Publishing a Game on the App Store and Google Play: Legal Requirements Privacy, EULAs, payments, user accounts, children, and intellectual property in mobile games

Legal requirements for publishing a mobile game on the Apple App Store and Google Play, including privacy, EULA, payments, accounts and intellectual property.1. Legal Issues When Publishing a Mobile Game

Publishing a mobile game on Apple’s App Store or Google Play involves more than meeting the technical requirements of the platform and submitting the game for review. Before launch, developers and publishers should also address a range of legal issues. Some arise from the rules imposed by Apple and Google, while others come from the laws of the countries in which the game will be made available.

Apple sets out its main requirements in the App Store Review Guidelines, while Google publishes the rules applicable to apps and games in its Google Play Developer Program Policies. These rules cover areas such as privacy, payments, advertising, content, children, user accounts, and user-generated content.

The scope of the legal review depends on how the game operates. A simple game that does not require an account, display advertising, or offer in-app purchases will generally raise fewer issues than a game that collects player data, uses analytics or advertising services, sells virtual currency or digital items, includes chat between players, or is intended for children.

Before launch, the developer should therefore have a clear picture of what information the game collects, which third-party services are integrated into it, how the game generates revenue, and who its target audience is. These details help determine which legal documents are required and whether the game itself needs to be adjusted before submission.

For example, a game that collects user data will usually need a privacy policy that reflects its actual data practices. A game with user accounts, purchases, or social features may require detailed Terms of Use. If the game offers virtual currency, subscriptions, or loot boxes, the payment rules of Apple and Google also need to be considered. Where children form part of the target audience, additional rules may apply to privacy, advertising, and data collection.

The developer should also confirm that it has the necessary rights in the game itself. The name of the game, logo, characters, graphics, music, code, and third-party assets may all be protected by copyright, trademarks, or other intellectual property rights. For further information, see our article on intellectual property protection for computer games.

Approval by Apple or Google does not mean that the game complies with all applicable laws. The stores review games according to their own policies, but responsibility for compliance with privacy law, consumer protection law, copyright law, trademark law, and other applicable laws remains with the developer or publisher.

For that reason, legal review should preferably take place before the game is submitted. Some issues can be dealt with through properly drafted legal documents. Others may require changes to the interface or code, such as adding an account-deletion mechanism, changing the payment flow, or obtaining consent before tracking a user.

2. Privacy, Data Collection and User Tracking

Even a game that does not ask a player to provide a name, address, or telephone number may collect personal or technical information. IP addresses, device identifiers, gameplay data, purchase history, crash data, advertising information, and analytics data are only some of the information that may be processed through a mobile game.

Before drafting the privacy policy, the developer should map the flow of data through the game. This means identifying what data is collected, who collects it, why it is collected, where it is sent, whether it is shared with third parties, and how long it is retained.

Privacy Policy

The privacy policy should describe what the game actually does. A generic policy copied from another website or application may not match the game’s real data practices.

The policy should clearly explain what information is collected from players, why it is used, with whom it may be shared, and how users can contact the game operator about privacy matters. Depending on the type of game and the applicable law, the policy may also need to address data retention, deletion, and the rights users have in relation to their personal information.

Simply mentioning a form of data collection in the privacy policy does not necessarily make that collection permissible. In some cases, the law or the platform rules require a separate notice, user consent, or a system permission before certain information can be accessed or used.

SDKs and Third-Party Services

A point that is often overlooked is that a significant amount of data collection may take place through third-party services rather than through code written by the developer.

Mobile games commonly use SDKs for advertising, analytics, campaign measurement, crash reporting, account login, and other services.

For example, an advertising SDK may receive a device identifier and usage data even if that information is never sent directly to the game developer’s own servers. From Apple’s and Google’s perspective, the use of an external service does not remove the developer’s responsibility.

Google explains in its SDK requirements that developers are responsible for ensuring that the code and services integrated into their apps comply with Google Play policies. Apple takes a similar approach in its User Privacy and Data Use guidance.

