# Google Play (Issue found: Invalid Data safety section)

**URL:** <https://forum.defold.com/t/google-play-issue-found-invalid-data-safety-section/71172>\
**Category:** Bugs\
**Created:** [June 27, 2022, 6:55pm UTC](https://forum.defold.com/t/google-play-issue-found-invalid-data-safety-section/71172 "2022-06-27T18:55:49Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![d954mas](https://forum-defold.b-cdn.net/user_avatar/forum.defold.com/d954mas/32/5401_2.png) [@d954mas](https://forum.defold.com/u/d954mas)\
**Post date:** [June 27, 2022, 6:55pm UTC](https://forum.defold.com/t/google-play-issue-found-invalid-data-safety-section/71172/1 "2022-06-27T18:55:49Z")

</div>

I’m updating my app in Play Market. And get warning from google  
`SPLIT_BUNDLE 1: Policy Declaration - Data Safety Section: Device Or Other IDs Data Type - Device Or Other IDs (some common examples may include Advertising ID, Android ID, IMEI, BSSID)`

I do not collect anything, there are no analysts.

1)Defold 1.3.3  
2)permissions

```lua
<uses-permission android:name="android.permission.WAKE_LOCK" />

```

3)Dependencies

```lua
dependencies#0 = https://github.com/AGulev/jstodef/archive/1.3.0.zip
dependencies#1 = https://github.com/DanEngelbrecht/LuaScriptInstance/archive/master.zip
dependencies#2 = https://github.com/d954mas/defold-box2d/archive/refs/tags/0.9.2.zip

```

 ![2022-06-27_15-12-19](https://forum-defold.b-cdn.net/uploads/default/original/3X/c/7/c717b1c78c0f025acd07ec6a21bd90bcb793de55.png)

---

<div class="post-metadata">

**Author:** ![d954mas](https://forum-defold.b-cdn.net/user_avatar/forum.defold.com/d954mas/32/5401_2.png) [@d954mas](https://forum.defold.com/u/d954mas)\
**Post date:** [June 27, 2022, 6:58pm UTC](https://forum.defold.com/t/google-play-issue-found-invalid-data-safety-section/71172/2 "2022-06-27T18:58:29Z")

</div>

I have no ideas, how google detect it.  
I upload my game to “Open testing” and after review(1-2 hours) get email from google.

---

<div class="post-metadata">

**Author:** ![d954mas](https://forum-defold.b-cdn.net/user_avatar/forum.defold.com/d954mas/32/5401_2.png) [@d954mas](https://forum.defold.com/u/d954mas)\
**Post date:** [June 27, 2022, 7:01pm UTC](https://forum.defold.com/t/google-play-issue-found-invalid-data-safety-section/71172/3 "2022-06-27T19:01:13Z")

</div>

Maybe it something with android\_id?  
Defold always try to get it

> <https://github.com/defold/defold/blob/6b03d6f75afb1411f62d96850cd8d94b1971916e/engine/dlib/src/dlib/sys.cpp#L754>

---

<div class="post-metadata">

**Author:** ![britzl](https://forum-defold.b-cdn.net/user_avatar/forum.defold.com/britzl/32/23_2.png) [@britzl](https://forum.defold.com/u/britzl)\
**Post date:** [June 28, 2022, 5:54am UTC](https://forum.defold.com/t/google-play-issue-found-invalid-data-safety-section/71172/4 "2022-06-28T05:54:59Z")

</div>

I haven’t heard of this before and I’m not entirely sure of its meaning.

“We detected user data transmitted off device that you have not disclosed in your app’s Data safety section as data user collected.”

The three extensions you have do not transmit any data and Defold itself surely does not. It is true that we get the device id to populate one of the sys.get\_sys\_info() fields, but the data is not transmitted anywhere…

You should be able to complete/update the Data safety form for your app to get rid of the warning though:

> <https://stackoverflow.com/questions/71199143/action-required-your-app-is-not-compliant-with-google-play-policies-what-is-t/71234298#71234298>

---

<div class="post-metadata">

**Author:** ![d954mas](https://forum-defold.b-cdn.net/user_avatar/forum.defold.com/d954mas/32/5401_2.png) [@d954mas](https://forum.defold.com/u/d954mas)\
**Post date:** [June 28, 2022, 6:40am UTC](https://forum.defold.com/t/google-play-issue-found-invalid-data-safety-section/71172/5 "2022-06-28T06:40:29Z")

</div>

Yes I can complete data safety and set that I collected android\_id.

But it is strange behavior. I do not collected anything(

---

<div class="post-metadata">

**Author:** ![Mathias\_Westerdahl](https://forum-defold.b-cdn.net/user_avatar/forum.defold.com/mathias_westerdahl/32/228_2.png) [@Mathias\_Westerdahl](https://forum.defold.com/u/Mathias_Westerdahl)\
**Post date:** [June 28, 2022, 6:50am UTC](https://forum.defold.com/t/google-play-issue-found-invalid-data-safety-section/71172/6 "2022-06-28T06:50:18Z")

</div>

> [@britzl](#):
>
> We detected user data transmitted off device that you have not disclosed in your app’s Data safety section as data user collected.

