Purpose
Every requested Android permission must have a legitimate, clearly communicated purpose tied to core app functionality. Over-requesting permissions is a leading cause of Play Store rejection.
5.1 Sensitive Permissions Requiring Justification
The following sensitive permissions require explicit justification and are subject to elevated Play Store review:
- CAMERA (android.permission.CAMERA)
- LOCATION (ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION)
- MICROPHONE (android.permission.RECORD_AUDIO)
- CONTACTS (READ_CONTACTS, WRITE_CONTACTS)
- SMS (SEND_SMS, RECEIVE_SMS, READ_SMS)
- CALL LOG (READ_CALL_LOG, WRITE_CALL_LOG)
- STORAGE (READ_EXTERNAL_STORAGE, WRITE_EXTERNAL_STORAGE)
- BLUETOOTH (BLUETOOTH, BLUETOOTH_CONNECT)
- NOTIFICATIONS (POST_NOTIFICATIONS)
5.2 Audit Rule
For every permission, ask: “Does my application genuinely require this to function?” If the answer is no — remove it.
5.3 Examples
- Bad (unjustifiable): A calculator or bookkeeping app requesting Contacts, Location, and Microphone.
- Good (justifiable): A video-calling app requesting Camera (required), Microphone (required), and Contacts (potentially required).
5.4 Permissions Audit Table
| Permission |
Requested? |
Feature Supported |
Justified? |
Runtime Request Used? |
| Camera | NO | N/A — No camera features | No (Not required) | N/A |
| Location | NO | N/A — Dependent dropdowns used | No (Unnecessary) | N/A |
| Microphone | NO | N/A — No voice features | No (Unnecessary) | N/A |
| Contacts | NO | Manual entry or Contact Picker | No (Broad access avoided) | N/A (Contact Picker used) |
| SMS | NO | System SMS/WhatsApp intents | No (Background SMS avoided) | N/A (Delegated to OS app) |
| Call Log | NO | N/A — No telephony tracking | No (Unrelated) | N/A |
| Storage | NO | Scoped app-private storage used | No (Scoped storage used) | N/A (No broad storage) |
| Bluetooth | NO | N/A — No hardware accessories | No (Unrelated) | N/A |
| Notifications | NO | User-initiated actions only | No (No push spam) | N/A |
| Internet (INTERNET) | YES | HTTPS/TLS 1.3 REST API with backend | Yes (Essential) | Normal permission |
| Network State (ACCESS_NETWORK_STATE) | YES | Offline detection & candidate failover | Yes (Essential) | Normal permission |
5.5 Implementation Notes
- Use runtime permission requests rather than relying only on manifest declarations.
- Explain, in-context (at the moment of request), why the permission is needed.
- Use the Android Contact Picker instead of requesting broad Contacts access when full access isn’t necessary — complying with Google’s updated Contacts Permissions policy (effective January 27, 2027).
- Sensitive data/permission handling overall follows Google’s User Data policy.
Sign-off Checklist
- ☑ Every requested permission mapped to a specific feature
- ☑ Unjustified permissions removed
- ☑ Runtime permission prompts implemented with clear in-context explanations
- ☑ Contact Picker used instead of full Contacts access where possible
- ☑ Re-audited whenever a new feature or SDK adds a permission