App Store Privacy Labels in 2026: Why Apple and Google Disagree About the Same App
Store privacy labels are written by the developer, not audited by Apple or Google, and the two stores ask different questions with different thresholds. That is why one short drama app can declare no data collection on Google Play while its Apple label reports tracking linked to your identity. A mismatch is a prompt to investigate, not proof of wrongdoing.
Three apps we rate highest after hands-on testing:
Huge library — thousands of dramas, 200+ new titles every month
Free daily episodes + unlock more by watching ads
Best value for binge-watchers — subscriptions from $5.99/week
For: Android, iOS and Web



6,844 visited this page todayIn-app purchases available
30M+ monthly viewers — one of the fastest-growing drama apps
Daily free episodes and generous new-user bonuses
Addictive revenge & alpha-romance catalog, great localization
For: Android, iOS and Web



In-app purchases available
Best for international viewers — English, Spanish, French & more
Flexible player — control the story pace your way
Coin packs or VIP subscription that unlocks all content
For: Android, iOS and Web



In-app purchases available
What a store privacy label actually is — and what it is not
When a developer submits a build, both stores make them fill in a disclosure form. Apple publishes the result as the App Privacy section of the product page. Google publishes it as the Data safety section. Neither store decompiles the app, watches its network traffic and derives the label from what it sees. The label is a declaration, and the store's role is to publish it and to enforce accuracy after the fact as a policy matter.
That is worth saying out loud, because the visual design of both labels implies otherwise. They look like nutrition panels, which people read as measured facts. They are closer to a customs declaration: structured, comparable, binding on the person who signed it, and entirely dependent on that person having understood the questions and answered them completely.
None of this makes labels useless. Within a single platform they are genuinely comparable — if you check five apps on the same store, you are comparing like with like, which is exactly the discipline behind our 2026 ranking of all 14 short drama apps. They also create a public record. A developer whose label says one thing while the app plainly does another is exposed to store enforcement and, in several jurisdictions, to consumer-protection regulators. What labels cannot do is substitute for an audit that nobody performed.
| Apple App Privacy | Google Play Data safety | |
|---|---|---|
| Who fills it in | The developer, at submission, per app version | The developer, in Play Console, per app |
| Verified by the store? | No independent audit; accuracy enforced as a policy obligation | No independent audit; accuracy enforced as a policy obligation |
| Top-level categories | Data Used to Track You; Data Linked to You; Data Not Linked to You | Data collected; Data shared; each mapped to declared purposes |
| Cross-company ad linking | An explicit category, tied to App Tracking Transparency | No direct equivalent; surfaces as a purpose such as advertising or marketing |
| Named exemptions | Limited; centred on the definition of tracking | Documented exemptions, including ephemeral processing and service-provider handling |
| Security statements | Not part of the label | Encryption in transit and deletion-request availability are declared fields |
| What a blank means | "Data Not Collected" — the developer states nothing in Apple's categories is gathered | "No data collected" — the developer states nothing in Google's categories is collected, subject to the exemptions |
| Update cadence | Reviewed with each submitted version | Editable independently of a release; can drift from the shipped code |
The BUMPiNT case: one app, two declarations
BUMPiNT is a Japanese short drama app published by emole. We checked both of its live listings on 3 September 2026. On the US App Store, the App Privacy section reports data used to track you and data linked to your identity. On Google Play the same day, the Data safety section declares that no data is collected and none is shared; that Play listing showed a last update of 21 August 2026.
