This policy is designed to provide guidance to developers building on the Actions on Google platform, including Actions that will be published in the directory. Some partners may have access to additional APIs and be subject to varying policies.
For the purposes of this policy, the term “Action” applies to either the Action project or individual Actions within that project. This policy applies to all aspects of Actions, including their content, advertising content (where permitted), behavior, and listing information in the directory.
Avoiding a policy violation is always better than managing one, but when violations do occur, we’re committed to ensuring developers understand how they can bring their Action into compliance.
If your Action violates our policy, you may receive an email notification with a specific reason for removal or rejection. Repeated or serious violations of the policy will result in termination of individual, related or partner accounts.
We may also limit the discoverability of your Action if it is low quality (such as failing to gracefully handle user queries), unhealthy (such as crashing or exiting unexpectedly), or contains content that is inappropriate for most audiences.
We don't allow Actions that facilitate or promote sexual gratification or sexually explicit content. This includes:
- Pornographic, sexually explicit, or erotic content.
- Content that describes sexual acts or sex toys.
- Escort services or other services that may be interpreted as providing sexual acts in exchange for compensation.
- Content that describes or encourages bestiality.
Google has a zero-tolerance policy against child sexual abuse content. If we become aware of content facilitating or promoting the distribution of child sexual abuse content, we will report it to the appropriate authorities and delete the Google Accounts of those involved with the distribution.
Violence and dangerous activities
We don't allow Actions that facilitate or promote gratuitous violence or dangerous activities. This includes:
- Graphic descriptions of realistic violence or violent threats to any person or animal.
- Terrorist groups documenting their attacks.
- Instructions for engaging in or facilitating violent activities, including bomb-making or weapon-making.
- Self-harm, including instructions to carry out self-harm.
We don’t allow Actions that facilitate the sale of explosives, weapons, firearms and related components.
Bullying and harassment
We don't allow Actions that facilitate threats, harassment, or bullying. This includes content primarily intended to harass or single out another person for abuse, malicious attack, or ridicule.
We don't allow Actions that facilitate or promote content that advocates hate or violence against groups of people based on their race or ethnic origin, religion, disability, gender, age, nationality, veteran status, sexual orientation, or gender identity.
Actions that facilitate or promote near-hate negativity towards a protected group are prohibited. This includes Actions that make inflammatory or excessively negative statements about:
- Appearance or hygiene.
- Socio-economic status.
- Ethics or morality.
- Disability or medical condition.
- Criminal history.
- Sexual activity.
We don't allow Actions that lack reasonable sensitivity towards, or capitalize on, a natural disaster, atrocity, conflict, death, or other tragic event.
We don't allow Actions that facilitate or promote online gambling services, including but not limited to, online casinos, sports betting, lotteries, or games of skill if they offer prizes of cash or other value.
We don't allow Actions that facilitate or promote illegal activities You are solely responsible for determining the legality of your Action in its targeted locale. Actions determined to be unlawful in locations where they are published will be removed.
Alcohol & Tobacco
Actions that facilitate or promote the sale of alcohol or tobacco, or related products, are allowed in countries listed in Google’s Alcohol Adwords policy. All Actions must:
Implement account linking and verify user meets legal age requirements
Comply with all restrictions or procedures required by an applicable local law
These requirements apply to all alcohol beverage products, including wine, beer, spirits, and alcohol kits, and tobacco products, including cigarettes, cigars, rolling tobacco, and e-cigarettes.
Actions that sell alcohol or tobacco cannot use the Food Order Direct Action API to complete transaction.
Alcohol and tobacco branded Actions must include age verification at the beginning of the conversation.
We don’t allow Actions that promote excessive use of alcohol or tobacco, or use by minors
We don’t allow Actions that facilitate the sale or production of recreational drugs.
We don't allow Actions that provide, collect, or store medical information in violation of applicable legal obligations. Google is not able to commit that the Actions on Google platform can meet the requirements of HIPAA or other similar medical data regulations.
Actions that provide health information must include a disclaimer at the beginning of the user’s first conversation with the Action and in the directory description.
