a nightly seed script.
- Ship and submit. If the app changed, build with a higher
versionCodeand upload it to production and every testing track (internal, closed, open) that carries the old build. Google says to deactivate non-compliant bundles, so make sure they sit under Not included in the new release, then send it for review together with the form changes.
If you use Firebase Authentication
FirebaseAuth.getInstance().currentUser?.delete() throws FirebaseAuthRecentLoginRequiredException if the last sign-in isn't recent, so reauthenticate first. Deleting the Auth user does not delete Firestore, Realtime Database or Cloud Storage data; clean that up in a backend function or with Firebase's Delete User Data extension.
What your account deletion web page must contain
Google's account deletion help article requires the link to be "functional", the deletion pathway to be prominent and the page to reference your app or developer name. Users must be able to submit a request through it: Google names a link that starts deletion, a customer service email or a form as options. A page that holds up in review usually has:
- A stable, public HTTPS URL such as
https://example.com/delete-account. The page itself should load without login, from any country and without the app. - The app name and developer name as shown on Google Play, in the heading.
- Numbered steps at the top and the request mechanism itself. If you verify identity, do it on the web, never "open the app to continue". Make sure every sign-in method works there: users who signed up with phone OTP or Sign in with Google have no password, so offer the same method, an email one-time code or a plain request form.
- What is deleted and what is kept, with reason and retention period, such as invoices kept for tax law.
- The timeline and how users are notified. Google asks you to complete requests "within a reasonably quick period of time"; laws such as the GDPR may be stricter.
- Prerequisites, such as subscriptions, "clearly outlined" with a support flow. Deleting an app account doesn't cancel a Google Play subscription, so link to
https://play.google.com/store/account/subscriptions. - Optional partial deletion of specific data, such as photos or history, without closing the account.
Reusing your privacy policy is allowed if the deletion section is "highlighted and reasonably prominent", for example via an anchor link like /privacy#delete-account, and users can actually submit a request from there. A dedicated page is clearer.
Answering the Data deletion questions in the Data safety form
Open Policy and programs → App content → Data safety and go to the Data collection and security step. The exact wording in Play Console changes from time to time, but expect questions along these lines:
| Question | What to enter |
|---|---|
| Whether you provide a way for users to request that their data is deleted | Yes if users can request deletion. Google also lets you answer yes if collected data is automatically deleted or anonymized within 90 days of collection. |
| Which account creation methods your app supports | Every method that applies, such as username and password or OAuth. Choose the "no account creation" option only if that is true for every version and region. |
| Link users can use to request account and data deletion | Your web deletion page, not the homepage or store listing. |
| Whether users can request deletion of some or all data without deleting their account | Yes only if that flow exists, plus its link. |
There is one global form per package name covering every version, region and user age currently distributed, so if any of them allows sign-up, declare it. The data types you declare also define what "associated data" your deletion must cover; our Data safety section guide shows how to audit them.
During the 2023 rollout you could unblock updates by clearing your deletion answers. That was a temporary workaround: since the December 2023 deadline, incomplete answers block publishing, so fix them instead.
How Google's rule differs from Apple's 5.1.1(v)
Teams that build for Apple first often fail on Google Play because Apple doesn't ask for a standalone web page:
| Topic | Google Play | Apple App Store |
|---|---|---|
| Inside the app | Required. A link to your web deletion page is acceptable. | Required. Deletion must be initiated in the app; a direct link to a web page that completes it is allowed. |
| Outside the app | Web resource required, usable without reinstalling | No standalone requirement |
| Email or support requests | A customer service email or form is an accepted way to request deletion on the web | Outside highly regulated industries, apps shouldn't require a phone call, email or other support flow |
| Declaration | Data deletion questions and URL in the Data safety form, shown on the listing | No dedicated form field; App Review checks the app |
| Provider-specific rules | None comparable | Apps with Sign in with Apple should revoke user tokens via its REST API |
A public deletion page with a real request mechanism plus a true in-app deletion flow usually covers both stores. Apple's details are in our 5.1.1(v) guide.
Responding to Google: resubmit or appeal
For most account deletion rejections, fix and resubmit. Google says not to republish a rejected app until the policy violation is fixed.
- Form or link problems only: correct the URL or answers and send the changes for review from Publishing overview. No new build is needed unless the app itself has to change.
- App problems: upload a build with a higher
versionCodeto every affected track and keep the rejected bundle out of all releases. - Reviewer couldn't load your page: remove the cause (geoblock, bot challenge, expired certificate) before resubmitting.
Appeal only if you are sure the finding is wrong, via the appeal link in the enforcement email or the Policy status page. Google allows one appeal per enforcement action, so include the deletion URL, the exact in-app path, test credentials and a short screen recording of both flows. If the reviewer got stuck at login, see our broken functionality guide.
Preventing account deletion rejections
- Make deletion part of "done" for every sign-in feature. When you add a login method or data store, extend the deletion job and page in the same pull request.
- Monitor the deletion URL from several regions: HTTP 200, a valid certificate and your app name in the HTML. Website redesigns break this link more often than code does.
- Add an end-to-end test in CI (Espresso or Maestro): create a throwaway account, delete it in the app, then assert the backend no longer knows the user.
- Re-check the Data safety form whenever a release adds SDKs, sign-in providers or data types.
AI-assisted checks are good at spotting contradictions between Data safety answers, privacy policy and deletion page; a human still needs to click through the flows like a reviewer. At appsubmitter.io we combine both in our CI/CD and submission work. Want a second pair of eyes before resubmitting? Book a free consultation call.
Template: how to reply to the Google Play review team
Adapt this template to your situation. Keep it factual, short and specific – and only claim what you have actually changed.
Checklist before you resubmit
- Every account type is covered: in-app sign-up, SSO, phone or OTP login, and website sign-up linked from the app.
- A clearly labeled Delete account option is easy to reach from account settings in every region.
- Deletion removes the account and all associated data declared in the Data safety form, and service providers get a deletion request.
- The web deletion URL loads over valid HTTPS without the app installed, geoblocking or bot challenges.
- The web page names the app or developer as on Google Play and lets users submit the request right there, whatever sign-in method they used.
- Retention exceptions, the deletion timeline and subscription cancellation steps are stated on the page and in the privacy policy.
- The Data safety form lists the correct account creation methods, the account deletion URL and accurate partial-deletion answers.
- Reusable test credentials are in Sign-in details and demo accounts are recreated if a reviewer deletes them.
- The new build has a higher versionCode, is on production and all testing tracks, and the rejected bundle is under Not included everywhere.
Frequently asked questions
Do I need a web deletion link if my app already has in-app account deletion?
Can the account deletion web page require users to log in?
Can I use my privacy policy as the account deletion URL?
/privacy#delete-account. It must still name your app or developer and give users a way to submit the request, such as a form or email address. A dedicated page is usually clearer for users and reviewers.My app only uses Sign in with Google. Does the account deletion requirement apply?
Can I keep some user data after deleting an account?
How fast do I have to delete the data?
Does the requirement apply to Wear OS or Android TV apps?
Official source: Play Console Help – Understanding Google Play's app account deletion requirements. Store policies change regularly – always check the current version. This guide is independent advice and not affiliated with Apple or Google.