Skip to main content
Home/Blog/Google Play's 2026 Anonymous and Random Chat App Rules: Age-Restriction, Child-Safety and Developer Verification Changes
Back to Intelligence Hub
platform-policyGlobalRisk Level: high

Google Play's 2026 Anonymous and Random Chat App Rules: Age-Restriction, Child-Safety and Developer Verification Changes

Announced July 15, 2026, Google Play expands its age-restriction, Families and child-safety policies to anonymous and random chat apps, with new Play Console verification deadlines.

Updated July 16, 2026· Originally published July 16, 202613 min readAuditSocials Research
TweetShare
Quick Answer

On July 15, 2026, Google Play announced a package of policy changes that tighten how anonymous chat and random chat apps operate and, separately, harden developer verification across the store. From August 26, 2026, three policies expand to cover anonymous and random chat apps: the Age-Restricted Content and Functionality policy, the Families Policy Requirements (which will prohibit developers of anonymous chat apps from targeting children), and the Child Safety Standards / Child Endangerment policy. From September 30, 2026, developers must register their apps in Play Console to satisfy Android developer verification and Play Console requirements — Google says roughly 99% of apps were registered automatically, but unregistered apps risk global removal from Google Play. Further out, on January 27, 2027, the SMS and Call Log Permissions policy will stop permitting account verification via phone call as a use case for the READ_CALL_LOG permission, directing developers to the Digital Credentials API or SMS Retriever API instead. For app developers, agencies with app-owning clients, and brands running companion apps, the practical message is that anonymous-chat functionality now sits squarely inside Google's child-safety enforcement, and store access itself depends on completing registration and verification on time. Review the platform framework in the Google Ads policy guide, pre-screen product and store copy with the AI Compliance Audit, and track changes on the Policy Change Tracker.

Google Play's 2026 Anonymous and Random Chat App Rules: Age-Restriction, Child-Safety and Developer Verification Changes

What Google Play Changed in July 2026

On July 15, 2026, Google Play announced a set of policy changes that do two things at once: they bring anonymous chat and random chat apps under Google's core child-safety policies, and they tighten developer verification and Play Console registration requirements across the whole store. The changes were published through Google Play's policy announcement and deadline pages, with staggered effective dates running from August 2026 into early 2027.

The anonymous-chat element is the headline. Apps built around random matching or anonymous conversation have drawn sustained scrutiny over how easily minors can reach adults and adult content, and Google's response is to apply its existing age-restriction, Families and child-endangerment frameworks directly to this app category rather than treating it as a gap. Alongside that, a separate but equally consequential thread — Play Console registration and developer verification — determines whether an app can remain distributable at all.

"We're expanding our Families Policy Requirements policy to prohibit developers of anonymous chat apps from targeting children.
— Google Play, Policy announcement (July 15, 2026)"

This guide sets out exactly which policies expanded, the deadlines that apply, how the Play Console registration and verification requirement works, and what the SMS and Call Log permission change means. For the broader Google advertising framework these apps also touch, see the Google Ads policy guide, and track how this and related changes evolve on the Policy Change Tracker.

The Three Child-Safety Policy Expansions

Three separate Google Play policies are being expanded to apply to anonymous chat and random chat apps, all with the same effective date. Each targets a different layer of the child-safety problem, and together they close the space in which this app category previously operated with lighter obligations.

What Is Expanding, and to What

PolicyWhat the expansion doesEffective
Age-Restricted Content and FunctionalityApplies the age-restriction framework to anonymous chat and random chat appsAugust 26, 2026
Families Policy RequirementsProhibits developers of anonymous chat apps from targeting childrenAugust 26, 2026
Child Safety Standards (Child Endangerment)Applies the Child Safety Standards policy to anonymous chat and random chat appsAugust 26, 2026

The practical effect is layered. The Families Policy expansion means an anonymous chat app cannot present itself to, or be targeted at, children — the app must not sit in family-facing surfaces or court a child audience. The Age-Restricted Content and Functionality expansion means the app's content and features are assessed against Google's age-restriction expectations. And the Child Safety Standards expansion brings these apps under the child-endangerment framework that governs how platforms must prevent and respond to child sexual abuse and exploitation risks. Because all three land on the same date, developers of affected apps face a combined compliance workload rather than a single change. Screen store listings, feature descriptions and in-app copy for risk with the Keyword Risk Checker.

