App Store Privacy Labels in 2026: Why Apple and Google Disagree About the Same App

· 9 min read · Guide

Store privacy labels are written by the developer, not audited by Apple or Google, and the two stores ask different questions with different thresholds. That is why one short drama app can declare no data collection on Google Play while its Apple label reports tracking linked to your identity. A mismatch is a prompt to investigate, not proof of wrongdoing.

Three apps we rate highest after hands-on testing:

Advertising Disclosure

Editor's Choice — Best Overall
Best
1
DramaBox
  • Huge library — thousands of dramas, 200+ new titles every month
  • Free daily episodes + unlock more by watching ads
  • Best value for binge-watchers — subscriptions from $5.99/week
  • For: Android, iOS and Web
6,844 visited this page today
9.8
EXCELLENT
Free to download
In-app purchases available
2
ShortMax
  • 30M+ monthly viewers — one of the fastest-growing drama apps
  • Daily free episodes and generous new-user bonuses
  • Addictive revenge & alpha-romance catalog, great localization
  • For: Android, iOS and Web
9.4
EXCELLENT
Free to download
In-app purchases available
5
KalosTV
  • Best for international viewers — English, Spanish, French & more
  • Flexible player — control the story pace your way
  • Coin packs or VIP subscription that unlocks all content
  • For: Android, iOS and Web
9.0
EXCELLENT
Free to download
In-app purchases available

What a store privacy label actually is — and what it is not

When a developer submits a build, both stores make them fill in a disclosure form. Apple publishes the result as the App Privacy section of the product page. Google publishes it as the Data safety section. Neither store decompiles the app, watches its network traffic and derives the label from what it sees. The label is a declaration, and the store's role is to publish it and to enforce accuracy after the fact as a policy matter.

That is worth saying out loud, because the visual design of both labels implies otherwise. They look like nutrition panels, which people read as measured facts. They are closer to a customs declaration: structured, comparable, binding on the person who signed it, and entirely dependent on that person having understood the questions and answered them completely.

None of this makes labels useless. Within a single platform they are genuinely comparable — if you check five apps on the same store, you are comparing like with like, which is exactly the discipline behind our 2026 ranking of all 14 short drama apps. They also create a public record. A developer whose label says one thing while the app plainly does another is exposed to store enforcement and, in several jurisdictions, to consumer-protection regulators. What labels cannot do is substitute for an audit that nobody performed.

Table 1. Apple App Privacy versus Google Play Data safety — how the two systems differ
 Apple App PrivacyGoogle Play Data safety
Who fills it inThe developer, at submission, per app versionThe developer, in Play Console, per app
Verified by the store?No independent audit; accuracy enforced as a policy obligationNo independent audit; accuracy enforced as a policy obligation
Top-level categoriesData Used to Track You; Data Linked to You; Data Not Linked to YouData collected; Data shared; each mapped to declared purposes
Cross-company ad linkingAn explicit category, tied to App Tracking TransparencyNo direct equivalent; surfaces as a purpose such as advertising or marketing
Named exemptionsLimited; centred on the definition of trackingDocumented exemptions, including ephemeral processing and service-provider handling
Security statementsNot part of the labelEncryption in transit and deletion-request availability are declared fields
What a blank means"Data Not Collected" — the developer states nothing in Apple's categories is gathered"No data collected" — the developer states nothing in Google's categories is collected, subject to the exemptions
Update cadenceReviewed with each submitted versionEditable independently of a release; can drift from the shipped code

The BUMPiNT case: one app, two declarations

BUMPiNT is a Japanese short drama app published by emole. We checked both of its live listings on 3 September 2026. On the US App Store, the App Privacy section reports data used to track you and data linked to your identity. On Google Play the same day, the Data safety section declares that no data is collected and none is shared; that Play listing showed a last update of 21 August 2026.

Those two statements describe the same brand and, broadly, the same service. They are not describing the same artefact, and they are not answering the same question. This is a documented inconsistency between two self-declarations. It is not evidence of wrongdoing by emole, by Apple or by Google, and we are not alleging any. Both declarations can be literally accurate under their own platform's rules at the same time.

