
Google does not treat a VPN like a flashlight app. Android's VpnService can see device traffic. Play's policy is public: only core VPN apps (and a short list of exceptions) may build a device-level tunnel, you must document that use in the Play listing, you must encrypt from the device to the tunnel endpoint, and you must not siphon other apps' traffic to make money. The sensitive-permissions article and the dedicated VpnService help page are the two tabs I keep open. Policies move. Read them the week you submit.
This is not the App Store rejection-patterns piece, and it is not the screenshots piece. Those are Apple metadata and listing pixels. This is Play Console work: declare the API, show a prominent disclosure, record the consent flow, and keep analytics out of the payload.
I will describe the operator process and quote the shape of questions Google has previewed in their VpnService help article (core VPN yes/no, permitted exception categories, videos, data types, monetization redirect). Console UI labels change. If a checkbox in your tenant does not match my nouns, trust the live Console and the live policy, not this blog.
Klox white-label means your Play identity if you want a real brand. You click submit. You own Data safety plus the VpnService declaration. Reseller skips this because users install Klox. Consumer Klox is WireGuard, OpenVPN, OpenConnect, and Shadowsocks, five devices, from $2.83 a month, seven-day money-back. That sentence does not complete a declaration form.
If your 'Android app' is an undated APK with no disclosure screen, you are not ready for production. You are ready for a policy strike.
I have seen contractors treat the declaration as a one-time quiz they can guess. It is not. It is a description of the binary. When the binary changes, the description changes. Budget that as a release step, next to signing and screenshots. If your release checklist ends at 'upload AAB,' you will eventually upload a strike.
Related reading: App Store Rejection Patterns for Branded VPN Apps and VPN App Screenshots That Survive App Store Review. Apple VPN Entitlements for a White-Label Brand and White-Label VPN and 14 Day Launch Checklist. What is a VPN? and Download KloxVPN.
Looking for a reliable VPN?
KloxVPN — from $2.83/month. Apps for every device.
Why Play treats VpnService as a restricted tool
A VPN app can intercept traffic. Junk apps have used that to mess with ads, to watch payloads, to pretend to be a 'cleaner.' Play's answer is a short allow-list: core VPN, or exceptions like parental control, enterprise management, device security, network tools, browsers, carrier apps. If you are a consumer privacy VPN, you are in the core-VPN bucket. Say so. Do not dress as a game with a hidden tunnel.
The sensitive-permissions policy (the page at answer/9888170) is the parent. VpnService has its own subsection there and a dedicated explainer (answer/12564964) with a preview of declaration questions. Use both. The parent page also covers other restricted APIs. Do not skip it because you think you only need 'the VPN form.'
Encryption to the tunnel endpoint is mandatory in the policy text. WireGuard, OpenVPN, OpenConnect, and Shadowsocks are how Klox-shaped clients do that job. You still have to tell the truth in the listing: this app creates a VPN tunnel. If the store description reads like a wallpaper pack, you failed documentation even if the binary is honest.
- 1Skim the seating / order diagram.
- 2Do the numbered steps once on your real network.
- 3Use the FAQ if a sentence was too long.
- 4Follow one related article — not ten tabs.
How to read this page
| Piece | What Google's public help describes | What I actually prepare | Failure mode |
|---|---|---|---|
| Core VPN question | Is VPN the core functionality? | Yes, for a branded privacy client | You pick an exception you are not |
| Listing copy | Document VpnService use in the Play listing | Description says the app creates a VPN tunnel | Lifestyle copy, no tunnel mentioned |
| In-app disclosure | Prominent, in-flow, not only a policy URL | A dedicated screen before connect | Buried in Settings > Legal |
| Consent | Affirmative action, then system VPN dialog | Accept control, then Android's VPN prompt | Pre-ticked box, connect on launch |
| Videos | Short clips of VPN use and of disclosure | 90 seconds or less, full text readable | A mute speed-test montage |
| Data / ads | Declare collection; no monetizing others' traffic | No payload analytics; Data safety matches SDKs | SDK reads destinations 'for ads' |
If the disclosure is only in a privacy policy, it is not prominent. Play already said that.
— KloxVPN operator notes
Google Play: Permissions and APIs that Access Sensitive Information
Google Play: Understanding the VpnService policy
Core VPN vs the exception list
Google's preview asks whether VPN is core. If you say no, you pick an exception: parental control, enterprise management, device security, network tools, browsers, carrier, and so on. White-label consumer privacy is core VPN. Do not tick 'device security' because it sounded enterprise. Mismatch is a rejection. Being in an exception category is also not enough; you still document listing use and you still encrypt to the endpoint.