Key Compliance Deadlines

The July 15 announcement bundles several deadlines with different dates. Treating them as a single event is a mistake — each has its own timeline and its own consequence for missing it. The table below sets out the sequence as published.

The Deadline Timeline

DateRequirementApplies to
August 26, 2026Age-Restricted Content, Families Policy and Child Safety Standards expansions take effectAnonymous and random chat apps
September 30, 2026Apps must be registered in Play Console to meet developer verification and Play Console requirementsAll Play apps (and apps distributed outside Google Play, optionally)
January 27, 2027READ_CALL_LOG permission can no longer be used for account verification via phone callApps using SMS or Call Log permission groups for verification

The staggering matters for planning. The child-safety expansions demand the earliest action and carry the most direct enforcement risk for the affected app category. The Play Console registration deadline is store-wide and existential — an unregistered app faces global removal. The permission change is further out but requires engineering work to re-architect account verification, so it should not be left until January 2027. Map these dates into your own release calendar and track any further updates on the Policy Change Tracker.

Play Console Registration and Developer Verification

Separate from the child-safety changes, Google is enforcing a store-wide registration and verification requirement with a September 30, 2026 deadline. This is the change most likely to catch developers by surprise, because it applies to every app, not just a specific category.

What the Requirement Says

To meet Android developer verification requirements and Play Console requirements, developers must register their Play apps in Play Console. Google states that roughly 99% of apps on Play were registered automatically, so most developers are already compliant — but the responsibility to check remains. Developers should review their Play Console Home page and register any remaining apps they want to continue distributing, in order to avoid global removal from Google Play and ensure a smooth installation experience for users.

Why It Matters Beyond the Play Store

  • Global removal is the stakes: an unregistered app can be removed globally from Google Play — the most severe outcome for any developer.
  • It extends to off-Play distribution: developers can also register apps distributed outside Google Play, so they remain installable on certified Android devices under the developer-verification regime.
  • The 99% figure is not a guarantee for you: automatic registration covers most apps, but any app in the remaining share must be handled manually before the deadline.

The verification push reflects a broader Android direction: tying app distribution and installability to verified developer identity. For agencies and studios managing multiple apps or client portfolios, the action is straightforward but must not be skipped — audit every app in every Play Console account and confirm registration status. Audit your wider compliance posture with the AI Compliance Audit.

The SMS and Call Log Permission Change

The third strand of the July 15 announcement is a change to the SMS and Call Log Permissions policy, effective January 27, 2027. It is narrower than the child-safety expansions but has real engineering implications for any app that verifies user accounts through the phone.

What Changes

Under the updated policy, the READ_CALL_LOG permission will no longer be permitted as a way to verify accounts via phone call. In other words, developers cannot lean on call-log access as a mechanism for confirming a user's identity or account. Google directs developers to more privacy-preserving alternatives: the Digital Credentials API — used directly or through a verification provider built on it — or the SMS Retriever API, which allows one-time-code verification without requiring broad SMS-reading permissions.

Why Google Is Making the Change

  • Reducing sensitive-permission use: call-log and broad SMS permissions are among the most sensitive an app can request, and Google has been steadily narrowing the use cases that justify them.
  • Steering to purpose-built APIs: the Digital Credentials API and SMS Retriever API achieve verification with far less access to personal data, aligning with data-minimization expectations.
  • Lead time is deliberate: the January 2027 date gives developers time to migrate, but re-architecting verification flows is non-trivial and should be scoped now.

For product and engineering teams, the takeaway is to inventory any account-verification flow that relies on call-log or broad SMS permissions and plan a migration to the recommended APIs well ahead of the deadline. This dovetails with broader data-minimization duties under privacy law; map cross-border obligations with the Legal Compliance Scan.

What Developers, Agencies and Brands Must Do

Although the child-safety expansions target a specific app category, the July 15 package touches a much wider set of developers, agencies and brands. The practical response depends on which apps you run and how you verify users.