It would be great if they mentioned _which_ data, and also _how_ they detected that.  
In theory you could collect a lot of data and encrypt it and send it over http, and how would they know?  
Is it perhaps the fact that the android id was collected at all?

---

<div class="post-metadata">

**Author:** ![d954mas](https://forum-defold.b-cdn.net/user_avatar/forum.defold.com/d954mas/32/5401_2.png) [@d954mas](https://forum.defold.com/u/d954mas)\
**Post date:** [June 28, 2022, 6:55am UTC](https://forum.defold.com/t/google-play-issue-found-invalid-data-safety-section/71172/7 "2022-06-28T06:55:34Z")

</div>

Yes, but that all information that i get(  
It is some id

> [@d954mas](#):
>
> Device Or Other IDs Data Type - Device Or Other IDs (some common examples may include Advertising ID, Android ID, IMEI, BSSID)

---

<div class="post-metadata">

**Author:** ![d954mas](https://forum-defold.b-cdn.net/user_avatar/forum.defold.com/d954mas/32/5401_2.png) [@d954mas](https://forum.defold.com/u/d954mas)\
**Post date:** [June 28, 2022, 6:59am UTC](https://forum.defold.com/t/google-play-issue-found-invalid-data-safety-section/71172/8 "2022-06-28T06:59:26Z")

</div>

> **[Declare your app's data use  |  Privacy  |  Android Developers](https://developer.android.com/privacy-and-security/declare-data-use)**
>
> This document provides guidance and examples for Android developers on how to accurately declare their app's data collection and sharing practices in Google Play's Data safety form.

---

<div class="post-metadata">

**Author:** ![britzl](https://forum-defold.b-cdn.net/user_avatar/forum.defold.com/britzl/32/23_2.png) [@britzl](https://forum.defold.com/u/britzl)\
**Post date:** [June 28, 2022, 8:43am UTC](https://forum.defold.com/t/google-play-issue-found-invalid-data-safety-section/71172/9 "2022-06-28T08:43:58Z")

</div>

> [@Mathias\_Westerdahl](#):
>
> Is it perhaps the fact that the android id was collected at all?

It probably is. I don’t think Google will know what happens with the value after it is retrieved. I think they only check if we have code to get it or not.

---

<div class="post-metadata">

**Author:** ![AGulev](https://forum-defold.b-cdn.net/user_avatar/forum.defold.com/agulev/32/4541_2.png) [@AGulev](https://forum.defold.com/u/AGulev)\
**Post date:** [June 28, 2022, 8:46am UTC](https://forum.defold.com/t/google-play-issue-found-invalid-data-safety-section/71172/10 "2022-06-28T08:46:18Z")

</div>

Maybe then this method should be in a separate extension as we did before with advertisement info?

---

<div class="post-metadata">

**Author:** ![Mathias\_Westerdahl](https://forum-defold.b-cdn.net/user_avatar/forum.defold.com/mathias_westerdahl/32/228_2.png) [@Mathias\_Westerdahl](https://forum.defold.com/u/Mathias_Westerdahl)\
**Post date:** [June 28, 2022, 9:14am UTC](https://forum.defold.com/t/google-play-issue-found-invalid-data-safety-section/71172/11 "2022-06-28T09:14:29Z")

</div>

If so, I think it perhaps should.

---

<div class="post-metadata">

**Author:** ![d954mas](https://forum-defold.b-cdn.net/user_avatar/forum.defold.com/d954mas/32/5401_2.png) [@d954mas](https://forum.defold.com/u/d954mas)\
**Post date:** [June 30, 2022, 12:43pm UTC](https://forum.defold.com/t/google-play-issue-found-invalid-data-safety-section/71172/12 "2022-06-30T12:43:40Z")

</div>

For now, i fill in data safety policy that device\_id is collected.  
It solved a problem.

But if you try to fix that issue it will be cool:)

---

<div class="post-metadata">

**Author:** ![britzl](https://forum-defold.b-cdn.net/user_avatar/forum.defold.com/britzl/32/23_2.png) [@britzl](https://forum.defold.com/u/britzl)\
**Post date:** [June 30, 2022, 1:12pm UTC](https://forum.defold.com/t/google-play-issue-found-invalid-data-safety-section/71172/13 "2022-06-30T13:12:20Z")

</div>

> [@AGulev](#):
>
> Maybe then this method should be in a separate extension as we did before with advertisement info?

> [@Mathias\_Westerdahl](#):
>
> If so, I think it perhaps should.

I’m concerned that this is a breaking change. If we decide to move it to an extension then maybe we should still keep the `device_id` field around in `sys.get_sys_info()` and replace it with an UUID generated from a MAC address (and maybe emit a warning or something).

> [@d954mas](#):
>
> But if you try to fix that issue it will be cool:

Could you please create a ticket on GitHub?

---

<div class="post-metadata">

**Author:** ![d954mas](https://forum-defold.b-cdn.net/user_avatar/forum.defold.com/d954mas/32/5401_2.png) [@d954mas](https://forum.defold.com/u/d954mas)\
**Post date:** [June 30, 2022, 8:05pm UTC](https://forum.defold.com/t/google-play-issue-found-invalid-data-safety-section/71172/14 "2022-06-30T20:05:30Z")

</div>

[https://github.com/defold/defold/issues/6764](https://github.com/defold/defold/issues/6764)