Those two statements describe the same brand and, broadly, the same service. They are not describing the same artefact, and they are not answering the same question. This is a documented inconsistency between two self-declarations. It is not evidence of wrongdoing by emole, by Apple or by Google, and we are not alleging any. Both declarations can be literally accurate under their own platform's rules at the same time.
| Field | US App Store | Google Play |
|---|---|---|
| Privacy declaration | Data used to track you; data linked to you | No data collected; no data shared |
| Listing freshness at check | Version 4.15.0, displayed as updated one day earlier | Last updated 21 August 2026 |
| Age rating shown | 13+ | Rated for its own Play content category |
| Store rating at check | 3.9 from 58 ratings | Separate Android rating pool |
| What we can conclude | The two forms disagree. Neither declaration is verified by its store, so the disagreement identifies a question to ask, not an answer. | |
One BUMPiNT reviewer on Apple reported repeated charges and difficulty removing payment information. That is one review. It is worth knowing about, and it is not evidence of prevalence — a single account of a billing problem tells you what can go wrong, not how often it does. The same discipline applies elsewhere in the category: one Vigloo reviewer alleged that coins were spent without consent, and another said a saved playlist had vanished. We report those as individual reports because that is all they are.
Why the two stores disagree, mechanically
There are four ordinary reasons a label can differ across platforms, none of which require anyone to be lying.
They describe different binaries
The iOS and Android versions of an app are separately compiled products that frequently embed different advertising, attribution and crash-reporting components. If the Android build ships without the third-party ad SDK that the iOS build includes, the honest Android declaration really is thinner. This is common in apps that monetise mainly through iOS.
The two forms define "collection" differently
Google's Data safety form carries documented exemptions. Data that is only processed ephemerally, and data handled by a service provider strictly on the developer's behalf, need not be declared as collection in the way an intuitive reading would suggest. Apple's questionnaire draws its lines in different places. Two engineers filling in both forms in good faith can land on "no" in one and "yes" in the other.
Only Apple has a "tracking" category
Apple's top-level Data Used to Track You heading exists because of App Tracking Transparency. Google's form has no field that asks the same question in the same shape; cross-company advertising activity surfaces indirectly, through the purposes attached to shared data. So a behaviour that produces a bold red heading on one store may produce a modest line item on the other.
Labels drift out of date
Apple reviews the declaration with each submitted version. Google's form can be edited on a different schedule from the code. When a label was last touched matters, which is why the update dates in the table above are part of the evidence and not decoration. If you want a broader view of how these apps compare on the things stores do measure, the full comparison table is the place to start.
What "tracking" means under Apple's definition
Apple's term is much narrower than the everyday word. Under the App Tracking Transparency framework, tracking means linking user or device data collected in this app with data collected from other companies' apps, websites or offline properties, for targeted advertising or advertising measurement — or sharing it with a data broker. If the developer does either, the label must show Data Used to Track You, and the app must ask permission through the system prompt.
Two consequences follow, and both are routinely misread.
First, plenty of collection is not tracking. An app that logs which episodes you watch, keeps that data entirely inside its own systems, and uses it to recommend more of the same is collecting a great deal about you and is not tracking you in Apple's sense. That data can still appear on the label — under Data Linked to You, which is a separate heading meaning tied to your identity, account or device rather than aggregated and anonymised.
Second, an app can be tracking without ever building a profile itself. Handing an identifier to an advertising network that does the linking is enough. This is why the heading appears on so many free apps whose developers would sincerely describe themselves as not interested in your data: the interest belongs to the SDK they installed.
What Google's Data safety form asks instead
Google asks a different set of questions. Roughly: which of these data types does your app collect; which does it share with third parties; for what purpose in each case; is the data encrypted in transit; and can users request deletion. There is also a separate line for whether the app has undergone an independent security review, which is a distinct claim from the collection declaration.
The structure is purpose-led rather than tracking-led. That makes it good at a question Apple's label handles poorly — what is this for? — and weaker at the one Apple foregrounds. A Play listing can show a substantial collection list with sensible-sounding purposes and give you no clean way to tell whether an advertising identifier is being joined with data from elsewhere.
"No data collected" is therefore a real statement with a specific meaning, and not a synonym for "this app is private". It means the developer answered no to Google's categories, as Google defines them, with Google's exemptions available. It is a good sign. It is not a guarantee, and it is not comparable to a blank Apple label.
