Privacy notice for a mobile app
A privacy notice for an iOS or Android app, drafted for the developer with the in-app tracking notice and consent guidance, for a fixed fee of £595 in five working days.
Privacy notice for a mobile app
Buy now, £595An app collects data a website never sees: the device identifier, the location, the contacts, the camera roll, the usage patterns the analytics kit reports and whatever the third-party software inside the app sends home. The privacy notice has to describe each of those, explain which permission unlocks which data and why the app asks for it, deal with the software development kits that are in the app whether the developer thinks about them or not, satisfy the app stores' own disclosure requirements, and handle children if they might use it. I draft the privacy notice and the cookie notice for the business, with guidance on the consent mechanism, for a fixed fee of £595, delivered in five working days.
Who this is for
Developers and publishers in England and Wales of consumer or business apps on the Apple and Google stores, from a first release to an app whose notice was written for a previous version.
What matters in a mobile app privacy notice
What an app collects that a website does not
As controller, the business must under Article 13 of the UK GDPR tell users what it collects, and an app collects device identifiers, operating system and app version, crash and performance data, usage events, push notification tokens, and whatever the permissions unlock, as well as the account and content data the user enters; the notice should list the categories in the app's own terms, the purpose and lawful basis for each (the contract under Article 6(1)(b) for the service, legitimate interests under Article 6(1)(f) for security and improvement, consent for anything optional), and should be written for the screen it will be read on, with a short in-app version linking to the full notice.
Device permissions and the data each one unlocks
Location, camera, microphone, contacts, photos, calendar, health and motion data, Bluetooth and notifications are each a permission the operating system asks the user to grant, and the notice should explain for each permission the app requests what data it gives access to, why the app needs it, whether the app works without it, and whether the data leaves the device; location in particular should be described precisely (precise or approximate, in the foreground or in the background, stored or used in the moment), because background location collection is the practice the regulator and the stores scrutinise most, and health and biometric data are special category data under Article 9 of the UK GDPR needing explicit consent or another condition.
Software development kits, analytics and the trackers inside the app
Most apps contain third-party software development kits for analytics, crash reporting, advertising, attribution and social login, each of which collects data and sends it to the kit's provider, and the notice should name the categories of provider (or the providers), what they receive, whether they act as the developer's processor or as controllers for their own purposes (advertising networks usually do), and the user's choices; the storage of and access to information on the device by those kits falls within regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003, which requires consent before non-essential cookies and similar technologies are placed, so that in-app analytics and advertising trackers need a consent mechanism on first launch in the same way a website needs a banner, and the pack includes the guidance for it.
The app stores, their privacy labels and the notice they expect
Apple and Google require a privacy policy link in the store listing and in the app, require the developer to complete a data disclosure (the privacy nutrition label and the data safety section) describing the data collected, linked to the user and used for tracking, and reject or remove apps whose disclosures contradict their behaviour; the notice should match the disclosures the developer makes to the stores, should be hosted at a stable address, and should be updated when the data collection changes, because an app whose notice says one thing and whose store label says another has a problem with the store before it has one with the regulator.
Children, age and the design code
If children are likely to use the app, the Information Commissioner's age appropriate design code under section 123 of the Data Protection Act 2018 applies with its standards on default settings, data minimisation, profiling, nudge techniques and transparency in language children understand, and consent for an information society service offered directly to a child is valid only from the age of thirteen under section 9 of the Data Protection Act 2018, below which a parent's consent is needed; the notice should say whether the app is intended for children, what age assurance the app uses, and how parents exercise rights, and an app not intended for children should say so and should not collect data that suggests otherwise.
Accounts, deletion and the data that outlives the app
The notice should state what happens when the user deletes the app (local data goes, server data does not), how the user deletes their account and the data with it (which the stores now require to be available in the app), the retention periods for account, content, usage and support data, the position on backups, the international transfers to the kit providers and the hosting under the safeguards Article 46 of the UK GDPR requires, and each right the individual can exercise (access, correction, erasure, restriction, portability, objection), how, within what time (a month), and the right to complain to the Information Commissioner's Office; the notice can record the business's registration with the Information Commissioner's Office under the Data Protection (Charges and Information) Regulations 2018.
What it costs
Website privacy and cookies pack, £595. Privacy notice, cookie notice and consent guidance. Five working days.
DPA and privacy terms, £795. Data processing agreement plus privacy notice. Five working days.
Buying online forms the engagement on payment. The scope is what the data protection agreements and privacy terms page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.
What you get
- A data processing agreement that meets the statutory requirements and can be used as a schedule to your main contract
- A privacy notice written for people to read rather than to be scrolled past
- Clear allocation of controller and processor roles, which is where most confusion starts
- International transfer provisions where you use overseas suppliers
- Sub-processor and security provisions proportionate to what you do
- A note on the operational steps the documents assume you are taking
What is not included
- Full compliance audits and data mapping exercises
- ICO registration, which you do yourself
- Breach response and regulatory correspondence
- Cyber security certification such as Cyber Essentials
- Advice on data protection law outside the UK and EU
Questions I am often asked
Do we need cookie consent in an app?
For analytics, advertising and attribution kits that store or access information on the device, yes: the same rule applies as to website cookies, so the app needs a consent mechanism on first launch. The pack includes guidance on it.
Our app uses location. What does the notice need to say?
Whether precise or approximate, foreground or background, stored or used in the moment, why the app needs it and whether it works without it. Background location is what the regulator and the stores look at hardest.
Can children use our app?
If they are likely to, the age appropriate design code applies and consent is valid only from thirteen. The notice says whether the app is for children and what age assurance it uses; an app not for children should say so.
Related guidance and services
- Data protection agreements and privacy terms, £595, the service this page describes
- Terms and conditions drafting, £995
- SaaS and technology contracts, £995
- Privacy notice for a SaaS product
- Terms of service for a mobile app
This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: October 2026. Email geoffrey@caesar.co.uk.