Privacy is no longer a legal footnote. Users increasingly choose apps they trust, app stores require clear disclosures, and data protection laws such as the Kenya Data Protection Act and the GDPR set firm expectations. At Annan Digital Labs, privacy is part of our design process from the first workshop. Here is how we approach it.
Start with data minimization
The simplest way to protect data is not to collect it. For every feature, we ask:
- What is the minimum information needed for this to work?
- Can it stay on the user’s device instead of our servers?
- Can we use an anonymous or aggregated version instead?
- How long do we actually need to keep it?
This discipline reduces risk, simplifies compliance and often makes the app faster and cheaper to run.
Ask for permissions in context
Nothing erodes trust faster than an app that asks for the camera, contacts and location the moment it opens. We request permissions only when the user reaches the feature that needs them, and we explain why in plain language first. If a user declines, the rest of the app keeps working.
Write privacy policies people can read
A privacy policy should answer simple questions clearly:
- What data does the app collect?
- Why is it collected?
- Who is it shared with?
- How long is it kept?
- How can I delete it?
- Who do I contact with questions?
Every app we publish has its own policy that answers these questions specifically for that app, hosted on a stable public web address. That address goes into the Google Play Console and the app’s store listing. You can see ours in our Privacy Center.
Keep the Data safety form honest
Google Play requires every app to complete a Data safety declaration describing the data it collects and shares, including data collected by third-party libraries such as analytics, crash reporting and advertising SDKs. We audit every SDK in an app before release and make sure the declaration, the privacy policy and the app’s real behaviour all match. Mismatches can lead to rejected updates or removal from the store, and more importantly, they break user trust.
Make account deletion easy
If an app lets users create an account, users must also be able to delete it. Google Play requires apps with accounts to offer deletion both inside the app and through a web page that works even if the app is uninstalled. We build both paths from the start:
- An in-app Delete account option in settings;
- A public data deletion page where users can submit a request;
- Clear information about what is deleted, what must be retained for legal reasons, and how long it takes.
Protect data in transit and at rest
Technical safeguards we apply by default include:
- HTTPS for all network communication;
- Encrypted storage for sensitive data on the device;
- Least-privilege access controls on servers and databases;
- Secrets kept out of source code and app bundles;
- Regular dependency updates and security reviews.
Plan for the unexpected
Even well-built systems can face incidents. We document how data flows through each product, keep logs that help investigate issues without over-collecting personal data, and prepare a response plan so that affected users and authorities can be informed promptly if something goes wrong.
Privacy as a competitive advantage
Treating privacy seriously is not just about avoiding penalties. Clear, honest data practices lead to better reviews, higher retention and smoother app store approvals. If you are planning an app and want privacy built in from the start, get in touch.