How to read a label in 60 seconds
You do not need to become a privacy analyst. You need a repeatable sequence, and it takes about a minute. This is the same routine we run for every app in our app scorecards.
| # | Step | What you are looking for |
|---|---|---|
| 1 | Open both store listings, even if you only use one | Whether the two declarations agree. Disagreement is your signal to slow down. |
| 2 | On Apple, read the three headings top to bottom | Data Used to Track You first. Then what sits under Linked to You versus Not Linked to You. |
| 3 | On Play, expand "See details" | The split between collected and shared, and the purpose given for each data type. |
| 4 | Check the two security fields on Play | Encrypted in transit, and whether deletion can be requested. Absence of either is informative. |
| 5 | Compare the label date with the app's last update | A label far older than the current build is describing software you are not installing. |
| 6 | Look specifically for purchase and financial data | If you intend to pay, you want to know what is retained about that and for how long. |
| 7 | Open the privacy policy and search three words | "advertising", "third part", "retention". Thirty seconds of reading, high yield. |
| 8 | Check one peer app on the same store | Context. A label only means something next to a comparable one. |
What the label does not tell you
The gaps are as important as the contents. A store label does not name the specific companies that receive your data. It does not state retention periods. It does not say which countries the data crosses or which legal regime governs it once it arrives. It does not describe what deletion actually removes, or how long that takes.
It also tells you nothing about money, and money is where most short drama complaints actually live. Your renewal date, your coin balance and what happens to unspent coins are all outside the label's scope. Three beginner mistakes account for a large share of the trouble we see. The first is assuming a free download means a free catalogue — it almost never does, and the genuinely usable free tiers are narrower than the marketing suggests. The second is deleting the app instead of cancelling the subscription; a store-managed subscription keeps billing until you cancel it through Apple or Google, which is why we wrote a step-by-step cancellation guide. The third is assuming that because an app exists on iOS it must also work on Android, on a television or offline. That inference fails constantly.
If the economics are what you are actually worried about, the label will not help, but how coin systems price an episode and how prices shift between countries will.
The regulatory picture, and what is actually in force
Coverage of this area has a persistent failure mode: writers treat a bill or an exposure draft as though it were enacted law. It is not a small error. It changes what a company is obliged to do today and what a reader can rely on. Below, every item carries its status.
| Jurisdiction | Instrument | Status | What it means for a viewer |
|---|---|---|---|
| United States | COPPA, 16 CFR Part 312, as amended; final rule published 22 April 2025 | In force since 23 June 2025 | Services directed to under-13s, or with actual knowledge they collect children's data, owe parental-consent and privacy duties. A store age rating does not by itself resolve whether an app is in scope. |
| United States | FTC Negative Option Rule ("click to cancel") | Vacated; new rulemaking began 11 March 2026 | Recurring-plan design remains subject to the FTC Act and other subscription laws, but the vacated 2024 rule must not be cited as operative federal law. |
| Japan | APPI reform bill approved by Cabinet on 7 April 2026 | Bill — not confirmed enacted law | Nothing to rely on yet. Consent and data-handling rules may change; the final text and commencement date are not settled. |
| Japan | Consumer Contract Act | In force | Provides the core consumer-contract framework. Misleading terms and cancellation questions need local legal review, not a generic reading. |
| Australia | Australian Consumer Law; ACCC proceedings of December 2025 against HelloFresh and Youfoodz | In force; the case is an allegation, not a final finding | Misleading subscription practices are actionable. The pending case shows regulator attention on subscription traps; it does not establish that anyone broke the law. |
| Australia | Under-16 social media restrictions | In force; scope is not automatic | They target services meeting the statutory social-media definition. A streaming app is not covered merely because it shows short vertical video; that needs feature-by-feature analysis. |
| Australia | OAIC Children's Online Privacy Code | Exposure draft released April 2026 — not final | Signals the direction of travel on age assurance and privacy by design. It imposes no obligations in its draft form. |
Why age ratings do not settle privacy questions
Age ratings are also developer-supplied, derived from a content questionnaire, and they classify suitability rather than data practice. They vary widely inside this one category. BUMPiNT carries 13+ on its US Apple listing; DramaBox and ShortMax both carry 18+ on their US Apple listings. All three were checked on 3 September 2026. Those differences reflect how each developer answered questions about violence, sexual content and themes — not how much data each app gathers.