A legal review should therefore include a list of the SDKs and external services used by the game, together with an assessment of what information each service collects and how that information is used.

Apple App Privacy

In addition to a privacy policy, Apple requires developers to provide information through App Store Connect about their data collection and use practices. This information appears on the game’s App Store page under App Privacy.

Under Apple App Privacy, developers must disclose the categories of data collected, the purposes for which the data is used, whether the data is linked to the user’s identity, and whether it is used for tracking. Data collected through third-party SDKs may also need to be disclosed.

Three things therefore need to match: what the game actually does, what the privacy policy says, and what the developer has disclosed to Apple.

Google Play Data Safety

Google uses a similar system called Data Safety. Through Google Play Console, developers are required to provide information about data collection, data sharing, and the purposes for which the data is used.

The disclosure must also take into account data collected through third-party libraries and SDKs. The official requirements are set out in the Google Play Data Safety guidance.

The answers submitted to Apple should not simply be copied into Google Play. The two platforms use different definitions and categories, so each disclosure should be reviewed separately.

Apple App Tracking Transparency

One significant difference between the two platforms is Apple’s App Tracking Transparency, or ATT.

ATT applies in certain situations where information collected about a user or device is linked with information from other companies’ apps, websites, or other sources for purposes such as targeted advertising or advertising measurement. Where ATT applies, the user’s permission generally needs to be obtained through Apple’s system prompt before tracking begins.

This is particularly relevant to games that rely on advertising or use advertising and attribution services. Even if the developer does not itself carry out the tracking, the activities of an SDK integrated into the game may trigger ATT requirements.

Apple also prohibits developers from circumventing a user’s refusal by using alternative identifiers or techniques such as fingerprinting. More information is available in Apple’s App Tracking Transparency documentation.

Google Play does not have an identical ATT mechanism, but it applies its own rules relating to personal data, advertising identifiers, permissions, consent, and SDK use.

3. Terms of Use and EULA

Alongside the privacy policy, developers should consider how the legal relationship between the game operator and the player will be governed. The two main documents used for this purpose are Terms of Use and an End User License Agreement, commonly referred to as a EULA.

A EULA mainly deals with the licence granted to the user to use the software. It generally makes clear that the player does not acquire ownership of the game or its code, but receives a limited licence to use the game subject to the agreed terms. It may cover matters such as copying, modification, reverse engineering, commercial use, and intellectual property rights in the software.

Terms of Use are broader. In a game that includes user accounts, multiplayer functionality, purchases, or interaction between players, the terms may regulate account creation and use, cheating, bots, suspension or termination of accounts, purchases, virtual currency, user-generated content, and other aspects of player conduct.

Not every game needs two separate documents. In some cases, the relevant terms can be combined into a single agreement. The main question is whether the terms properly reflect how the game operates and the risks associated with it.

Apple provides a default arrangement. If the developer does not provide its own EULA, Apple’s Standard EULA applies. A developer that wants tailored terms can submit a Custom EULA through App Store Connect and specify the countries in which it will apply. Apple explains the process in its Custom License Agreement guidance.

Google Play uses a different structure. There is no standard EULA that applies to every game in the same way as Apple’s Standard EULA. Google’s distribution agreement provides a basic licence framework, and the developer may adopt its own EULA or Terms of Use, subject to the Google Play Developer Distribution Agreement.

For a commercial game that includes accounts, purchases, virtual currency, multiplayer features, or user-generated content, the relevant question is not simply whether the store provides a default licence. The developer should consider whether the contractual terms actually give the game operator the protections and enforcement tools it needs.

4. Payments, Virtual Currency and Loot Boxes

Many mobile games are free to download and generate revenue through purchases made inside the game. Coins, gems, skins, characters, extra lives, battle passes, and subscriptions are common examples of digital products that are specifically addressed by the platform rules.