Table 2. BUMPiNT store declarations, both observed on live listings on 3 September 2026
FieldUS App StoreGoogle Play
Privacy declarationData used to track you; data linked to youNo data collected; no data shared
Listing freshness at checkVersion 4.15.0, displayed as updated one day earlierLast updated 21 August 2026
Age rating shown13+Rated for its own Play content category
Store rating at check3.9 from 58 ratingsSeparate Android rating pool
What we can concludeThe two forms disagree. Neither declaration is verified by its store, so the disagreement identifies a question to ask, not an answer.

One BUMPiNT reviewer on Apple reported repeated charges and difficulty removing payment information. That is one review. It is worth knowing about, and it is not evidence of prevalence — a single account of a billing problem tells you what can go wrong, not how often it does. The same discipline applies elsewhere in the category: one Vigloo reviewer alleged that coins were spent without consent, and another said a saved playlist had vanished. We report those as individual reports because that is all they are.

Why the two stores disagree, mechanically

There are four ordinary reasons a label can differ across platforms, none of which require anyone to be lying.

They describe different binaries

The iOS and Android versions of an app are separately compiled products that frequently embed different advertising, attribution and crash-reporting components. If the Android build ships without the third-party ad SDK that the iOS build includes, the honest Android declaration really is thinner. This is common in apps that monetise mainly through iOS.

The two forms define "collection" differently

Google's Data safety form carries documented exemptions. Data that is only processed ephemerally, and data handled by a service provider strictly on the developer's behalf, need not be declared as collection in the way an intuitive reading would suggest. Apple's questionnaire draws its lines in different places. Two engineers filling in both forms in good faith can land on "no" in one and "yes" in the other.

Only Apple has a "tracking" category

Apple's top-level Data Used to Track You heading exists because of App Tracking Transparency. Google's form has no field that asks the same question in the same shape; cross-company advertising activity surfaces indirectly, through the purposes attached to shared data. So a behaviour that produces a bold red heading on one store may produce a modest line item on the other.

Labels drift out of date

Apple reviews the declaration with each submitted version. Google's form can be edited on a different schedule from the code. When a label was last touched matters, which is why the update dates in the table above are part of the evidence and not decoration. If you want a broader view of how these apps compare on the things stores do measure, the full comparison table is the place to start.

What "tracking" means under Apple's definition

Apple's term is much narrower than the everyday word. Under the App Tracking Transparency framework, tracking means linking user or device data collected in this app with data collected from other companies' apps, websites or offline properties, for targeted advertising or advertising measurement — or sharing it with a data broker. If the developer does either, the label must show Data Used to Track You, and the app must ask permission through the system prompt.

Two consequences follow, and both are routinely misread.

First, plenty of collection is not tracking. An app that logs which episodes you watch, keeps that data entirely inside its own systems, and uses it to recommend more of the same is collecting a great deal about you and is not tracking you in Apple's sense. That data can still appear on the label — under Data Linked to You, which is a separate heading meaning tied to your identity, account or device rather than aggregated and anonymised.

Second, an app can be tracking without ever building a profile itself. Handing an identifier to an advertising network that does the linking is enough. This is why the heading appears on so many free apps whose developers would sincerely describe themselves as not interested in your data: the interest belongs to the SDK they installed.

What Google's Data safety form asks instead

Google asks a different set of questions. Roughly: which of these data types does your app collect; which does it share with third parties; for what purpose in each case; is the data encrypted in transit; and can users request deletion. There is also a separate line for whether the app has undergone an independent security review, which is a distinct claim from the collection declaration.

The structure is purpose-led rather than tracking-led. That makes it good at a question Apple's label handles poorly — what is this for? — and weaker at the one Apple foregrounds. A Play listing can show a substantial collection list with sensible-sounding purposes and give you no clean way to tell whether an advertising identifier is being joined with data from elsewhere.

"No data collected" is therefore a real statement with a specific meaning, and not a synonym for "this app is private". It means the developer answered no to Google's categories, as Google defines them, with Google's exemptions available. It is a good sign. It is not a guarantee, and it is not comparable to a blank Apple label.

How to read a label in 60 seconds

You do not need to become a privacy analyst. You need a repeatable sequence, and it takes about a minute. This is the same routine we run for every app in our app scorecards.