Actions providing fitness functionality, including activity monitoring (calories burned, steps taken, etc.), weight data, and BMI are permitted.
We don’t allow Actions that provide services or store sensitive financial data in violation of applicable legal obligations. Google is not able to commit that the Actions on Google platform can meet all requirements set by financial regulations.
Financial data or authentication data cannot be collected via the conversational interface. This includes, for example, bank account or credit card numbers, or PIN/passwords. Actions that provide bank account information, such as credit balances, must implement account linking.
Actions providing general financial information, including interest rates and stock prices, are permitted.
We don’t allow Actions that enable users to contact emergency responders. For example 911 or 999 services.
If your Action contains content that may be inappropriate for a general audience, discusses mature themes, disturbing or distressing content, or frequently has profanity, it must include a disclaimer at the beginning of the user’s first conversation with the Action and in the Actions directory description.
If your Action contains user-generated content, it must include a warning indicating as such at the beginning of the user’s first conversation with the Action and in the Actions directory description.
Intellectual Property, Deception, and Spam
We don't allow Actions or developer accounts that infringe the intellectual property rights of others, including trademark, copyright, patent, trade secret, and other proprietary rights. We also don't allow Actions that encourage or induce infringement of intellectual property rights.
We will respond to clear notices of alleged copyright infringement. For more information or to file a Digital Millennium Copyright Act request, please visit our copyright procedures.
If you are a trademark owner and you believe an Action is infringing on your trademark rights, we encourage you to reach out to the developer directly to resolve your concern. If you can't reach a resolution with the developer, please submit a trademark complaint through this form.
We don't allow Actions that use another Action or entity's brand, title, logo, or name in a manner that may result in misleading users. Impersonation can occur even if there isn't an intent to deceive, so please be careful when referencing any brands that do not belong to you. This applies even if that brand doesn't yet have a presence on the directory.
Encouraging infringement of copyright
We don't allow Actions that induce or encourage copyright infringement. Before you publish your Action, look for ways it may be encouraging copyright infringement and get legal advice if necessary.
We don't allow Actions that infringe on others' trademarks. A trademark is a word, symbol, or combination that identifies the source of a good or service. Once acquired, a trademark gives the owner exclusive rights to the trademark usage with respect to certain goods or services.
Trademark infringement is the improper or unauthorized use of an identical or similar trademark in a way that is likely to cause confusion as to the source of that product. If your Action uses another party's trademarks in a way that is likely to cause confusion, your Action may be removed.
We don't allow Actions that attempt to deceive users. Actions must provide accurate disclosure of their functionality and perform as reasonably expected by the user. Actions must not attempt to mimic system functionality or warnings of any kind. Any changes to device settings must be made with the user's knowledge and consent and be easily reversible by the user.
We don't allow Actions that contain false or misleading information or claims, including in the trigger phrase, description, title, or icon. Don't try to imply an endorsement or relationship with another entity where none exists.
Examples of misleading claims include:
- Misrepresenting or not accurately and clearly describing Action functionality, for example:
- An Action that claims to be a food delivery service in its description or invocation, but is actually a ride-sharing service.
- An Action that claims to be a restaurant reservation service, but only contains restaurant reviews.
- An Action that uses a trigger phrase related to coffee, but is actually a pizza delivery service.
- Misrepresenting the current status or performance on the directory (e.g. "Editor's Choice," "Number 1 Action").
- Featuring medical or health-related functionality that is misleading or potentially harmful.
- Claiming functionality that is impossible to implement.
- Actions that are improperly categorized.
- Misleading a user as to the content or destination of a link.
Unauthorized use or imitation of system functionality
We don't allow Actions that mimic or interfere with device or Assistant functionality. Examples of prohibited behaviour include:
- Using a voice for your Action that mimics the Google Assistant's voice.
- Mimicking system notifications or warnings.
- Pretending to be Google or another Google Action.
We don't allow Actions that spam users or the directory in any way. Examples of spammy behavior include:
- Actions that push content to users' mobile devices without their permission or send excessive or irrelevant content using the Update API.