Practical Actions by Situation

  • If you build anonymous or random chat apps: treat August 26, 2026 as a hard deadline to bring the app into line with the Age-Restricted Content, Families and Child Safety Standards policies — including not targeting children, implementing age-appropriate controls, and meeting child-endangerment obligations.
  • If you run any Play app: confirm registration in Play Console before September 30, 2026 to avoid global removal, even if you expect automatic registration covered you.
  • If your app verifies accounts by phone: plan migration away from READ_CALL_LOG-based verification to the Digital Credentials API or SMS Retriever API before January 27, 2027.
  • If you are an agency or studio: run this as a portfolio audit across every client and every Play Console account, since a single unregistered app or non-compliant chat feature can remove access.

There is an advertising dimension too. Age-restriction status affects how apps and their content can be promoted and targeted, so marketers running user-acquisition campaigns for affected apps should confirm that targeting and creative respect the new age boundaries. Brands with companion or community apps that include any anonymous or open-chat functionality should assess whether the child-safety expansions reach them. Because policy wording and deadlines can shift, verify the current position against Google Play's official policy and deadline pages before finalizing changes, and see the child-and-teen dimension of platform rules in the compliance glossary.

Google Play Compliance Checklist

  • [ ] Determined whether any of your apps qualify as an anonymous chat or random chat app under the expanded policies
  • [ ] Brought affected apps into line with the Age-Restricted Content and Functionality policy by August 26, 2026
  • [ ] Ensured anonymous chat apps do not target children under the expanded Families Policy Requirements
  • [ ] Met the Child Safety Standards / Child Endangerment obligations for affected apps
  • [ ] Reviewed Play Console Home and confirmed every app is registered before September 30, 2026
  • [ ] Registered any off-Play-distributed apps you want installable on certified Android devices
  • [ ] Inventoried account-verification flows using READ_CALL_LOG or broad SMS permissions
  • [ ] Scoped migration to the Digital Credentials API or SMS Retriever API ahead of January 27, 2027
  • [ ] Reviewed user-acquisition targeting and creative for age-restriction compliance on affected apps
  • [ ] Verified all requirements against Google Play's official policy and deadline pages