What the policy forbids in plain language
Collecting personal or sensitive data through the tunnel without prominent disclosure and consent. Redirecting or manipulating other apps' traffic to make money — Google's example is shoving ads through another country. If your monetization idea is 'we inspect payloads to sell insights,' stop. That is not a Klox partner motion. We will not help you invent it.
The declaration as a process, not a trivia quiz
Google's help page says apps using VpnService need to complete the declaration in Play Console, subject to approval. Historically they even published a deadline for existing apps. Your deadline is: before production users, not after a strike.
Process I actually run: (1) freeze the binary that uses VpnService, (2) write listing text that says it is a VPN, (3) ship the in-app disclosure, (4) record two short videos, (5) fill Data safety so it does not fight the declaration, (6) answer the Console questionnaire from the live form, (7) keep a copy of what you submitted. If you change how the API is used, Google says you must submit again. Treat that as true.
I will not invent every label in your tenant. The preview questions include core yes/no, exception categories, a video of the app opening and the VPN being used, what data the VPN service collects or shares, a video of the prominent disclosure, and whether you redirect traffic for monetization. If your form is grouped differently, follow the form.
Who clicks in a white-label deal
You, on your Play Console, if you own the brand. If the vendor publishes, it is their declaration and their account risk. That is not white-label as customers mean it. Confirm who is the developer. Transfers later are pain.
Closed testing and new accounts
New Play identities often need testing tracks and a wait before production. That is calendar, not a VpnService quirk. Put it on the launch critical path. A perfect declaration on an account that cannot ship production is still stuck.
Prominent disclosure: in the app, in the path, not in a PDF
Google's VpnService help repeats User Data rules. The disclosure must be in the app, shown in normal use, not only a website. It must not require a scavenger hunt through menus. It must say what is accessed or collected through VpnService, and how it is used or shared. It must require an affirmative action — tap to accept, tick a box. It cannot be only a privacy policy. It cannot be mixed into a pile of unrelated consents. Separate screen. VPN-shaped words.
Write like a human. 'This app creates a VPN tunnel to the operator's servers so your device traffic is encrypted in transit. Account email is used to bill and support you. We do not sell your traffic to advertisers.' If you collect more, say more. If you do not run the nodes, do not say 'we operate servers in …' unless that is true. Link the operator notice if that is the honest model.
System VPN dialog is not a substitute. Android's prompt is required to start the service. Play still wants your disclosure first. Two steps. Do not skip yours because the OS has one.
What 'affirmative' is not
A pre-checked box. Connect on first launch with a toast. 'By continuing you agree' under a spinner. Dark-pattern accept. If the user declines, do not trap them. The parent restricted-permissions policy says you respect a no. A VPN app can still offer a browse-only help screen. It should not force the tunnel.
Language and readability
If you localize the app, localize this screen. A German binary with an English wall of text looks like you hid the deal. Keep type large enough that a 90-second video can show every line. If it scrolls, the video must scroll slowly. Google says that out loud in the video guidance.
The videos: 90 seconds, boring, complete
Google's preview asks for a short video (90 seconds or shorter) of the app opening and the VPN being used, with voice-over or captions if it is not obvious. It asks for another showing the prominent disclosure. The guidance block is specific: open the app, walk to the disclosure, show the full text (scroll if needed), show consent including granting VpnService, and show the path when the user does not consent and later sees the screen again.
That last bit is the one teams skip. Record the decline path. If decline does nothing, or if the screen never appears again, you built a trap or a dead end. Fix the app, then shoot.
Upload a YouTube or cloud URL to an MP4 or similar. Unlisted YouTube is fine. A 4K cinematic of a skyline is not. I want a Pixel on a desk and a thumb.
What I put on a teleprompter
'This is the branded client. Home. Disclosure. Accept. Android VPN permission. Connected. Disconnect. Re-open. Decline path. Help still works.' Then I stop talking. Captions on, because reviewers may watch muted.
What gets the video rejected in spirit
Speed-test theater. A map animation. Fast cuts that hide the disclosure text. A build that is not the one you submitted. Record the same version code.
