1.1. Publish the Privacy Policy as a web page at a permanent URL (for example ninetydayplan.org/privacy). Not as a PDF, not behind a login, not geo-restricted. The link must open without errors.
1.2. Enter this URL in Google Play Console (Policy, App content, Privacy Policy) and in App Store Connect (App Privacy).
1.3. Publish the Terms of Use at a permanent URL and link to both documents from the App (Profile, Settings) and from the website footer.
1.4. Insert the effective date in each document before publishing.
2.1. Keep the in-app path: Profile, Settings, Delete Account. Deletion must actually delete the account and the data, not merely deactivate the account.
2.2. The deletion request is handled through the support page at https://ninetydayplan.org/support. This exact address is referenced in the Privacy Policy, the Consent and the Terms of Use, and the same URL must be entered in the Data safety form in Play Console. If you decide to use a different address, let me know and I will update all three documents.
2.3. The current support page mentions personal data deletion requests, which is correct, but it does not yet state what is deleted, what is retained and how long the request takes. Google checks for this. Add a short block covering the three points below.
2.4. Requirements to that page, checked by Google:
2.5. Do not use a Google Form that requires signing in to a Google account. Such forms are rejected.
2.6. Make sure deletion requests actually reach ninetydayplan.app@gmail.com and are answered.
3.1. Fill the form so that it matches the Privacy Policy. Any discrepancy between the form, the policy and the actual behaviour of the App is a review flag.
3.2. Important: third-party SDKs count as your own data collection. The build currently includes Firebase Analytics, Firebase Cloud Messaging and Resend. All three must be declared.
3.3. The current listing states that no data are shared with third parties. This contradicts the presence of Firebase Analytics, Firebase Cloud Messaging and Resend, which process device identifiers, usage events and e-mail addresses. The declaration must be corrected before submission.
3.4. Since April 2025 Android ID is explicitly treated as a device identifier and must be declared under "Device or other IDs" if any SDK reads it.
3.5. Declare, per data category: whether it is collected, whether it is shared, the purpose, whether it is optional, whether it is encrypted in transit and whether it can be deleted.
| Category | Collected | Comment |
|---|---|---|
| Personal info (name, e-mail, phone, address) | Yes | Entered by the user in the profile |
| Location (approximate) | Yes | Declared in the current listing |
| Device or other IDs | Yes | Including Android ID if read by any SDK |
| App info and performance (crash logs) | Check | Declared in the current listing. Confirm with the developer which component collects them, since Crashlytics is not in the SDK list |
| Contacts entered manually by the user | Check | Data about the user’s clients and partners recorded in the App. Declare in accordance with how they are stored |
| Financial info | Check | Income figures recorded by the user. If they are stored on the server, declare them |
5.1. The subscription is sold on the website, not through in-app purchases. Both stores require that digital content unlocked inside the app be sold through their own billing systems, so this model must be implemented carefully.
5.2. Inside the App there must be no buttons, links, prompts or instructions leading the user to pay on the website. This includes wording such as "buy on our website", banners with the address, and QR codes. For the same reason the Terms of Use and the Privacy Policy do not contain a purchase link: they state only that payment is processed outside the App.
5.3. The App may only show that access to the paid functionality is not active. Any external purchase path must be discovered by the user outside the App.
5.4. Before the purchase the user must clearly see: the duration of the trial, the date of the first charge, the price, the billing period and how to cancel.
5.5. Cancellation of automatic renewal must be simple and must not require contacting support.
5.6. If a charge occurs after the user has cancelled, refund it in full.
6.1. Screenshots and the description must not contain income promises or guarantees of results. The store listing currently shows figures such as growth percentages and income statistics: make sure they are presented as illustrations of the interface, not as promised results.
6.2. Do not use the trademarks of direct sales companies in the icon, screenshots, title or description unless you hold the corresponding permission.
6.3. Check the age rating. The App is a business tool and its content is addressed to adults, so the questionnaire in the console should be filled accordingly.
7.1. Article 12(2) of Law No. 94-V requires storage of personal data in a database located in the territory of Kazakhstan. The current infrastructure is located abroad. Cross-border transfer itself is governed by Article 16: paragraph 2 permits transfer to states that ensure protection of personal data, and paragraph 3(1) permits transfer to states that do not, where the data subject has consented. The documents rely on both grounds, but consent to transfer does not substitute compliance with the storage requirement of Article 12(2).
7.2. Recommendation: either place the primary database in Kazakhstan, or obtain a written position from a Kazakhstan lawyer on the approach chosen, since Article 12(2) is worded as an unconditional requirement.
7.3. Note the short deadline of Article 8(7) of Law No. 94-V: where a user withdraws consent, processing must be terminated within fifteen working days, or a reasoned refusal must be given. Support processes should be able to meet this deadline.
7.4. Three amending laws to Law No. 94-V are pending: No. 326-VIII from 25 August 2026, No. 350-VIII from 14 September 2026 and No. 311-VIII from 1 January 2027. The documents are prepared under the version in force as of 12 July 2026. Review the documents after the first of these dates.
8.1. The Privacy Policy URL opens without a login and without errors.
8.2. The deletion page URL opens without a login, leads directly to the request and names the App.
8.3. The in-app deletion path works and actually deletes the account.
8.4. The Data safety form matches the Privacy Policy and the SDKs actually present in the build.
8.5. There are no external payment links inside the App.
8.6. The e-mail address ninetydayplan.app@gmail.com is monitored and requests are answered.
8.7. The effective dates are filled in all documents.