- Actions whose primary purpose is to drive traffic to a website or another Action that is not owned by the Action’s developer.
- Submitting multiple duplicative Actions to the Actions directory.
Privacy and Security
You must be transparent in how you handle user data (e.g., information provided by a user, collected about a user, and collected about a user's use of the Action or device). This policy establishes the directory's minimum privacy requirements; you or your Action may need to comply with additional restrictions or procedures if required by an applicable law.
All Actions must:
Handle all user data securely
All transmissions of user data must use modern cryptography, and your Action's interaction with the Actions on Google APIs must use HTTPS.
Accurately describe the reason for requesting user data via a permission API
You must clearly and accurately disclose the legitimate business reason for requesting user data via a permission API by using the "context" field in the corresponding method.
In addition to the requirements above, the table below describes requirements for specific activities and data types.
|Activity / Data Type||Requirement|
|Payment and Financial Data
(including credit card and bank account numbers)
|Don't collect payment or financial data via the conversational interface (text or speech).|
|Email Addresses||Gain explicit consent from the user.|
(including passwords, PINs, and answers to security questions)
|Don't collect authentication data via the conversational interface (text or speech).
After a user's account has been linked, PINs or passwords may be used as part of a second verification process.
Account linking and Identity
You may use the Account Linking API and OAuth 2 to create a link between a Google user and an existing non-Google account on your system. When implementing account linking using OAuth, you must own your OAuth endpoint or have control over it with an OAuth service provider. Do not provide URLs from Identity Providers directly in your Actions on Google configuration. Only one OAuth config per action package is permitted.
Don't use any other method to associate a Google user with an account on your system, including using an association from another Action engaging in account linking. For example, if you offer multiple Actions requiring account linking, each Action must independently use the Account Linking API — using the configuration defined in the respective action package — to associate the Google user with the existing account.
If you initiate account linking mid conversation, then prior to triggering the account linking process you must explain why you are prompting the user to link their account.
Don't request any OAuth scope from Google unless the user is signing in to your service using Google Sign-In. Don't encourage users to agree to additional Google OAuth scopes by directing them to a website or Action.
Device and network abuse
We don't allow Actions that interfere with, disrupt, damage, or access in an unauthorized manner the user's device or other devices, computers, servers, networks, application programming interfaces (APIs), or services. This includes other Actions, any Google service, and the device's network.
We don't allow Actions that steal data, secretly monitor or harm users or that are otherwise malicious.
All Actions that collect user data must comply with the User data policy and fully disclose their functions.
The following are explicitly prohibited:
- Viruses, trojan horses, malware, spyware, and any other malicious software.
- Promoting or facilitating the distribution or installation of malicious software.
- Introducing or exploiting security vulnerabilities.
- Stealing a user's authentication information (such as usernames or passwords).
- Tricking users into disclosing personal or authentication information.
- Running other Actions without the user's prior consent.
- Secretly collecting device usage.
Actions and their listings on the directory must not provide any means to activate or access functionality that violate these terms.
If your Action is associated with a security vulnerability that could be exploited to compromise another Action, application, device, or service, we may remove it to protect users.
Monetization and Ads
No in-conversation ads are permitted.
Naming, Directory Listing, and Promotion
Your Action’s invocation name and Actions directory listing is how users interact with and discover Actions. Your Action's listing dramatically affects the directory's quality, so avoid spammy listings, low quality promotion, and anything that artificially boosts your Action's visibility. Fill out all of the details required for the directory listing, including providing visible, non-blank icons.
Your Action’s directory listing (including name, descriptions, etc.) must comply with the Prohibited Content and Intellectual Property policies and not include words that are vulgar, sexually explicit, or offensive.
All Actions must have a unique invocation name that will allow users to trigger the Action's functionality. Action names are unique within each language, so once a name is approved, no other Action can register the same name in the same language. Your directory listing must have at least one sample invocation, all of which must include your Action’s name, for example "Talk to Google Shopping," and consistently triggers your Action.