Data questions and Data safety have to agree
The preview includes whether the VPN service collects or shares data, then a type list that looks a lot like Data safety categories: location, personal info, financial, messages, photos, browsing, crash logs, device IDs, and so on. I am not going to pretend I know every toggle in your Console this week. I am going to tell you to answer from the binary, not from the homepage.
Account email for login is collection. Crash SDK is collection. A payment SDK is collection. Destination hostnames stored for 'analytics' is the kind of collection that fights a privacy brand and may fight policy if you did not disclose. Payload inspection for ads is how you lose.
Data safety is a separate form. Reviewers compare. If declaration says no browsing history and an SDK is logging URLs, you did it to yourself.
No traffic-payload analytics
Do not parse user payloads to learn what they do on the web. Do not sell that. Do not 'anonymize' it and wink. A consumer VPN's job is to carry packets to an endpoint with encryption, not to become a telemetry company. If you need quality metrics, stick to app performance and crash data you disclosed. If you need abuse controls, that is a different, narrow workflow you should be able to explain without storing browsing history. Confirm what the operator actually retains. Do not guess.
TLS on the control plane is not a privacy policy
RFC 8446 is TLS 1.3. It is good that your API uses modern TLS. It does not mean you 'collect nothing.' Forms care about categories of data, not cipher suites. Do not paste RFC numbers into Data safety.
Listing text that actually documents VpnService
Policy: document use of VpnService in the Google Play listing. That means the public description should say this is a VPN app that creates a device tunnel. Not only in a support site. Not only in the declaration form.
Write a short paragraph: what the tunnel is for, platforms, that WireGuard, OpenVPN, OpenConnect, and Shadowsocks are available if that is true for your binary, that a system permission will appear. Do not promise city counts you cannot defend. Do not paste Klox consumer pricing into a partner listing unless it is your price.
Full description and short description both matter. The feature graphic should look like the app, not a hoodie spy. That is the screenshots article. Mention it because listing documentation is words and pixels.
Category and tags
Pick the category that matches a VPN. Tools is common. Do not hide in Entertainment. Tags that say 'fast unlimited free proxy' attract the wrong reviewer mood and the wrong users.
What's new
When you resubmit after a disclosure change, say that in What's new. Reviewers are not telepathic. 'Disclosure screen added before connect' is a useful sentence.
Encrypt to the endpoint, then stop overclaiming
Policy requires encryption from the device to the VPN tunnel endpoint. That is the job of the protocols you ship. Klox-shaped apps use WireGuard, OpenVPN, OpenConnect, and Shadowsocks for that path. You still should not write 'military grade' in the listing. Say encrypted tunnel. If someone wants cipher details, put them in a help article you can keep true.
Split tunnel, if you have it, is a disclosure issue: not all traffic may go through the tunnel. Say so in the app if users can exclude apps. If you cannot exclude, do not screenshot a per-app list.
Kill switch vs VpnService
A kill switch is app logic around the tunnel. It is not a substitute for disclosure. It can also break captive portals and generate tickets. If you show it in the listing, it must exist in the binary. Play is not the only one who will notice. Users will.
Always-on VPN
Android settings can pin a VPN always-on. If you instruct users to do that, your disclosure should still have happened in-app first. Do not tell people to enable always-on as a way to skip your screen.
SDKs, ads, and the monetization question
Google's preview asks whether you redirect or manipulate user traffic from other apps for monetization. The correct answer for a honest consumer VPN is no. If you answered yes, the help text says you are outside allowed use unless you can explain a policy-fitting case. I cannot think of one I want a Klox partner to run.
Ad SDKs in a VPN app are a mess even when they do not touch the tunnel. They create Data safety rows and user distrust. If you must run ads, they still cannot use tunnel payloads. Most brands should just charge money. Klox consumer is a paid product with a refund window. Copy that idea, not a rewarded-ad interstitial on the connect button.
Crash and performance SDKs
Allowed if disclosed. Keep them from slurping network destinations. Configure them like you meant it. Default SDK settings are how privacy brands die.
Third-party code is still your declaration
Play's User Data policy reminds you that SDKs you bundle are your problem. If a library collects by default, you disclose or you rip it out. White-label does not mean 'the vendor's SDK soup is invisible.'
Failure modes I see on partner brands
Undeclared VpnService. Declared, but listing never says VPN. Disclosure only in a policy URL. Video of a different app. Video too fast to read. Data safety empty. Exception category selected for a consumer VPN. Monetization left blank by a contractor who did not understand the question. Demo account expired so review could not even reach the disclosure.