The legal point matters more. COPPA scope depends on whether a service is directed to children under 13 or has actual knowledge that it collects their data. An app store rating is not one of the tests. A 13+ label does not place an app outside COPPA, and an 18+ label does not immunise it. The same caution applies to Australia's under-16 rules, which turn on a statutory definition of a social media service rather than on a store's content badge. Anyone reasoning from a rating straight to a compliance conclusion has skipped the analysis.
If you are choosing on behalf of a younger viewer, the useful signal is the combination of rating, label, policy and payment controls together. Our DramaBox review and the rest of the individual app write-ups record all four rather than leaning on the badge.
Settings that reduce what any app collects
These take a few minutes and apply to every app on the device, not just this category.
- iOS: Settings → Privacy & Security → Tracking, and turn off Allow Apps to Request to Track. That denies the ATT prompt by default for everything. Then Settings → Privacy & Security → Apple Advertising and switch off personalised ads.
- Android: in Settings → Privacy (or Google → Ads, depending on version), delete the advertising ID. Deleting it, rather than resetting it, is the stronger option.
- Both: decline notification permission at install. Notification prompts in this category exist largely to pull you back into a cliffhanger, and refusing costs you nothing.
- Sign in with an email address rather than a social or platform account where the app allows it. Fewer linked identities means fewer joins available downstream.
- Require authentication for every purchase — Face ID, fingerprint or password — and turn off any in-app auto-unlock feature that spends coins without confirming.
- Review permissions after a week, not at install. Anything the app has not needed by then, revoke.
One honest caveat: none of this stops first-party analytics. Turning off the advertising identifier limits cross-company linking, which is exactly the thing Apple's tracking category is about. It does not stop an app recording what you watched, when you stopped, and which paywall you hit. That data is the core of the business model, and no toggle removes it.
Frequently asked questions
Why do Apple and Google privacy labels for the same app disagree?
Because they are two separate forms, filled in by the developer, about two separate builds of the app. Apple and Google define collection, sharing and tracking differently, apply different exemptions, and update at different times. The iOS and Android versions may also embed different advertising and analytics components. A disagreement is structural, not automatically a contradiction.
Does no data collected on Google Play mean the app collects nothing?
Not necessarily. It means the developer declared that nothing in Google's listed data categories is collected or shared as Google defines those terms. Google's Data safety form carries documented exemptions, including data processed only ephemerally and data handled by a service provider on the developer's behalf. Read the privacy policy alongside the label rather than instead of it.
What does Data used to track you mean on an Apple privacy label?
Apple uses tracking in a narrow, specific sense: linking data from this app with data gathered from other companies' apps, sites or offline records for targeted advertising or ad measurement, or sharing it with a data broker. Analytics confined to the developer's own app is not tracking under that definition, even though it is still collection.
Is a privacy label discrepancy evidence that a developer lied?
No. Two self-declarations written against different taxonomies can both be accurate. A mismatch tells you that at least one of the two descriptions does not transfer to the other platform, which is a reason to read the vendor's privacy policy and check what the app actually asks for. Treat it as a prompt to investigate, not a finding.
Does an app's age rating tell me whether it is safe for a child?
No. An age rating classifies content suitability and is itself derived from a developer questionnaire. It says nothing about what data the app collects or which children's privacy laws apply. US COPPA scope turns on whether a service is directed to under-13s or has actual knowledge it collects their data, not on a store label.
Is the FTC click-to-cancel rule still in force in 2026?