Names must meet the following requirements:
- One-word names are not allowed, unless the name is unique to your brand or trademark within the target country. Instructions to request an exception for individual countries are below. Compound words broken into multiple words will not circumvent this requirement, for example key board counts as one word.
- Two-word names are not allowed if one of the words is a definite article (the), indefinite article (a or an), pronoun (like my), or preposition (for, to, or of). For example, your name should not be a bicycle, an espresso, to amuse or for fun.
- A name uniquely identifies your Action, so it must distinguish itself from other Actions and from features of the Assistant. We don’t allow names that are:
- Common phrases (for example, thank you, how are you?, good morning)
- Confusingly similar with features of the Assistant (especially with home automation, device control, and media playback commands)
- Potentially confusing users into thinking they are interacting with Google or that Google is promoting, endorsing, or sponsoring content featured in the Action.
- Generic, including words or phrases that are categories of products, services, or content. We will consider exceptions to this prohibition on a case-by-case basis. Instructions to request an exception are below.
- Names of people or places are not allowed unless they also contain other words (for example, Bill's horoscope or New York tourism) or you are a government agency of that location (for example, the City of New York can register the name New York City).
- Some words and phrases are reserved and cannot be used in names, including, ok, Google, launch, ask, tell, load, exit quit, volume up, game, action, assistant, and app. Test your name in the API dashboard to confirm it doesn't use a reserved word or phrase. We may make exceptions for certain reserved words or phrases if used in a qualifying multi-word combination, if the name isn’t confusing, and if it doesn’t otherwise violate these policies. Instructions to request an exception are below.
- Depending on the language, some characters may be prohibited in the name pronunciation field; for example, languages using the Latin alphabet must contain only lower-case alphabetic characters, spaces between words, possessive apostrophes (for example, Sam's science trivia), or periods used in abbreviations (for example, a. b. c.). Other characters such as numbers must be spelled out, for example, twenty one.
- Names must be easy to pronounce correctly and be phonetically distinct to avoid being misinterpreted as similar sounding words and other Action names (within the same language). Don't use names that are phonetically similar to ones prohibited by these policies, such as vulgar, offensive, generic, or common names (even if spelt them differently).
In evaluating these policies, we consider the pronunciation of the word, how it’s spelled in the console, and the commonly accepted way to spell the pronounced word (if there is one).
We will consider exceptions to certain naming policies on a case-by-case basis; you can request an exception filling out this form And requesting an Action Name Whitelist.
Your Action's invocation name must be a phonetic version of its display name. The only permitted differences are: punctuation, spaces, and using numerals vs. spelling out numbers and ordinals (such as three vs. 3 or third vs. 3rd).
The description of your Action must accurately describe its functionality and the services or content it provides. Here are a few best practices for writing a description of your Action:
- Provide a clear, succinct description of how your Action can help users, for example, "You can use this Action to do X." Excessive length, detail, or repetition in your Action description can result in a violation of this policy.
- Highlight what's great about your Action. Share interesting and exciting facts about to help users understand what makes your Action special.
- Make sure that your Action's title and description accurately describes its functionality.
- Avoid using excessive, repetitive, or unrelated keywords or references.
- Disclose whether your Action requires payment for any of its features.
User testimonials are not allowed in the Action's description.
We don't allow Actions that directly or indirectly engage in or benefit from promotional practices that are deceptive or harmful to users or the developer ecosystem. This includes Actions that engage in the following behavior:
- Using deceptive ads on websites, Actions, or other properties, including notifications that are similar to system notifications and alerts.
- Manipulating or inflating usage statistics, and product ratings, ranking or reviews.
- Engaging in unsolicited promotion via SMS services.
- Offering compensation for using Actions, including money, digital or physical goods.
It is your responsibility to ensure that any ad networks or affiliates associated with your Action comply with these policies and do not employ any prohibited promotion practices.
Actions for Families
Actions targeting children under 13 or providing content explicitly for children under 13 are only allowed as part of the Actions for Families program. This includes Actions designed for use by mixed audiences that include children under the age of 13. Currently, Actions for Families program is only available in the United States, Canada, United Kingdom, France, Italy, Germany, Australia, and Japan.