Frequently Asked Questions

What did Google Play announce on July 15, 2026 about anonymous and random chat apps?
On July 15, 2026, Google Play announced that three of its core child-safety policies would expand to apply to anonymous chat and random chat apps, all taking effect on August 26, 2026, alongside separate store-wide changes to developer verification and app permissions. The three expansions are the Age-Restricted Content and Functionality policy, the Families Policy Requirements, and the Child Safety Standards (Child Endangerment) policy. The Age-Restricted Content and Functionality expansion means anonymous and random chat apps are now assessed against Google's age-restriction expectations for content and features, which is significant because these apps frequently facilitate unmoderated or lightly moderated interaction that can expose minors to adult content. The Families Policy Requirements expansion prohibits developers of anonymous chat apps from targeting children, meaning the app cannot be presented to, marketed to, or designed for a child audience, and cannot sit in family-facing surfaces. The Child Safety Standards expansion brings these apps under the child-endangerment framework, which governs how developers must prevent and respond to child sexual abuse and exploitation risks on their platforms. Taken together, these changes reflect a deliberate decision by Google to stop treating anonymous and random-matching apps as a category with lighter obligations and instead apply the full weight of its child-safety framework to them. The reason is well documented: random-matching and anonymous-chat formats make it unusually easy for adults and minors to be connected without meaningful safeguards, and self-declared age checks during onboarding are easy to bypass. By expanding these three policies simultaneously, Google closes several gaps at once — targeting, content and endangerment — rather than leaving developers to comply with one dimension while ignoring others. For developers, the practical consequence is that any app built around anonymous or random conversation must be re-evaluated against all three policies before the August 26 deadline, and features that cannot meet the child-safety bar may need to be restricted, gated behind robust age assurance, or removed. Agencies and studios should run this as a portfolio-wide review. Review the broader Google framework in the Google Ads policy guide and track ongoing changes on the Policy Change Tracker. The organizing principle is that anonymous and random chat apps now fall under Google Play's age-restriction, Families and child-endangerment policies as of August 26, 2026.
What is the Play Console registration deadline and what happens if I miss it?
Google Play set a September 30, 2026 deadline by which developers must register their apps in Play Console to satisfy Android developer verification requirements and Play Console requirements, and the consequence of missing it is severe: an unregistered app can face global removal from Google Play. This is a store-wide requirement, not one limited to a particular app category, so every developer with apps on Play needs to confirm their status. Google has stated that roughly 99% of apps on Play were registered automatically, which means most developers are already compliant without taking any action — but that statistic is precisely why the requirement is easy to overlook. The responsibility still rests with the developer to check, because any app in the remaining share that is not registered by the deadline is exposed. The correct action is to review your Play Console Home page and register any remaining apps you want to continue distributing. Beyond the Play Store itself, the registration mechanism extends to apps distributed outside Google Play: developers can register those apps too, so they remain installable on certified Android devices under Android's developer-verification regime. This reflects a broader Android direction of tying app distribution and installability to verified developer identity, and it means the registration step has implications even for developers who distribute through other channels. For individual developers, the task is simple — log into Play Console, check registration status, and complete registration for anything outstanding. For agencies, studios and larger organizations, the task is a systematic audit: every Play Console account and every app within it must be checked, because a single missed registration can remove a live, revenue-generating app globally. It is worth treating this with the same seriousness as a payment or certificate expiry, since the failure mode is not a warning but removal. Because deadlines and mechanics can be updated, confirm the current requirement against Google Play's official Play Console and developer-verification pages before relying on any summary. Audit your broader compliance posture with the AI Compliance Audit and keep watch on store-policy shifts via the Policy Change Tracker. The organizing principle is that every Play app must be registered in Play Console by September 30, 2026 or risk global removal, and most — but not necessarily all — apps were registered automatically.
How does the READ_CALL_LOG permission change affect account verification, and what should I use instead?
Effective January 27, 2027, Google Play's SMS and Call Log Permissions policy will no longer permit account verification via phone call as a use case for the READ_CALL_LOG permission, which means developers who rely on call-log access to confirm user identity must migrate to alternative, more privacy-preserving verification methods before that date. Google directs developers to two recommended approaches: the Digital Credentials API — used either directly or through a verification provider built on top of it — and the SMS Retriever API, which enables one-time-code verification without requiring an app to hold broad SMS-reading permissions. The change sits within a long-running effort by Google to narrow the legitimate use cases for its most sensitive permissions. Call-log and broad SMS permissions expose a great deal of personal information, and Google has progressively restricted them to a small set of core use cases, removing others over time. Account verification via phone call is now being removed as a justification for READ_CALL_LOG specifically, closing a mechanism some apps used to confirm accounts by detecting an incoming or outgoing verification call. The rationale is data minimization: the recommended APIs accomplish verification with far less access to a user's data, so there is no longer a strong justification for granting an app call-log access purely for verification. For product and engineering teams, the practical work is to inventory every account-verification flow in the app estate and identify any that depend on READ_CALL_LOG or broad SMS permissions. Each such flow needs to be re-architected around the Digital Credentials API or the SMS Retriever API. This is not a trivial configuration toggle — it can involve changing how one-time codes are delivered and read, integrating a credentials provider, and updating the app's permission declarations and privacy disclosures. Because the deadline is in early 2027, there is lead time, but the migration should be scoped and planned now rather than deferred, particularly for apps with large user bases where verification is on a critical path. This also intersects with privacy law's data-minimization principles, so teams should treat it as both a platform-policy and a privacy-compliance exercise. Map cross-border legal obligations with the Legal Compliance Scan and review permission-related definitions in the compliance glossary. The organizing principle is that call-log-based phone-call verification ends on January 27, 2027, and developers should migrate to the Digital Credentials API or SMS Retriever API.
