Play Data Safety — Bachat

Generated 21 July 2026 by /kit-generate-legal, from the SDKs and endpoints actually wired in the build. Re-run after toggling anything in KitConfig or adding a table/endpoint — a form that no longer matches the app is the exact thing Play removes apps for.

Open this side-by-side with Play Console → App content → Data safety and copy the answers.

Data collection and security

QuestionAnswer
Does your app collect or share any of the required user data types?Yes
Is all of the user data collected by your app encrypted in transit?Yes
Do you provide a way for users to request that their data is deleted?Yes

Deletion detail to enter: In-app via Profile → Delete account, which permanently erases the account, all tax records and all receipt images immediately. Users may also email team@morpheralabs.com. There is no retention window.

Data types collected

Only the categories below are active. Everything not listed here must be left unchecked.

Personal info → Name

Personal info → Email address

Personal info → User IDs

Financial info → Purchase history

Financial info → Other financial info

Photos and videos → Photos

App activity → App interactions

App info and performance → Crash logs

App info and performance → Diagnostics

Device or other IDs → Device or other IDs

Categories to leave UNCHECKED

Verified absent from the build — do not tick these:

Security practices section

QuestionAnswer
Is data encrypted in transit?Yes — all traffic is HTTPS/TLS
Can users request data deletion?Yes — in-app, immediate
Has your app been independently validated against a security standard?No

Before you submit

  1. Privacy policy URL — host playstore/privacy_policy.html and paste the URL under App content → Privacy policy. Play rejects submissions without one.
  2. Data deletion — under App content → Data deletion, point at the hosted policy (Section 4 describes the in-app flow) and provide team@morpheralabs.com as the request address.
  3. KitConfig.PRIVACY_URL and TERMS_URL are still https://example.com/.... Update them to the hosted URLs, or Settings → Privacy opens a dead link on a shipped build.