安卓封禁用户推荐ID咨询及Android ID合规问题求助
Hey, I get where you're coming from—dealing with Google Play's compliance warnings while trying to protect your exclusive content can be a headache. Let's break down the best compliant options for banning users and how to fix that warning:
Here are the Google-approved identifiers you should consider, ordered by reliability for your use case:
Custom User Account ID (Top Pick)
If your app already has a user registration system (email, phone number, or custom username), this is the most reliable and compliant option. Banning by account ID directly targets the offending user, not just their device—so even if they switch phones, they can't access your exclusive content with the same account. This avoids all device identifier-related compliance issues entirely since it's a user-controlled identity you manage.Firebase Installation ID (FID)
If you don't have a user account system yet, FID is Google's recommended non-permanent device identifier. It's tied to the app installation, not the device itself, and complies with Play Store policies. You can get it via the Firebase Installations SDK with a simple call:FirebaseInstallations.getInstance().getId() .addOnCompleteListener { task -> if (task.isSuccessful) { val fid = task.result // Use this FID for your ban logic } }Note: Users can reset FID by clearing app data or reinstalling, so this works best for temporary bans or as a stopgap until you implement a user account system.
Google Sign-In ID
If you offer Google Sign-In as a login option, you can use the authenticated Google user ID (fromGoogleSignInAccount.getId()) as your ban identifier. This is compliant, user-bound, and works across devices—similar to a custom account ID but leverages Google's authentication system.
To fix the Google Play warning and get your beta build approved:
Remove all Android ID usage
Stop fetching or usingSettings.Secure.ANDROID_IDanywhere in your codebase. This is the root cause of your warning, as Android ID is considered a sensitive device identifier that doesn't meet Play Store's data privacy requirements for most use cases.Implement your chosen identifier
Integrate the identifier you picked (custom account ID, FID, or Google Sign-In ID) into your ban logic. Make sure all checks for banned users use this new identifier instead of Android ID.Update your backend ban system
Modify your backend to store and check against the new compliant identifiers. If you're switching from Android ID, you can gradually phase out old ban records as users update to your new build.Resubmit with a clear note
When you upload your updated beta build to Google Play, add a note in the review comments explaining that you've replaced the non-compliant Android ID with [your chosen identifier, e.g., Firebase Installation ID or custom user account IDs] to comply with Play Store policies. This helps the review team verify your fix quickly.
- Always prioritize user-bound identifiers (account IDs) over device-bound ones—they're more effective for banning and fully compliant.
- If using FID, consider adding a prompt for users to register an account after a few uses, so you can switch to more reliable account-based banning long-term.
- Ensure you're handling all identifiers securely: encrypt stored identifiers and only transmit them over HTTPS to protect user privacy.
内容的提问来源于stack exchange,提问作者Cobra47

