Google Play account deletion URL: requirements and a template

By Turgay UlutaşUpdated 6 min read

The account deletion field shows up in the Data safety form, usually after you've already answered a dozen questions and just want to submit. It asks for a URL, and a lot of developers paste their privacy policy link or a support email and move on. Sometimes that passes. Often it comes back as a policy issue weeks later.

Here's what Google actually asks for, what the page needs to say, and a template you can adapt.

What Google requires

The rule is part of Google's User Data policy:

If your app allows users to create an account from within your app, then it must also allow users to request for their account to be deleted.

Users must have a readily discoverable option to initiate app account deletion from within your app and outside of your app.

So there are two paths, and you need both:

  1. In the app. A deletion option users can find, typically in account or settings.
  2. Outside the app. A web page where someone can request deletion, including a person who already uninstalled your app.

Google also says what deletion means:

When you delete an app account based on a user's request, you must also delete the user data associated with that app account. Temporary account deactivation, disabling, or "freezing" the app account does not qualify as account deletion.

You can keep specific data when there's a legitimate reason, such as fraud prevention, security or legal requirements like tax records. Your page and your privacy policy should say what you keep and for how long.

Who needs a deletion URL, and who doesn't

You need one if users can create an account from inside your app, whatever the method: email and password, Sign in with Google, phone number or any other login.

You don't need one if your app doesn't let users create accounts. In the Data safety form you answer that your app doesn't allow account creation, and the URL field doesn't apply. An app where people only sign in with accounts you create for them elsewhere (for example, staff accounts from an employer) is a different case; read the policy for your situation.

Google's account deletion help page also exempts permanently private apps and enterprise device management apps.

The deadline to complete the data deletion questions was December 7, 2023, with extensions for some developers until May 31, 2024. Any app with accounts published or updated today needs this in place.

What the web page must include

Google's requirement for the web link:

The weblink must be functional (for example, loads without error), relevant in scope (for example, the pathway to request account deletion should be prominently featured and easily discoverable on the page) and reference the app or developer name (that is, as it appears on your store listing in Google Play).

In practice, the page should have:

  • Your app's name (and developer name) exactly as on the store listing.
  • The steps, visible without scrolling through unrelated text. A long privacy policy with deletion buried in section 9 is a weak answer to "prominently featured".
  • A way to request deletion without the app: an email address, a form or a sign-in page with a delete button.
  • What gets deleted and what you keep, with retention periods for anything kept.
  • How long it takes. "Within 30 days" is common and easy to keep.

A template you can adapt

Replace the parts in brackets. Keep it on its own URL, such as /delete-account.

Delete your [App name] account

You can delete your [App name] account and its data at any time.

In the app: open [App name], go to Settings > Account > Delete account, and confirm.

Without the app: email [privacy email] from the address you signed up with, with the subject "Delete my account". We'll confirm by email and delete your account within 30 days.

What we delete: your account, profile, [content users create] and [other data].

What we keep: purchase records for [period], because tax law requires it. [Anything else, and why.]

[App name] is developed by [developer name as on Google Play].

If you use a form instead of email, make sure it works without an account and that someone actually reads the submissions.

Where to enter the URL in Play Console

Go to Policy and programs > App content > Data safety. In the data collection and security step, choose the account creation methods your app supports. Once you do, a field appears for the delete account URL. Paste the page's URL there and continue through the form.

The same form also asks whether users can request deletion of some data without deleting their whole account. That one is optional, and you only answer yes if you actually offer it.

Common reasons deletion pages get flagged

  • The link goes to the home page or app store listing. The deletion steps have to be on the page itself.
  • The link only works for signed-in users. The request path has to be reachable by someone who deleted the app.
  • It's just an email address in the URL field. Google asks for a web link.
  • The page doesn't name the app. Common when one generic page covers several apps.
  • "Deletion" is really deactivation. If the data stays, it doesn't count.
  • The in-app option is missing or hidden. Google asks for both paths, not one.

If your app uses Firebase Authentication

Firebase Auth makes the in-app part easy: call delete() on the signed-in user after a recent sign-in. Remember that it removes only the auth record. Data in Firestore, Realtime Database or Storage stays until you delete it too, usually with a Cloud Function that runs when a user is deleted, or in the same flow in your app. For the web request path, an email address that you handle by deleting the user in the Firebase console works fine at small scale.

Keep the three pages in sync

Your deletion page, your privacy policy and your Data safety form all describe deletion. They need to agree on what's deleted, what's kept and how long it takes. If you change your process, update all three together. It's one of the reasons a small website for your app is worth having: one place where the policy, the deletion steps and your contact details live together.

Frequently asked questions

Do I need an account deletion URL if my app has no login?
No. The requirement applies to apps that let users create an account from within the app. In the Data safety form you answer that your app doesn't allow account creation, and no URL is needed.
Can the deletion URL be an email address?
The Data safety form asks for a web link, so use a page. The page itself can tell people to request deletion by email, as long as it names the app and makes the steps easy to find.
Is deactivating an account enough?
No. Google says temporary deactivation, disabling or freezing an account does not qualify as account deletion. The account and its associated data have to be deleted.
Can I keep some data after deleting an account?
Yes, when there is a legitimate reason such as security, fraud prevention or legal requirements like tax records. Say what you keep and for how long on the deletion page and in your privacy policy.
Does Sign in with Google count as creating an account?
Yes, if signing in creates an account for the user in your app. Any sign-in method that creates an app account brings the deletion requirement with it.

Keep reading