Do these changes affect advertisers and brands, or only app developers?
While the July 15, 2026 announcement is framed around Google Play developer policies, its effects reach advertisers, agencies and brands as well, because app distribution, age-restriction status and store standing all shape how apps can be marketed and monetized. The most direct developer-facing elements — the child-safety expansions, Play Console registration, and the permission change — are obligations on whoever owns and publishes the app, but the downstream commercial consequences touch anyone who promotes or invests in those apps. For advertisers running user-acquisition campaigns, the age-restriction dimension is the key link. When an app becomes subject to the Age-Restricted Content and Functionality policy, its content and audience expectations change, and marketers need to ensure that campaign targeting and creative respect the new age boundaries rather than courting a younger audience the Families Policy now prohibits for anonymous chat apps. Promoting an anonymous or random chat app to, or in a way that reaches, children would run against the expanded Families Policy, so acquisition strategies built on broad or youth-skewing targeting need review. For brands, the relevant question is whether any of their own apps include functionality that falls within the expanded definitions. A brand with a companion app, a community app, or any product that offers anonymous conversation, open messaging, or random user matching should assess whether the child-safety expansions apply — the policies attach to the functionality, not to the company's primary business. If they do apply, the brand faces the same August 26 obligations as any other developer of such an app. For agencies, the changes create a client-advisory role: agencies managing app portfolios or user-acquisition budgets should proactively flag the deadlines to clients, run registration audits, and adjust campaign plans for affected apps. The Play Console registration requirement in particular is one an agency can easily check on a client's behalf and one that, if missed, would nullify any acquisition investment by removing the app entirely. The safe approach for any commercial stakeholder is to confirm, for each app they promote or own, its registration status, its age-restriction position, and its exposure to the child-safety expansions. Pre-screen store listings and campaign copy with the Keyword Risk Checker and audit the full compliance picture with the AI Compliance Audit. The organizing principle is that the changes are developer obligations with real advertiser and brand consequences through age-restriction, targeting and store-access effects.
How should agencies and studios manage compliance across multiple apps and clients?
For agencies and studios managing multiple apps or client portfolios, the July 15, 2026 Google Play changes are best handled as a structured, portfolio-wide audit rather than an app-by-app afterthought, because the deadlines are staggered, the consequences range up to global removal, and a single overlooked app can undermine an entire client relationship. The most efficient approach is to build a simple compliance matrix that lists every app across every Play Console account and tracks its status against each of the relevant requirements. The first column of that matrix is Play Console registration, tied to the September 30, 2026 deadline. Because Google auto-registered roughly 99% of apps, most entries will already be compliant, but the audit exists precisely to catch the exceptions — and for an agency, the exceptions are the risk, since a missed registration removes a live client app globally. Every Play Console account the agency touches should be reviewed on its Home page, and any unregistered app registered before the deadline. The second area is the anonymous and random chat classification, tied to the August 26, 2026 child-safety expansions. The agency should identify any client app that offers anonymous conversation, random matching, or open messaging, and flag it for review against the Age-Restricted Content, Families and Child Safety Standards policies. Where an app falls in scope, the agency's role is to coordinate the substantive compliance work — age assurance, ensuring the app does not target children, and meeting child-endangerment obligations — with the client's product and legal teams, since these are not changes an agency can make unilaterally. The third area is account verification, tied to the January 27, 2027 permission change. The agency should ask each client whether their apps verify accounts using call-log or broad SMS permissions and, if so, ensure a migration to the Digital Credentials API or SMS Retriever API is on the roadmap. Beyond the matrix, agencies add value by translating these deadlines into client-facing action plans, adjusting user-acquisition campaigns for age-restriction compliance, and monitoring for further policy updates that could add or move deadlines. Because Google's policy pages are the authoritative source and details can change, the agency should verify each requirement against the official Play Console and policy pages rather than relying solely on a summary. Track platform-policy changes centrally on the Policy Change Tracker and standardize client audits with the AI Compliance Audit. The organizing principle is that agencies should run a staggered, portfolio-wide audit covering registration, chat-app classification and verification, coordinating substantive fixes with clients and confirming everything against Google's official pages.

Don't miss the next policy change.

Create a free account — track every policy change across 8 platforms, get instant alerts, and access every free compliance tool. Or try our Keyword Risk Checker first.

Create Free Account

Report Keywords — Run AI Compliance Audit

#Google Play#Play Console#Child Safety#Age Restriction#Content Moderation#Developer Verification#Kids & Teens#App Compliance#Platform Policy#Developers#2026 Policy#Compliance Guide 2026

Share This Report

TweetShare

Related Posts

Related Resources