Table 3. A 60-second privacy label check, in order
#StepWhat you are looking for
1Open both store listings, even if you only use oneWhether the two declarations agree. Disagreement is your signal to slow down.
2On Apple, read the three headings top to bottomData Used to Track You first. Then what sits under Linked to You versus Not Linked to You.
3On Play, expand "See details"The split between collected and shared, and the purpose given for each data type.
4Check the two security fields on PlayEncrypted in transit, and whether deletion can be requested. Absence of either is informative.
5Compare the label date with the app's last updateA label far older than the current build is describing software you are not installing.
6Look specifically for purchase and financial dataIf you intend to pay, you want to know what is retained about that and for how long.
7Open the privacy policy and search three words"advertising", "third part", "retention". Thirty seconds of reading, high yield.
8Check one peer app on the same storeContext. A label only means something next to a comparable one.

What the label does not tell you

The gaps are as important as the contents. A store label does not name the specific companies that receive your data. It does not state retention periods. It does not say which countries the data crosses or which legal regime governs it once it arrives. It does not describe what deletion actually removes, or how long that takes.

It also tells you nothing about money, and money is where most short drama complaints actually live. Your renewal date, your coin balance and what happens to unspent coins are all outside the label's scope. Three beginner mistakes account for a large share of the trouble we see. The first is assuming a free download means a free catalogue — it almost never does, and the genuinely usable free tiers are narrower than the marketing suggests. The second is deleting the app instead of cancelling the subscription; a store-managed subscription keeps billing until you cancel it through Apple or Google, which is why we wrote a step-by-step cancellation guide. The third is assuming that because an app exists on iOS it must also work on Android, on a television or offline. That inference fails constantly.

If the economics are what you are actually worried about, the label will not help, but how coin systems price an episode and how prices shift between countries will.

The regulatory picture, and what is actually in force

Coverage of this area has a persistent failure mode: writers treat a bill or an exposure draft as though it were enacted law. It is not a small error. It changes what a company is obliged to do today and what a reader can rely on. Below, every item carries its status.

Table 4. Regulatory instruments relevant to short drama apps, with status as at 3 September 2026
JurisdictionInstrumentStatusWhat it means for a viewer
United StatesCOPPA, 16 CFR Part 312, as amended; final rule published 22 April 2025In force since 23 June 2025Services directed to under-13s, or with actual knowledge they collect children's data, owe parental-consent and privacy duties. A store age rating does not by itself resolve whether an app is in scope.
United StatesFTC Negative Option Rule ("click to cancel")Vacated; new rulemaking began 11 March 2026Recurring-plan design remains subject to the FTC Act and other subscription laws, but the vacated 2024 rule must not be cited as operative federal law.
JapanAPPI reform bill approved by Cabinet on 7 April 2026Bill — not confirmed enacted lawNothing to rely on yet. Consent and data-handling rules may change; the final text and commencement date are not settled.
JapanConsumer Contract ActIn forceProvides the core consumer-contract framework. Misleading terms and cancellation questions need local legal review, not a generic reading.
AustraliaAustralian Consumer Law; ACCC proceedings of December 2025 against HelloFresh and YoufoodzIn force; the case is an allegation, not a final findingMisleading subscription practices are actionable. The pending case shows regulator attention on subscription traps; it does not establish that anyone broke the law.
AustraliaUnder-16 social media restrictionsIn force; scope is not automaticThey target services meeting the statutory social-media definition. A streaming app is not covered merely because it shows short vertical video; that needs feature-by-feature analysis.
AustraliaOAIC Children's Online Privacy CodeExposure draft released April 2026 — not finalSignals the direction of travel on age assurance and privacy by design. It imposes no obligations in its draft form.

Why age ratings do not settle privacy questions

Age ratings are also developer-supplied, derived from a content questionnaire, and they classify suitability rather than data practice. They vary widely inside this one category. BUMPiNT carries 13+ on its US Apple listing; DramaBox and ShortMax both carry 18+ on their US Apple listings. All three were checked on 3 September 2026. Those differences reflect how each developer answered questions about violence, sexual content and themes — not how much data each app gathers.

The legal point matters more. COPPA scope depends on whether a service is directed to children under 13 or has actual knowledge that it collects their data. An app store rating is not one of the tests. A 13+ label does not place an app outside COPPA, and an 18+ label does not immunise it. The same caution applies to Australia's under-16 rules, which turn on a statutory definition of a social media service rather than on a store's content badge. Anyone reasoning from a rating straight to a compliance conclusion has skipped the analysis.

