Google Play asks you to describe in a Data safety form what your app collects and shares. If your Android app has a feedback component, what it sends has to be in that form. This guide walks through the questions for a Nitpick feedback component in an Expo app. It is information to help you fill in the form, not legal advice. Check the wording in the form itself before you submit, because Google changes it.
Collected and shared
For Google, collecting means transmitting data off the device, including data sent by libraries and SDKs in your app. Sharing means giving data to a third party. A service provider that processes data on your behalf does not count as a third party. Data that is only processed in memory for as long as it takes to answer a request is also exempt.
A feedback component sends the report to a server that stores it, so it is collection. Whether the storage counts as sharing depends on whether you regard Nitpick as a service provider acting for you. That is your judgement to make with your own advice.
What the component sends
Only after the user opens the panel and presses Send, for a general comment or after pointing at something:
- The comment, and the screenshot of your app screen if the user kept it.
- The tap position and the screen and element names you marked.
- The device manufacturer and model, the Android version, the language, the app version and the build.
Feedback is anonymous: no name, email address, account id, advertising id or device name.
Suggested answers
| Question | Suggested answer |
|---|---|
| Data collected: App activity, Other user-generated content | Yes, for the comment and the screenshot |
| Data collected: App activity, App interactions | Yes, for the tap position |
| Data collected: App info and performance, Diagnostics | Yes, for model, OS version and app version, if you read them as technical diagnostics |
| Device or other IDs | No |
| Collection optional or required | Optional, the user chooses to send it |
| Shared with third parties | No, if you treat Nitpick as your service provider |
| Encrypted in transit | Yes, reports are sent over HTTPS |
| Users can ask for deletion | Yes, through you |
The Google page we read does not name a screenshot of your own app screen. Other user-generated content is our reading, so open the help text of each category in the form and pick the closest fit for your own situation. Google calls a data type optional when users can control its collection and use the app without providing it, which fits a form the user opens and sends by choice.
Deletion requests
The form asks whether your app provides a way for users to request deletion of their data. If you answer Yes, describe in your privacy policy how a user contacts you, and delete the report from your dashboard. Reports are anonymous, so Nitpick cannot find a user's reports by account. A screenshot is removed 12 months after the report was made in any case.
The in-app disclosure and the policy
Under Google's User Data policy you need a prominent disclosure in the app, shown right before collection, when users may not expect it, and a privacy policy that you link in Play Console and in the app. The form of the component, with its preview and the line "Your feedback goes to the maker of this app." under Send, is how the user sees what is sent before it is sent. Whether that satisfies a reviewer is an interpretation. The paragraph for your policy is on Privacy and store forms.
Tested on Android?
The component was checked in Expo Go on iOS. Before you publish on Android, test it on your own Android build, and fill in the form from what you see.
Keep reading
For the iOS side, read App Privacy answers for a feedback component. The Expo specifics are in the privacy manifest guide for Expo, and the install steps are in adding in-app feedback to an Expo app.