What this rejection actually checks
Google cross-checks three things: a reachable privacy policy URL, the data-use disclosure you filled in the dashboard, and whether both match your code's real behavior. Any gap between them is what gets flagged.
- No privacy policy URL (or a dead / placeholder link) when your extension handles any user data.
- Disclosure mismatch — the dashboard says "no data collected" but the code sends data somewhere (analytics, a server call).
- Incomplete disclosure — the data-use section (collection, use, sale) is left blank or vague.
- Policy contradicts code — the written policy describes handling that doesn't match what the extension does.
How to fix it and resubmit
- Publish a real privacy policy. A public, reachable URL that accurately describes what you collect and why. Link it in the listing.
- Fill the data-use disclosure honestly. Tick exactly what you collect and how it's used — match it line-by-line to your code.
- If it's all local, prove it. When you process on-device and send nothing, state "no data collected" and make sure no network call contradicts it.
- Keep policy = disclosure = code. All three must tell the same story. Reviewers reject the moment they diverge.
Rule of thumb: the reviewer trusts your code over your words. Make the words match the code, not the other way around.
Privacy is one of six rejection families (permissions/Purple Potassium, metadata/Blue Argon, single purpose, privacy, remote code, functionality/Yellow Magnesium). If your email lists more than one, fix them together — a second rejection resets the review clock.
Not sure where policy and code diverge?
Paste your rejection email — get the exact cause in seconds, free. Or we fix the policy, disclosure, and code alignment and resubmit for you.
Free diagnosis → Remote code rejection? →