If you are choosing on behalf of a younger viewer, the useful signal is the combination of rating, label, policy and payment controls together. Our DramaBox review and the rest of the individual app write-ups record all four rather than leaning on the badge.

Settings that reduce what any app collects

These take a few minutes and apply to every app on the device, not just this category.

One honest caveat: none of this stops first-party analytics. Turning off the advertising identifier limits cross-company linking, which is exactly the thing Apple's tracking category is about. It does not stop an app recording what you watched, when you stopped, and which paywall you hit. That data is the core of the business model, and no toggle removes it.

Frequently asked questions

Why do Apple and Google privacy labels for the same app disagree?

Because they are two separate forms, filled in by the developer, about two separate builds of the app. Apple and Google define collection, sharing and tracking differently, apply different exemptions, and update at different times. The iOS and Android versions may also embed different advertising and analytics components. A disagreement is structural, not automatically a contradiction.

Does no data collected on Google Play mean the app collects nothing?

Not necessarily. It means the developer declared that nothing in Google's listed data categories is collected or shared as Google defines those terms. Google's Data safety form carries documented exemptions, including data processed only ephemerally and data handled by a service provider on the developer's behalf. Read the privacy policy alongside the label rather than instead of it.

What does Data used to track you mean on an Apple privacy label?

Apple uses tracking in a narrow, specific sense: linking data from this app with data gathered from other companies' apps, sites or offline records for targeted advertising or ad measurement, or sharing it with a data broker. Analytics confined to the developer's own app is not tracking under that definition, even though it is still collection.

Is a privacy label discrepancy evidence that a developer lied?

No. Two self-declarations written against different taxonomies can both be accurate. A mismatch tells you that at least one of the two descriptions does not transfer to the other platform, which is a reason to read the vendor's privacy policy and check what the app actually asks for. Treat it as a prompt to investigate, not a finding.

Does an app's age rating tell me whether it is safe for a child?

No. An age rating classifies content suitability and is itself derived from a developer questionnaire. It says nothing about what data the app collects or which children's privacy laws apply. US COPPA scope turns on whether a service is directed to under-13s or has actual knowledge it collects their data, not on a store label.

Is the FTC click-to-cancel rule still in force in 2026?

No. The 2024 Negative Option Rule was vacated, and the FTC began fresh rulemaking on 11 March 2026. Recurring-plan design is still governed by the FTC Act and other subscription laws, so cancellation obligations have not vanished. But the vacated rule should not be cited as operative federal law, and a lot of coverage still does.

Has Japan's APPI reform become law?

Not on the evidence we could verify. The Cabinet approved an APPI reform bill on 7 April 2026. A Cabinet-approved bill is a proposal placed before the Diet, not enacted law, and its final text and commencement date can change. Anyone planning around it should track the parliamentary stage rather than the announcement.

Are short drama apps covered by Australia's under-16 social media restrictions?

Not automatically. The restrictions target services that meet the statutory definition of a social media platform. Showing short vertical video does not by itself bring a streaming catalogue inside that definition; coverage depends on a feature-by-feature analysis of the specific product. Anyone asserting that every vertical drama app is caught is going beyond what the law says.

What settings actually reduce what a short drama app collects?

On iOS, turn off Allow Apps to Request to Track and disable personalised Apple advertising. On Android, delete or reset the advertising ID. On both, decline optional permissions, refuse notifications, sign in with an email address rather than a social account, and require authentication for every purchase. None of this stops first-party analytics.

What does a store privacy label not tell me?

It does not name the companies that receive your data, state retention periods, say which countries data crosses, or explain what deletion means in practice. It says nothing about your money either: your subscription, renewal date and coin balance are outside its scope. Deleting an app never cancels a subscription bought through a store.

Sources

Reported by the ShortDramaTop editorial team (how we test). . Every store observation on this page — privacy declarations, age ratings, rating counts and listing dates — was checked on live US listings on 3 September 2026 and can change without notice; re-check the listing before you install or pay. Where a legal instrument is a bill, an exposure draft or a vacated rule, we have said so rather than describing it as law, and nothing here is legal advice. Where we describe a difference between two store declarations we are documenting an inconsistency between self-reported forms, not alleging misconduct by any company. Individual user reviews are reported as individual reports and are not evidence of prevalence. Some links on this page are affiliate links: if you install an app through them we may earn a commission at no extra cost to you. This never affects our scores or our reporting. All trademarks belong to their respective owners.