An app's privacy notice, its store disclosure, and the behavior on your phone should match each other. If those sources conflict, or a privacy request you already tried went nowhere, you can file a complaint. Save proof before anything on the listing changes.
Most U.S. consumers should report the app through its store and, when the facts fit, send a complaint to a public agency. Those routes do different jobs. A store can review its own platform rules. An agency may use reports to identify deceptive or unlawful business practices.
This is practical consumer information, not legal advice. Who has last week's policy if you wait? Keep a dated copy.
Save proof before the app changes
Keep one dated folder while the listing is still live. Privacy evidence can disappear after an app update or policy rewrite.
Put these records in it:
- The app name, developer name, store link, app version, phone model, and operating system version.
- A screenshot or saved copy of the privacy policy, including the page URL and the date you viewed it.
- The relevant App Privacy or Data safety disclosure from the store listing, if one is shown.
- Screenshots of permission prompts, settings screens, account messages, ads, or in-app statements tied to your concern.
- A brief timeline describing what happened, when it happened, and whether you gave consent.
- Any message you sent to the developer and its response.
A reviewer can follow a sequence. A long conclusion about what you think happened is harder. Write events in order even if it feels repetitive: you installed the app, it requested location access, you declined, then it displayed a message suggesting it still knew your location. That sequence is easier to check.
Don't try to obtain evidence by bypassing security, accessing someone else's account, or modifying the app. It's usually enough to begin with a normal screenshot, privacy setting, or account record.
Report the listing to Google Play or Apple
Open the app's store listing first. Store menus and available report categories can change, so use the report or flag option shown for that listing and select the closest available reason. Describe the privacy issue if no category fits.
| Store | Where to start | What to include |
|---|---|---|
| Google Play | Open the app's listing and use its report or flag option. | The policy quote, the Data safety disclosure if displayed, your evidence, and a plain explanation of the mismatch. |
| Apple App Store | Use the reporting option on the app listing or Apple's Report a Problem service if it offers a suitable option. | The app name, store link, App Privacy information, screenshots, and the conduct you observed. |
Apple's App Privacy Report is available on iPhone or iPad running iOS or iPadOS 15.2 or later. It can show recent access to sensitive data such as location, camera, and microphone, plus domains contacted by apps. It can support a report. It does not, by itself, prove what information was sent to a domain or why.
Product pages on the App Store can show data types an app may collect, whether data may be linked to you, and whether it may be used for tracking. See Apple's explanation of App Store privacy information. Compare that information with the policy and your evidence.
Google says apps intended to abuse or misuse personal data, networks, or devices are prohibited on Google Play. Its Google Play safety guidance is useful context, but a user report is still a request for review, not proof that Google will remove an app. Don't rely on a promised response time.
Save any confirmation number, but secure your account without waiting for a reply.
Copy and adapt this privacy complaint template
A factual report works better than an accusation packed with legal terms, so name the statement you saw, describe the conduct, and attach only the evidence needed to check it. Write it in plain words.
Subject: Request to review privacy disclosure for [App name]
App and developer: [App name], [developer name]
Store link: [Google Play or App Store link]
App version and device: [version], [phone model], [operating system]
Privacy statement or store disclosure: On [date], the app's privacy policy or store disclosure stated: "[short exact quote]"
What I observed: On [date and time], I observed [specific event, permission request, message, setting, or other behavior]. This appears inconsistent with the statement above because [brief explanation].
Evidence attached: [screenshots, policy copy, App Privacy Report entry, correspondence, or other records]
Requested action: Please review whether this app's current behavior and privacy disclosures comply with your applicable policies. Please preserve this report and provide any available reference number.
Contact information: [email address, if you want a response]
Avoid sending passwords, full account numbers, government ID images, or unredacted medical records. To be honest, a short report with labeled screenshots is often more useful than a huge attachment dump.
Ask the developer for an answer
The store report and a direct request serve different purposes. Use the privacy contact listed in the app's policy whenever possible.
A developer may explain a setting, correct a misleading disclosure, or process a privacy request. Its response can also become useful evidence if it contradicts the published policy.
Keep this message separate from your store report if you are also asking to access, delete, correct, or opt out of certain uses of your data. Send that request on its own.
You could write:
I use [App name] and am requesting information about my personal data. Please explain what data associated with my account has been collected, the purposes for which it is used, and the categories of third parties with which it has been shared. I also request [access, deletion, correction, or an opt-out, as applicable]. My account identifier is [email or username].
The California Attorney General's CCPA guidance explains rights involving personal information, including choices that may apply to access, deletion, correction, and certain sharing. If you're a California resident, say so in the request.
Not every app company is subject to the CCPA or CPRA. A company may also need to verify that you control the account before acting on a request.
Escalate a U.S. complaint to the right agency
| Situation | Practical complaint route | What that route can do |
|---|---|---|
| The app's privacy claims seem false, misleading, or unfair to U.S. consumers | File through the FTC ReportFraud site | Gives the FTC information that may help identify patterns or support enforcement work. It is not a personal account-support service. |
| You are a California resident and believe a business subject to California privacy law ignored your request or privacy rights | Use the California Privacy Protection Agency complaint form | Lets you report a possible CCPA or CPRA issue. Include your request to the business and any response. |
| You are in the EU or EEA and believe the processing falls under GDPR | Contact your national data protection authority. The European Data Protection Board lists member authorities. | A data protection authority can review a GDPR complaint under its own procedures. |
A complaint to Apple or Google asks a platform to apply its own rules. A complaint to a public agency is different. Thing is, GDPR, CCPA, and FTC rules are not interchangeable labels to paste into every report.
The FTC route may fit when an app said it would not share location data, for example, but your evidence suggests a different practice. Explain the promise, the conduct, and the consumer impact. Don't claim a specific law was violated unless you know why it applies.
A U.S. consumer does not automatically gain a GDPR complaint simply because an app is global. GDPR issues should stay separate from U.S. FTC and California routes.
Understand what your evidence can show
"The policy said no location sharing on March 8, but the app requested location after I declined and the disclosure did not mention it" is stronger than "this app steals data." Reviewers can often act faster on a narrow claim.
| Evidence | What it can support | What it cannot prove alone |
|---|---|---|
| A dated privacy policy screenshot | What the developer said at that time | That the app actually collected or transferred data |
| An App Store privacy label or Google Play Data safety disclosure | The data practices disclosed on the listing | That every current app version behaves exactly as described |
| An App Privacy Report entry | Recent sensor access and network domains contacted | The contents of data sent to a domain |
| A phone permission screen | That the app requested or was granted a device permission | That the developer sold, shared, or retained the data |
| A developer's written reply | The developer's explanation or position | That the explanation is complete or accurate |
A privacy concern can be real even when the technical evidence is incomplete. Be precise about what each record proves.
Protect your account after reporting
Save the evidence first. Limit the app's access through your phone's permission settings, sign out if appropriate, and remove the app if you no longer trust it.
If you used a password that you also use elsewhere, change it, and if that same password sits on an email, social-media, financial, or cloud account the app could reach, review those connected-account settings and change the password there too.
Revoking a permission stops future access through that permission. It does not itself ask the developer to delete data it may already hold. Send a separate deletion request if that is what you want.
Contact the affected bank, card issuer, or account provider immediately if you see unauthorized charges, account takeovers, or identity misuse. A privacy complaint does not replace a fraud report.
Turns out the file you make today still matters if the policy page is gone tomorrow. Put the policy quote, the store link, the date, and a screenshot in one place. Submit the store report next. Then use the FTC or California route if the facts fit. You'll want that folder either way.