Google collects information about your device's network activity, installed apps (including apps not from Google Play), and URLs you visit as part of its malware protection system — and some of this data collection continues even if you turn off the protection feature.
This analysis describes what Google Play Store's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
The clause establishes Google's operational authority to gather security-related device data and take protective actions (warnings, removals, blocks) without prior user consent for each instance. It defines the scope of data collection that persists even when users disable certain protections, creating a baseline security monitoring framework.
The updated terms establish two new financial obligations for subscription users. First, Google may charge your payment method up to 48 hours before the start of a billing period, rather than 24 hours as previously stated. Second, the revised terms now explicitly state that if a subscription charge fails and you have not cancelled, you remain responsible for the uncollected amount, and Google may attempt to charge a backup payment method. This may alter your billing dates and the timing of when you are billed each period. Additionally, users are now explicitly liable for any background data fees incurred by Google system services and content updates, including when the device screen is locked. You can review your subscription settings in Google Play to monitor billing schedules and update payment methods.
View change record →Consumers who disable malware protection may not fully stop Google from receiving data about apps installed on their device, meaning a comprehensive app inventory and network connection data may be continuously transmitted to Google regardless of user settings.
How other platforms handle this
You may give us your Identity Data, Contact Data, Financial Data, Profile Data, and other information by filling in forms or by corresponding with us by post, phone, e-mail or otherwise.
NIM container releases that collect data, collect it for the following purposes: (a) to properly configure and optimize products for use with Software; and (b) to improve NVIDIA products and services.
Some of our ad partners may also enable us to collect similar data directly from their website or app by integrating our or our affiliates' advertising technology.
"To protect you against malicious third party software, URLs, and other security issues, Google may receive information about your Device's network connections, potentially harmful URLs, the operating system, and apps installed on your Device through Google Play or from other sources. Google may warn you if it considers an app or URL to be unsafe, or Google may remove or block its installation on your Device if it is known to be harmful to devices, data or users. You can choose to disable some of these protections in the settings on your Device, however, Google may continue to receive information about apps installed through Google Play, and apps installed on your Device from other sources may continue to be analyzed for security issues without sending information to Google.Excerpt from Google Play Store's Google Play Terms
(1) REGULATORY FRAMEWORK: This provision implicates GDPR Art.
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Netflix updated its Privacy Statement on April 18, 2026, disclosing voice recording collection and expanded household ad profiling for the first time.
Google's Privacy Policy covers Search, Gmail, YouTube, Maps, and every site running Google Analytics. Here is what it actually authorizes.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
The clause establishes Google's operational authority to gather security-related device data and take protective actions (warnings, removals, blocks) without prior user consent for each instance. It defines the scope of data collection that persists even when users disable certain protections, creating a baseline security monitoring framework.
Consumers who disable malware protection may not fully stop Google from receiving data about apps installed on their device, meaning a comprehensive app inventory and network connection data may be continuously transmitted to Google regardless of user settings.
ConductAtlas has identified this type of provision across 295 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Google Play Store.