Actions participating in the Actions for Families program must meet the eligibility criteria in this section and comply with the Terms of Service for Actions on Google, including the Actions for Families Addendum.
Actions on Google reserves the right to reject or remove any Action determined to be inappropriate for the program.
- Actions must be generally suitable for all ages including children under the age of 13 and not contain any inappropriate material, including adult themes, crude humor, and violent content.
- Actions must be designed for mixed audiences that include children under the age of 13. We cannot allow Actions into the Actions for Families program that are primarily designed for children under the age of 13.
- The primary purpose of the Action cannot be:
- To widely share unmoderated user-generated content, such as a social networking or user-forum Action, or
- To serve as a general utility, client, or communication Action, such as calculator, podcasting, home automation or reminder Actions.
Actions may not collect or solicit any personally identifiable user data.
Actions must not contain ads, including in streaming media. Self-promotional messages are acceptable.
Actions may not use Google sign-in (account linking), request OAuth scopes, access most user data APIs (except for coarse device location), or access any transaction APIs.
You represent that apps submitted to the Apps for Families program are compliant with COPPA (Children's Online Privacy Protection Rule) in the US, the EU General Data Protection Regulation, and other relevant statutes in Canada, United Kingdom, France, Italy, Germany, Australia, and Japan, including any APIs that your Action uses to provide the service.
Actions accepted to the Actions for Families program are required to continue to meet the program’s standards at all times, including in subsequent updates.
To ensure a great user experience, your Action must operate as described, provide a high-quality user experience, and take advantage of the platform's features.
Actions should follow the guidance for Conversation Design. Actions that significantly deviate from the user-interface design guidance or have poor user experiences may be disabled from specific surfaces, be rejected, or removed from the directory, including for:
- Suggesting the Action supports a larger scope of commands than it actually does, within the conversation or directory listing.
- For example, if the Action says "Ask me anything," but the Action can only answer the question "Who is president of the United States?".
- Listening for a user command without prompting the user.
- For example, if the Action answers a user's question and then starts to listen for an additional command without any prompt to the user suggesting a command or asking question.
- Failing to function properly on all Assistant-enabled devices that support the Action’s required capabilities.
- For example, if the Action functions on the Google Home device but not on the mobile device.
- Playing a silent sound file without a clear purpose.
- For example, if the Action opens and plays a silent sound file with no explanation.
- Misusing interaction features on Assistant-enabled devices.
- For example, triggering the Google Home LED lights outside of their intended purpose noted here.
- Continuously playing text-to-speech or recorded audio for longer than 120 seconds unless using the Media Response API.
- Having broken links or images.
- Failing to provide alternate text and voice for images in non-graphical interfaces.
- Audio not matching visual text and via text-to-speech in graphical interfaces.
- Registering or creating misleading or irrelevant intents to your Action.
- For example, selecting a built-in intent for ‘Order a Taxi’ when your Action provides weather information.
- Including unnecessary descriptive words, such as adjectives, adverbs, or ambiguous terminology in suggestion chips.
- For example, ‘Buy Best Pizza’ or ‘Try your luck’.
In addition, we reserve the right to reject Actions on the basis of content or functionality that are not explicitly prohibited by these policies, but that run contrary to these policies in spirit. In the event that your Action is rejected or removed under this section, we pledge to provide an explanation of our decision.
Special Requirements for Certain Use Cases
Certain APIs have special requirements, if your Action uses them, then it must also comply with those requirements.
All Actions must comply with these requirements:
Don’t expressly direct users to a website or mobile Action to complete a transaction. For example, don’t tell a user to visit a site, Action, or physical location (or provide a linkout chip) with a call-to-action to checkout, pay, or make a reservation.
If your Action enables users to complete a transaction, it must implement the Transactions API and comply with all of the below requirements. A transaction includes any agreement between a user and a business to fulfill a good or service, such as buying or selling products, providing a service, or making reservations or booking. This does not include adding items to a basket.