None of these are crypto failures. They are packet failures. The same energy as Apple review notes. Slow down.
Policy strikes can sit on the account, not only the app. Do not buy 'aged' Play accounts to skip this. That is how you buy someone else's sins.
Resubmitting after a change
You added an SDK. You changed the disclosure. You added split tunnel. Google said to submit the form again if API use changes. Calendar it. Do not hope the old approval covers a new datapath.
When to stop and resell instead
If nobody on your team can record a device video or fill Data safety, you do not want a branded Android app yet. Reseller. Users install Klox. You skip Console theology.
Play and Apple on the same calendar, without mixing the packets
Branded VPN launches die when Android is 'ready' and iOS is still waiting on an entitlement, or the other way around, and ads already spend. Play declarations have their own queue. Apple has Guideline 5.4 and Network Extension. Do not paste Data safety answers into App Privacy. Do not paste a Play video into App Review notes and hope.
Build a dual calendar: disclosure screen exists in both clients (the words can match; the UI will not). Play videos recorded. Apple review notes written in the same honest voice. Demo accounts that last. Nutrition labels and Data safety filled from the same SDK inventory. Then submit the slower store first if you cannot afford a split launch. I would rather both be late than one storefront convert people onto a brand that does not exist on the phone they own.
White-label does not merge those queues. You inherit protocol behavior. You own both consoles. If that sentence makes you tired, reseller exists so you can stop.
Operators typically want a status channel and a way to disable a subscriber without a payload log. Confirm what Klox includes on a call. Do not put a fictional Play API path in your runbook because a Stack Overflow answer used one in 2022.
SDK inventory is the shared source of truth
One spreadsheet: crash, payments, chat, maps, attribution. Each row: what it collects, whether it is in Android, iOS, or both, and which form field it feeds. The Play declaration's data list and Data safety should read as if they were filled by the same person on the same day. Because they should have been.
What 'ready for ads' actually means
Production track live, listing live, disclosure in the wild, videos not set to private-by-accident, demo account still valid for a re-review. If any of those are fake-ready, you are not ready. I have watched people turn on spend the hour they clicked submit. Review is not a CDN. It does not cache your optimism.
A checklist you can run the week you submit
Live policy tabs: 9888170 and 12564964. Binary with VpnService. Listing paragraph that says VPN. Disclosure screen in the first-run connect path. Decline path. Two videos under 90 seconds. Data safety matches SDKs. Declaration answers match the binary. Demo login that lasts through review. Internal note of version code and recording date.
Then have a second human watch the videos without sound. If they cannot explain what the app is, shoot again.
Confirm with Klox on a call what the partner Android build includes. I will not invent endpoint names or an SLA percent for that build. Ask. Write down the answer. Put only that in your own wiki.
Apple is a different stack
Network Extension, 5.4, nutrition labels, organization account. Do not paste Play answers into App Store Connect. Do the Apple packet separately. We pointed at that in the rejection-patterns post and the screenshots post.
Where the user should go
White-label if you want this paperwork and a brand. Contact if your Play identity is a mess. Pricing and download if you personally just need a VPN today.
Key Takeaways
Play's VpnService rules are not a riddle. Core VPN or a real exception. Say so in the listing. Encrypt to the endpoint. Disclose in-app with a real tap. Record the flow, including a no. Do not inspect payloads for ads. Do not redirect other apps' traffic to make money.
The form will look slightly different in your Console than it does in Google's preview article. Follow the live form. Follow the live policy pages. This blog is an operator checklist, not a screenshot of their UI.
I would rather you ship two weeks later with a readable disclosure than ship a silent tunnel and spend a month in appeals. Strikes are slower than videos.
Keep both Google tabs bookmarked. Re-read them when you bump a version that touches the tunnel. Policies get notes. Your memory of last quarter's form is not a source.
If you want a branded Android client and you will own Play Console, talk to us about white-label. If you do not want this declaration, sell Klox as Klox.
Related Resources
Own the Play Console. Declare the tunnel.
White-label is your brand on the Klox network. You still file VpnService paperwork on your developer account. Bring the disclosure screen, not a guess.
Talk to us about white-labelFrequently Asked Questions
KloxVPN Team
Experts in VPN infrastructure, network security, and online privacy. The KloxVPN team has been building and operating VPN services since 2019, providing consumer and white-label VPN solutions to thousands of users worldwide.