What Firebase Crashlytics means for your app's privacy disclosures

Firebase Crashlytics is a crash and performance monitor from Google. What it involves, whether it needs the tracking prompt, what goes on the App Store labels and the Play Data safety form, and the rejection it is usually behind.

Updated · Written from the same rules terms.gg uses to generate documents

What Firebase Crashlytics actually does

Crash reporting for mobile, and usually the reason Firebase is in the project at all.

What its job necessarily involves

These follow from what the thing is for, so they are true whichever version you installed:

What to open and check in Firebase Crashlytics

The settings below decide what the honest answer on the forms is, and they are specific to this SDK rather than to its category:

Firebase Crashlytics does not need the tracking prompt

A stack trace is not an advertising identifier, and nothing here follows anyone anywhere. So Firebase Crashlytics does not on its own require App Tracking Transparency. That is a statement about this SDK, not about your app: add one ad network or one attribution tool and the prompt applies to everything.

Firebase Crashlytics in Europe: defensible under legitimate interests

Keeping an app from crashing is a real interest of yours and of the person using it, so crash and performance monitoring is one of the easier things to justify under legitimate interests. That is not a free pass: you still have to write down the assessment, say so in the policy, and keep what you collect to what a fix needs.

Firebase Crashlytics in California: probably not a sale

Firebase Crashlytics does its job for you rather than for its own commercial purposes, which normally keeps it a service provider rather than a sale. That depends on your contract saying so, and the standard terms usually do.

Firebase Crashlytics on the App Store privacy labels

Apple asks what your app collects, and your app collects whatever its SDKs collect. Firebase Crashlytics is generally declared under App Functionality, alongside whatever the rest of your app does for its own reasons.

Firebase Crashlytics on the Google Play Data safety form

The form asks two things the labels do not: whether data is shared with anyone else, and whether it is encrypted in transit. For this SDK the honest answer is usually collected but not shared, because it processes on your behalf.

Check Google's own privacy manifest for Firebase Crashlytics

Since 2024 Apple has required third-party SDKs on its list to ship a signed privacy manifest declaring what they collect and which sensitive APIs they use, and your app's combined manifest is built from them. That file is the authoritative answer for Firebase Crashlytics, it comes from Google, and it changes when they ship.

The rejection Firebase Crashlytics is usually behind

Crashlytics is declared as diagnostics while the Firebase Analytics that came with it is declared as nothing.

What to put in the privacy policy about Firebase Crashlytics

Keeping it true after launch

A legal page stops being true the moment the product moves past it, usually by adding a payment provider, an analytics SDK or a sign-in. No store re-checks your pages against your build, so the drift is yours to notice.

Common questions

Do I need a privacy policy just because I use Firebase Crashlytics?

Yes, and you needed one anyway. Both stores ask for the URL before a listing goes live, whatever the app does. The SDK changes what the policy has to say, not whether you need one.

Does Firebase Crashlytics put me over the line into tracking?

Not by itself. The question is always about your app as a whole, so it is the other things you installed that decide the answer.

Does removing the SDK fix a rejection?

Usually yes and it is the fastest route, but only if you also correct the labels and the form. Reviewers compare what you declared against what the binary contains, and a stale declaration fails on its own.