Your app can create accounts in one afternoon and still be missing a release-critical path: letting a person ask for that account and its associated data to be deleted. Google Play and Apple both require deletion for apps that support account creation, but their implementation details differ. Google Play requires an in-app path and a separate web resource for deletion requests. Apple requires users to be able to initiate deletion inside the app; if they must finish on a website, link directly to that completion page.
Treat account deletion as part of the product flow and the store submission, not as a support email added after review. Start by checking whether your app creates accounts, then map the request from the settings screen through your database and any services that hold user data.
Check whether the requirement applies
Google Play’s policy applies when an app lets a user create an app account from within the app. Its guidance also covers an app that sends the user to an account-creation flow outside the app. If account creation appears anywhere in the experience, offering a guest mode for other features does not remove the deletion requirement.
Apple’s App Review Guideline 5.1.1(v) says apps submitted to the App Store that support account creation must let people initiate account deletion within the app. This includes automatically created accounts. A sign-in button alone does not tell you whether the app is in scope: inspect the complete journey, including onboarding, social sign-in, guest conversion, and web-based registration.
If your app truly has no account creation, document that decision and check the current store policy for your app type. Do not infer an exemption from the fact that some users can use the app without signing in.
Build the two store paths separately
For Google Play, provide an in-app deletion path and a web resource where a person can request deletion of the account and associated data. The web resource matters because a user may have uninstalled the app or lost access to it. The link should work without requiring the person to reinstall the app just to submit a request. Play also asks developers to complete deletion questions in the Data safety form in Play Console and disclose the web link there.
For Apple, put the option to initiate deletion in the app, normally in account settings or another easy-to-find place. The option must cover deletion of the account record and associated personal data; temporarily disabling an account is not the same thing. If your process requires the person to visit a website to finish, link directly to the page where they can complete deletion. Do not send them to a generic homepage and make them search for the right form.
Keep those obligations distinct in your implementation notes. The Play web resource is a place to request deletion even when the app is unavailable. Apple’s web link is needed when the person must complete deletion on a website. One well-designed page may serve both purposes, but verify that it satisfies each store’s specific purpose and that each store listing points to the right place.
Make the request understandable and finishable
A useful flow answers three questions before the user confirms: what account will be deleted, what data will be removed, and what happens next. Explain any delay, any information you must retain for a legitimate legal or security reason, and what the person should expect to see when the request is complete.
You may verify that the person making the request controls the account and ask them to confirm the decision. Apple allows reauthentication or confirmation steps, but warns against making deletion unnecessarily difficult. Avoid a maze of unrelated screens, a required phone call, or a support conversation as the normal route. Apple allows extra customer-service steps for highly regulated industries; that is a limited case, not a default design pattern.
On Google Play, the web page must load, clearly identify the app or developer as shown on the store listing, make the deletion request path easy to find, and let the person submit a request. If you use an existing privacy or data-retention page, make the deletion section prominent. If subscription cancellation or another action is required before deletion, state that clearly and provide a way to initiate the necessary support flow.
Delete the account and coordinate the data
The visible button is only the beginning. Follow the account identifier through the systems your app uses: your primary database, uploaded files, analytics or messaging providers, and any other service that stores data tied to that account. Google Play says developers relying on service providers should delete data from their own servers and request deletion from those providers too.
Design the operation so a retry does not create a second, conflicting request. Keep a minimal request record with the account reference, request time, processing status, and completion time, subject to your retention obligations. Use that record to drive a clear state such as received, processing, or completed. Do not retain a copy of the user’s deleted profile as a convenient backup of the active account.
Some records may need to be retained for legal, regulatory, security, or fraud-prevention reasons. The stores’ guidance does not erase those obligations. Identify what you must keep, limit it to what is necessary, and explain the retention in the applicable privacy information. Ask qualified counsel about legal retention requirements for the markets where your app is available; do not use a blanket “we may keep data” statement to avoid implementing deletion.
If your app uses Sign in with Apple, Apple’s guidance also calls for revoking the user’s tokens as part of account deletion. If the app sells subscriptions, explain what happens to billing: deleting an app account does not itself cancel an auto-renewing subscription billed through Apple. Make the subscription step clear before the user confirms.
Test the whole journey before submission
Run the flow with a test account from each account-creation route you support. Confirm that the settings option is discoverable, confirmation is clear, the request reaches the server, associated data is removed or queued for deletion, and the person receives a completion message. Then try again with an account that has uploaded content, a subscription, and a failed downstream deletion request.
Test the Google Play web resource in a signed-out browser and on a device without the app installed. Make sure it identifies your app, loads without an error, and allows a request to be submitted. Open the Play Console Data safety form and check that your answers match the actual in-app and web behavior.
For Apple, submit a deletion request from inside the app. If it opens a website, verify that the link lands on the exact completion page and that the person can finish there. Check that the app does not offer only account deactivation. If the app uses Sign in with Apple, verify token revocation in the deletion path as well.
Keep evidence from these tests: the account state before the request, the request identifier, the affected data systems, and the completion result. That record helps you find gaps before review and answer accurately if a store asks how deletion works. Do not describe a flow as complete until you have tested the paths your app actually offers.
Put deletion on the release checklist
Before you submit, answer these questions:
- Can a user create an account anywhere in the app or through a linked registration flow?
- Can the user initiate full account deletion from inside the app?
- Does the Google Play web resource accept a deletion request without requiring the app?
- If Apple deletion finishes on a website, does the in-app path link directly to that page?
- Do your Data safety answers and store links match the deployed behavior?
- Do your database and service providers remove the account’s associated data?
- Have you explained any lawful retention, processing delay, and subscription consequences?
- Have you tested a normal request and a request that encounters a downstream failure?
If you are preparing an Android release, account deletion is one part of a broader submission. See our app store submission checklist for an AI-built app. If this is your first Google Play release on a newer personal account, also plan the closed test and 14-day production-access step. For an update, check the separate Google Play target API requirements.
The next practical step is to open your app’s account settings and trace a real deletion request through every system that holds that user’s data. Then verify the Play web resource and the Apple in-app path against the requirements above. Do that before the submission form asks you to describe a flow your app does not yet have.
Sources
- Google Play: Understanding app account deletion requirements
- Apple App Review Guideline 5.1.1(v), “Offering account deletion in your app.”


Top comments (0)