Transactions API Requirements
All Actions implementing the Transactions API must comply with these requirements:
Abide by the Transaction Terms in the Terms of Service for Actions on Google.
Offer your service in one of the following countries; United States, Canada, United Kingdom, Germany, France, Australia or Japan. Currently, the Transactions API is not available elsewhere.
Provide transactions related to real-world, physical goods and services. We currently don’t support transactions related to software, virtual goods and services, and donations.
Implement all of the required methods and parameters, including proper order handling and acknowledgements, and don’t create duplicate orders.
Implement all required callback APIs related to providing transaction status updates within the specified time periods, and any follow-up actions.
For transactions that involve any type of payment or money transfer, provide an accurate and itemized receipt to all users by email and correctly set all related parameters.
Only use personal information obtained via the conversational interface to facilitate that transaction, including sending receipts, confirmations, and updates. You must independently obtain the user’s consent (via an opt-in) to use that information for any other purpose, including marketing.
Provide accurate and timely information, including receipts, prices, descriptions, and fulfillment details.
Provide your own customer service, and provide a customer service contact phone number and/or email address.
Developers using Direct Actions (including the Food Order Direct Action API) must also comply with these requirements.
If you provide us with catalogs, menus, or other data via a data feed or other mechanism, the data must comply with these policies, including the sections on Prohibited Content and Intellectual Property. You must correctly implement all technical requirements and provide content for all required fields. The data provided must be relevant to the use case of feed and accurate. We may disable the feed (or a portion of it), disable use of the data, or takedown any related Actions for violations of these policies or if they create a poor user experience.
Actions controlling smart devices must ensure minimum security and safety precautions when the Action can:
- Unlock doors or disable physical security mechanisms.
- For example, unlocking car doors.
- Disarm or disable security or surveillance systems.
- For example, turning off a house alarm system.
- Operate devices that are capable of causing physical harm.
- For example, a cooking stove.
While the nature of the security and safety precautions may vary by the type of device, at minimum these devices must require account linking and a secondary user verification, such as confirmation on a secured mobile device or a password/PIN.
Security or surveillance Actions must not log PII of individuals outside the primary user without their consent. For example, doorbell Actions cannot log information about who may be at the door without the express consent of that individual.
We do not allow Actions that instruct motorized vehicles to move. For example, automobiles and lawn mowers.
These policies do not limit or amend any terms of service or other agreements that apply to the user's use of the applicable Google products or services, unless the policies expressly state that they are amending specific terms of service or agreements.
- 7/17/2018- Added a security vulnerability policy, and made small amendments to the Promotions policy, Transactions policy, Name requirements, and User Experience policy. In addition, we added an additional introductory language specifying our approach to enforcing our policies and developer communications.
- 5/22/2018- Amended the Violence and Dangerous Activities policy to prohibit Actions that facilitate the sale of explosives, weapons, firearms, and related components. We also expanded the availability of the Actions for Family program to include the United Kingdom, France, Italy, Germany, and Japan.
- 3/27/2018 - Several new policies were added, including a Financial Services policy and Alcohol & Tobacco policy. The Home Automation policy was expanded and re-named the Smart-Enabled Devices policy. Re-formatting or minor changes were made to the Health policy, Transactions policy, User Data policy, and User Experience policy.
- 2/1/2018 - User Experience, User-generated Content, Mature content, User Data (privacy), Update API (in spam policy), Emergency services apps policy added.
- 10/4/2017 - The Illegal Activities, Health, Account Linking, Name Requirements, and Transactions sections were updated. The Children section was replaced with the new Apps for Families section.
- 5/17/2017 - Changes were made to address several new features, including transactions, visual user interfaces, and smart home integrations. We added a policy relating to mature content warnings and clarified parts of the Naming, Directory Listing, and Promotion and User Experience sections.
- 2/8/2017 - The Gambling, Other Restrictions, and User Experience sections were updated. Several policies were updated and consolidated under the new Naming, Store Listing, and Promotion section. There were also miscellaneous non-substantive changes.