Flutter应用Google Play更新因无效数据安全表单被拒求解决方案
问题背景
Action Required: Your app is not compliant with Google Play Policies
Issue found: Invalid Data safety form
We reviewed your app’s Data safety form in Play Console and found discrepancies between it and how the app collects and shares user data. All apps are required to complete an accurate Data safety form that discloses their data collection and sharing practices - this is required even if your app does not collect any user data.We detected user data transmitted off device that you have not disclosed in your app’s Data safety form as user data collected.
Issue details
We found an issue in the following area(s):
SPLIT_BUNDLE 6: Policy Declaration - Data Safety Section: Device Or Other IDs Data Type - Device Or Other IDs (some common examples may include Advertising ID, Android ID, IMEI, BSSID)
About the Data safety section in Google Play User Data Policy
Your app must be in compliance with this policy. If your app continues to be non-compliant after August 22, 2022, your app updates will be rejected and your app may face additional enforcement actions in the future.Please make changes to align your app’s Data safety form with the app’s behavior. This can be done by either:
Updating your form in Play Console to declare the collection of Data Types noted below; or
Removing unwanted functionality and attributable code that collects this user data from your app or libraries used in your app, and when applicable to deactivate all non-compliant APKs.
To deactivate non-compliant APKS, you can create a new release and upload a compliant APK to each track containing the non-compliant APKs.
Be sure to increment the APK version code. If using staged rollout, be sure to set the release to 100% rollout.
注:应用基于Flutter构建,使用platform_device_id插件获取设备ID,用于限制用户最多在2台设备登录。
可行解决方案
方案一:更新Google Play数据安全表单(最快解决)
- 登录Google Play控制台,进入对应应用的「数据安全」板块
- 在「数据类型」选项中勾选「设备或其他ID」(对应邮件中指出的违规项)
- 补充准确的披露信息:
- 数据收集目的:用于限制用户登录设备数量(最多2台)
- 数据共享情况:若仅存储在自有服务器、未分享给第三方,选择「不共享」
- 数据保留期限:例如用户账号存续期间保留,或用户注销账号后立即删除
- 保存表单后重新提交应用更新
方案二:替换合规的设备标识方案(避免披露该数据类型)
如果不想在数据安全表单中披露原生设备ID,可改用合规方案实现登录限制:
- 移除
platform_device_id插件依赖,选择以下两种替代方案:- 自定义匿名标识:用户首次登录时生成随机UUID,存储在应用本地和服务器,以此作为设备标识(仅在应用卸载后失效,符合隐私要求)
- 依托账号体系的设备绑定:直接在用户账号下记录登录会话,通过会话有效期和数量限制实现设备登录管控,无需获取设备ID
- 修改代码逻辑,用新方案替代原设备ID的登录限制逻辑
- 确保新APK的版本号高于旧版本,上传到所有包含违规APK的发布渠道(若用分阶段发布,需设置为100%全量发布)
- 重新提交应用更新,同时确认数据安全表单中未勾选「设备或其他ID」(需确保确实不再收集该类数据)
内容的提问来源于stack exchange,提问作者MANISH