No. The 2024 Negative Option Rule was vacated, and the FTC began fresh rulemaking on 11 March 2026. Recurring-plan design is still governed by the FTC Act and other subscription laws, so cancellation obligations have not vanished. But the vacated rule should not be cited as operative federal law, and a lot of coverage still does.
Has Japan's APPI reform become law?
Not on the evidence we could verify. The Cabinet approved an APPI reform bill on 7 April 2026. A Cabinet-approved bill is a proposal placed before the Diet, not enacted law, and its final text and commencement date can change. Anyone planning around it should track the parliamentary stage rather than the announcement.
Are short drama apps covered by Australia's under-16 social media restrictions?
Not automatically. The restrictions target services that meet the statutory definition of a social media platform. Showing short vertical video does not by itself bring a streaming catalogue inside that definition; coverage depends on a feature-by-feature analysis of the specific product. Anyone asserting that every vertical drama app is caught is going beyond what the law says.
What settings actually reduce what a short drama app collects?
On iOS, turn off Allow Apps to Request to Track and disable personalised Apple advertising. On Android, delete or reset the advertising ID. On both, decline optional permissions, refuse notifications, sign in with an email address rather than a social account, and require authentication for every purchase. None of this stops first-party analytics.
What does a store privacy label not tell me?
It does not name the companies that receive your data, state retention periods, say which countries data crosses, or explain what deletion means in practice. It says nothing about your money either: your subscription, renewal date and coin balance are outside its scope. Deleting an app never cancels a subscription bought through a store.
Sources
- BUMPiNT, US App Store listing — App Privacy section reporting data used to track you and data linked to you; 13+ age rating; version 4.15.0 shown as updated one day before check; 3.9 rating from 58 ratings. Live listing checked 3 September 2026.
- BUMPiNT, Google Play listing — Data safety section declaring no data collected and no data shared; listing last updated 21 August 2026. Checked 3 September 2026.
- Apple, App privacy details on the App Store — developer documentation defining the declaration categories, including Data Used to Track You, Data Linked to You and Data Not Linked to You, and the App Tracking Transparency definition of tracking.
- Google Play, Provide information for Google Play's Data safety section — the developer form, its data categories and purposes, its encryption and deletion fields, and its documented collection exemptions.
- Federal Register — Children's Online Privacy Protection Rule, 16 CFR Part 312, final rule published 22 April 2025, effective 23 June 2025. In force.
- US Federal Trade Commission, Negative Option Rule — records that the 2024 rule was vacated and that new rulemaking commenced 11 March 2026. Vacated; rulemaking ongoing.
- Consumer Contract Act, official English translation — Japan's core consumer-contract framework. In force. The translation page did not expose a recent update date.
- Japan, APPI reform — Cabinet approval of a reform bill on 7 April 2026, reported in legal analysis rather than confirmed as enacted law in the evidence retained. Bill, not law.
- ACCC — proceedings commenced December 2025 against HelloFresh and Youfoodz over alleged subscription traps. Allegations only; no final finding.
- eSafety Commissioner, Australia — social media age restrictions and the statutory definition that determines which services are covered. In force; scope not automatic.
- OAIC Children's Online Privacy Code — exposure draft released April 2026, described in secondary legal analysis. Draft, not a final code.
- US Apple storefront observations, checked 3 September 2026 — DramaBox and ShortMax both listed at 18+; store ratings of roughly 4.8 from about 841,000 ratings for DramaBox and 4.6 from about 171,000 for ShortMax. Rating counts measure review volume, not users or subscribers.
- Individual user reviews cited in this article — one BUMPiNT Apple reviewer describing repeated charges and difficulty removing payment information; one Vigloo reviewer alleging coins were used without consent; one Vigloo reviewer reporting a disappeared playlist. Single reports, cited as such; they do not establish prevalence.
- ShortDramaTop hands-on testing of short drama apps, their store listings, permission prompts and payment flows (how we test).
1