Under Apple’s general rule, the sale of digital content or functionality within an app must usually be processed through Apple In-App Purchase. Google Play applies a similar principle through Google Play Billing. The applicable rules and exceptions are set out in the App Store Review Guidelines and the Google Play Payments Policy.

Where a game includes virtual currency, the review should cover not only how the player pays for it, but also what rights the player receives. Depending on the game, the Terms of Use may need to address whether currency or virtual items can be transferred between users, whether they can be redeemed for real money, what happens when an account is closed, and what changes the operator may make to the game’s virtual economy.

The stores also impose specific rules. Apple provides, among other things, that credits or in-game currencies purchased through In-App Purchase may not expire. Google provides that virtual currency purchased within an app must be used within the app or game title for which it was purchased.

Loot boxes require separate attention. Where a player pays for the chance to receive a random virtual item, Apple and Google require the odds of obtaining the different types of items to be disclosed in advance.

If loot boxes form a significant part of the game’s business model, local law should also be reviewed. In some countries, these mechanics may raise issues under gambling law, consumer protection law, or laws protecting minors.

Payment rules can also vary between countries. Apple and Google now operate different exceptions and programmes relating to external payments and alternative billing. A game intended for international distribution should therefore review the rules that apply in its target markets rather than assume that a single payment rule applies worldwide.

5. Children, User Accounts and User-Generated Content

A game that includes user accounts, a young audience, chat, or multiplayer functionality raises additional questions about how users are identified, what information is stored about them, and how they are able to interact with each other.

If the game is directed at children, or if children form part of its target audience, stricter privacy and advertising rules may apply. Apple operates a Kids Category and imposes special requirements relating to advertising, analytics, purchases, and external links. Google operates its Families Policies and requires developers to identify the game’s target audience and adjust data collection, advertising, and SDK use accordingly.

An age rating and a target audience are not the same thing. A game may have an age rating that allows minors to play without being a game directed at children. Conversely, if the design, content, and marketing of the game are aimed at children in practice, simply declaring an older target audience may not resolve the issue.

User Accounts and Account Deletion

Where users can create accounts, the deletion process should be planned in advance.

Apple requires apps that allow account creation to allow users to initiate account deletion from within the app. Google requires an in-app deletion option and an external route, such as a webpage, so that a user can request deletion even after uninstalling the game. Google explains these requirements in its Account Deletion Requirements.

Account deletion does not always mean that every piece of information must be deleted immediately. Certain records may need to be retained for accounting, security, fraud prevention, or legal reasons. Where information is retained, the operator should define what is kept, why it is kept, and for how long, and make sure the privacy policy is consistent with that practice.

Social Login

Apple also has specific rules for third-party login services such as Google or Facebook where they are used for the user’s primary account. In certain cases, Apple requires an alternative login option that meets its privacy requirements. In practice, this will often mean offering Sign in with Apple.

Google Play does not impose a general equivalent requirement to offer Google Sign-In merely because another login provider is available.

Chat and User-Generated Content

Where players can use text or voice chat, choose usernames, create clans, upload images, build levels, or publish other content, the game may be treated as containing User-Generated Content.

Apple requires appropriate mechanisms for dealing with objectionable content, reporting content, blocking users, and contacting the service operator. Google likewise requires moderation, reporting and blocking tools, together with terms that explain which types of content and behaviour are prohibited.

A clause in the Terms of Use that simply prohibits harassment or offensive content will not usually be enough. If the game allows users to communicate or publish content, the game should also provide practical tools for enforcing those rules.

6. Intellectual Property and Content Rules

Before launch, the developer or publisher should confirm that it has the necessary rights in all elements used in the game.

The review starts with the game’s name and logo. Before investing in branding and launch activities, it is sensible to check whether earlier trademarks may create a conflict. For a game with meaningful commercial potential, trademark registration should also be considered in the main markets in which the game is expected to operate.

