Backend & Auth

Privacy Policy for Apps Using Firebase

Firebase is a bundle of services — Authentication, Firestore/Realtime Database, Analytics, Crashlytics, Cloud Messaging — that store and process user data on Google’s infrastructure. Each one you enable has privacy implications to disclose.

Create My Privacy Policy

Last updated July 8, 2026

Why this affects your privacy policy

When you use Firebase, user accounts, app data, analytics events, crash reports, and push tokens are processed by Google as your backend provider. App stores expect this in your policy and data-safety forms, and Firebase Analytics in particular collects identifiers and usage data that must be disclosed.

Data typically processed

Data type Details
Account data Email, password hash, or federated identity via Firebase Auth.
App data Content users create, stored in Firestore/Realtime Database.
Analytics events Usage events and an app-instance ID via Firebase Analytics.
Crash diagnostics Stack traces and device state via Crashlytics.
Push tokens Device tokens for Cloud Messaging notifications.

What to disclose

  • That you use a third-party cloud backend to store and process user data.
  • Which categories you collect: account, user content, analytics, diagnostics, push tokens.
  • That data is hosted on the provider’s infrastructure and may be transferred internationally.
  • That analytics/crash tools collect identifiers and usage/diagnostic data.
  • How users can delete their account and associated data.

Example wording

Hosting & Backend. We use a third-party cloud platform to provide authentication, data storage, analytics, and crash reporting. Through these services we process your account details, the content you create in the app, usage analytics, and diagnostic data such as crash reports. This data is stored on the provider’s infrastructure and may be processed in other countries. You can request deletion of your account and data at any time.

Sample language only — adapt it to your actual data practices.

Best practices

  • Disclose each Firebase product you actually use — Analytics and Crashlytics collect the most.
  • Consider disabling Analytics ad-ID collection if you don’t run ads, and say so.
  • Set Firestore security rules so users can only access their own data (a privacy safeguard).
  • Mirror these categories in your App Store and Play Store data-safety disclosures.

Generate a policy that already covers Firebase and host it at a permanent URL.

Host Your Policy

Frequently asked questions

Does Firebase Analytics need to be in my privacy policy?

Yes. Firebase Analytics collects an app-instance identifier and usage/device data, which must be disclosed in your policy and your app-store data-safety forms.

Is Firebase GDPR compliant?

Google provides data-processing terms for Firebase, but compliance also depends on how you configure it and what you disclose. Your policy must describe your own data practices.

Do I need to name Google/Firebase specifically?

You must disclose that a third-party backend processes user data. Naming the provider is optional for GDPR/CCPA, though some app reviewers appreciate the specificity.

Related guides

This guide is for general informational purposes only and is not legal advice. Your privacy policy should reflect your actual data practices and applicable legal requirements, which vary by jurisdiction and platform.

Create and host your privacy policy

Fill out a short form, get a permanent HTTPS URL for your app submission.

Create My Privacy Policy