Skip to content
Docs
Docs/Publish

Prepare privacy, support and review access

Prepare real support and privacy pages, accurate store disclosures, account deletion and reviewer access for your app.

8 min readUpdated Oct 1, 2026

Store declarations should describe the app you are submitting, including its connected services. A generic policy or a successful build does not establish that those declarations are correct.

On this page

Start with the app’s actual data

Ask the agent to help inspect which features collect, store or send information. Review sign-in, saved records, uploads, analytics, payments and AI requests. Include third-party services and SDKs.

Use the findings to write and verify the disclosures. Do not infer no data collected merely because the app has no custom database.

Prepare public pages users can open

Use real published URLs and test them while signed out on a phone. Avoid placeholder addresses or links to private dashboards. Your app’s policy must describe its own behavior; the RNBlocks website policy is not a replacement.

Apple requires a privacy policy URL and app privacy answers. Its Support URL should lead to actual contact information. Complete Google Play’s Data safety form with the app’s data practices, including relevant third-party handling.

PageInclude

Privacy policy

The app and responsible publisher, data handled, purposes, services involved, retention and deletion practices, and a contact route.

Support

A working way to get help, with useful instructions for the app’s main features.

Account deletion, when needed

A usable request path, what is deleted, and any retained data and reason.

Complete Apple’s App Privacy fields

RNBlocks can propose answers for you to review. Enter and publish them in App Store Connect for now. Apple’s documented publishing API uses API keys; Sign in with Apple does not grant App Store Connect management access. RNBlocks does not ask for your Apple Account password.

  1. Add the policy URL

    In App Store Connect → Apps, select the app → App Privacy. Next to Privacy Policy, choose Edit, enter the published policy URL and Save.

  2. Describe the data practices

    Choose Get Started. Include collection by third-party code. Select relevant data types, then complete each type’s follow-up questions and save.

  3. Review before publishing the answers

    Check Product Page Preview. An authorized account holder reviews the accuracy confirmation before choosing Publish. This publishes privacy responses; it does not release the app.

Prepare the App Privacy information

Apple’s official App Privacy example. Complete it using your app’s actual data practices.

Apple: Manage App Privacy
  1. Provide the privacy policy for your app.
  2. Choose Get Started and review what your app and connected services collect.
  3. Use your app’s actual practices; the sample does not supply your answers.
Prepare the App Privacy information

Apple’s official App Privacy example. Complete it using your app’s actual data practices.

Complete Google Play’s Data safety form

Use Google’s definitions, including its exceptions for service-provider processing, instead of copying Apple’s labels unchanged. Revisit the answers when your app’s behavior changes. Closed/open testing and production require the form; an app exclusively in internal testing has an exemption.

Your intended audience is a product choice, separate from the content age rating. Select the age groups you designed the app for.

Some declarations still need Play Console. The agent can propose answers and link you to the correct page; review and save them there, then return to the same publishing conversation. Complete Ads and sign-in access before Target audience when Google lists them as prerequisites. Connecting with OAuth would not add fields missing from Google’s public API.

  1. Review the agent’s proposal

    In Store details, choose Review Google Data safety. Ask the agent to suggest answers from your app, then review or edit the collection, sharing, purposes, security and deletion answers. Save answers keeps your draft in RNBlocks.

  2. Approve the upload

    Choose Continue with agent to prepare the exact Google save review. With a connected Google Play account, the agent can send the approved answers through Google’s API. This does not release your app.

  3. Check the form in Google Play

    Open Play Console → App content → Data safety and confirm the answers arrived. Google may still require the separate Privacy policy URL and Target audience and content setup before the declaration can be submitted. A successful upload does not mean Google has approved it.

If users can create accounts

Apple requires apps supporting account creation to let users initiate deletion in the app. Temporary deactivation is not the same as deleting the account.

Google Play requires an in-app deletion path and a web resource for deletion requests when the app enables account creation. Explain any data that must be retained and why.

Test the implemented deletion journey using a disposable account. A privacy-policy sentence alone does not perform deletion.

Apple generally does not accept requiring a support call or email instead of a deletion flow outside highly regulated industries. If deletion takes time, explain the process and confirm completion. Apps using Sign in with Apple must also revoke the relevant user tokens.

Deleting an account and cancelling a store subscription are different tasks. Explain how users can manage an active subscription before deleting their account; do not quietly imply billing has stopped.

If personal data goes to an AI service

Identify the actual downstream provider and information sent. Under Apple’s current review rule, disclose where personal data goes and obtain explicit permission before sharing it with a third-party AI service.

Check the running app’s behavior: a user who declines should not have that personal data sent anyway. Do not promise on-device processing, training exclusions or retention terms unless they match the actual service and configuration.

Help the reviewer use the app

Avoid putting personal credentials in RNBlocks chat or public documentation. Use the provider’s private review fields for the access information it requests.

  • Provide an appropriate review account and instructions through the store’s designated review-access fields when sign-in is required.

  • Keep the backend and connected services available during review.

  • Explain any non-obvious setup, permission or sample-data requirement.

  • Complete age rating, content and other declarations using the app’s actual behavior.

  • Verify support, privacy and deletion links before submission.

Official references

Documentation
Open Studio