The same applies to characters, graphics, animation, music, sound effects, videos, photographs, and fonts. Even where an asset has been lawfully purchased, the licence terms should be reviewed to make sure they permit the intended use in a commercial game.

Code should also be reviewed. Games commonly use open-source libraries, plugins, APIs, and assets purchased through Unity Asset Store, Unreal Marketplace, and other sources. Each component may be subject to different licence terms, and some licences may require attribution or the inclusion of specific notices.

Apple prohibits unauthorised use of copyrighted works, trademarks, and third-party content under the App Store Review Guidelines. Google applies a similar policy under the Google Play Intellectual Property Policy.

Use of AI

Where AI tools are used to create graphics, music, voices, text, or other game content, the terms of the relevant service should be reviewed to determine what rights are granted in the output.

The developer should also consider what material was uploaded to the AI system, whether there was a right to use that material, and whether the resulting output may infringe third-party rights.

If the game itself allows users to generate content through generative AI, additional issues arise in relation to moderation, privacy, prohibited content, and responsibility for generated outputs.

Age Ratings and Restricted Content

The content of the game also needs to be reviewed. Violence, sexual content, drugs, gambling, simulated gambling, and strong language may affect the game’s age rating and, in some cases, whether the game can be distributed at all.

Apple assigns an Age Rating through App Store Connect. Google Play uses a content-rating system based on IARC. Developers should answer the relevant questionnaires accurately and update them when significant changes are made to the game.

A game involving real-money gambling is subject to a much more heavily regulated framework. Licensing requirements, territorial restrictions, and other local rules may apply. Approval by the store does not replace a review of gambling laws in the countries where the game will be offered.

7. Key Differences Between Apple and Google Play and What to Check Before Launch

Apple and Google regulate many of the same issues, but their systems are not identical.

Apple provides a Standard EULA that applies by default unless the developer submits a Custom EULA. Google uses a different contractual structure, under which the developer may adopt its own terms alongside the agreements that apply through Google Play.

Privacy disclosures are also handled differently. Apple uses App Privacy, while Google uses Data Safety. Both are intended to tell users what information is collected and how it is used, but the categories and forms are different.

For tracking, Apple uses ATT, which has no identical equivalent in Google Play. For payments, Apple uses In-App Purchase and Google uses Google Play Billing. For user accounts, Apple requires an in-app mechanism to initiate account deletion, while Google also requires an external deletion route.

Before submitting a game to either store, the developer should review the game from the user’s perspective from beginning to end. This includes identifying the legal entity publishing the game and the countries in which it will be offered, understanding what information is collected and which SDKs operate in the background, determining whether advertising or tracking is used, and making sure that the privacy policy and store disclosures accurately reflect the game’s actual practices.

The developer should also decide whether tailored Terms of Use or a EULA are needed, whether the game includes user accounts or social login, whether children form part of the target audience, and whether the game includes chat, multiplayer features, or user-generated content.

Where the game includes purchases, the payment method and the rules governing subscriptions, virtual currency, and loot boxes should be reviewed. At the same time, the developer should confirm that it owns or has licensed the rights needed for the game’s name, logo, characters, music, graphics, code, and other assets, and that the game’s age rating and content disclosures are accurate.

This review is best completed before submission. Some deficiencies can be corrected through legal documents, but others require changes to the game itself. A missing account-deletion mechanism, inadequate user-reporting tools, tracking that does not comply with Apple’s rules, or an incorrect payment flow may require additional development work and delay launch.

Apple’s and Google’s policies change from time to time, and some requirements differ between countries. Before launching a new game or making a substantial change to an existing one, the current platform rules and the laws applicable in the target markets should be reviewed.

An early legal review can identify issues before submission and help ensure that the privacy policy, Terms of Use, payment mechanisms, and intellectual property arrangements are appropriate for the specific game. Where a game involves significant data collection, children, purchases, user-generated content, or distribution in multiple jurisdictions, specific legal advice before launch may be advisable.

Have a question about the article?

You might also be interested in