验证您的应用以便与 Google Fit API 搭配使用
使用集合让一切井井有条
根据您的偏好保存内容并对其进行分类。
我们深知,健康与健身数据对用户来说特别敏感。确保数据的安全性和隐私性至关重要。为了确保交换此类数据时的安全性和隐私性,所有 Google Fit API 范围都处于“受限”状态。详细了解如何请求访问受限的 OAuth 范围。
您需要做些什么?
何时需要申请验证?
- 如果您要向应用添加新的 Google 健身范围,请按照说明为受限范围验证做好准备。
- 对于现有应用,请等待 Google 团队与您联系,他们将为您提供有关验证流程和后续步骤的更多信息。在此之前,您的应用仍可继续访问其当前访问的数据和范围。
常见问题解答
此政策适用于哪些 Google 健身 API?
此政策同时适用于 REST API 和 Android API。
对于 Google 健身 REST API 和 Android API,已获批准的使用情形有哪些?
Google 健身 REST API 和 Android API 已获批准的使用情形包括:健身和保健、奖励、健身指导、企业健康、医疗护理、健康研究和游戏。获准使用 Google 健身 REST API 和 Android API 的应用不得将其使用情形扩展至未声明或未经允许的用途。
已获批准的使用情形
|
健身与健康
此类应用可让用户使用手机传感器、手动记录日记或参与数字课程和引导式课程,跟踪健身 / 健康状况以及目标达成进度。
|
奖励
此类应用鼓励用户培养并保持健康的习惯以换取奖金。
|
健身指导
此类应用提供线上真人健身指导,以便帮助用户实现健康或健身目标。真人教练有权访问用户数据,以了解进度并提供指导和支持。
|
企业健康
以企业为中心的平台,健康经理能够为员工分发和管理健康计划。
|
医疗护理
此类应用可帮助用户接收和管理临床护理信息。这些应用可能会提供与临床医疗团队交换健康与健身数据的服务,例如专注于糖尿病或高血压等疾病的身体状况管理应用。
|
健康研究
此类应用为用户提供机会捐献自己的数据,以用于健康方面的研究。这类研究通常已获得机构审查委员会 (IRB) 或伦理委员会 (EC) 的批准,并且会在征得用户同意的情况下开展与健康相关的研究。
|
游戏
在此类应用中,用户的健身和/或健康状况影响着游戏进度。这类游戏会收集用户的活动数据,作为推动游戏情节发展的一种方式。
|
应用内披露的数据访问、收集、使用和分享有哪些要求?
应用内披露声明:
- 必须在应用内明示,不得只在应用说明或网站中显示;
- 必须在用户正常使用应用的情况下显示,并且无需用户打开任何菜单或设置就能查看;
- 必须说明要访问或收集的数据类型;
- 必须说明数据的使用和/或分享方式;
- 不得只列在隐私权政策或服务条款中;并且
- 不得包含在其他与 Google 健身数据收集无关的披露声明中。
- 无需明确同意,例如用户表示“接受”或“我了解”,因为这是在紧随其后的运行时提示中完成的;让用户可通过关闭或滑开披露声明而离开声明页面。
建议的披露声明格式:
为符合政策要求,建议您参考以下示例格式:“(本应用)会收集健康与健身数据以支持(“功能”)、(“功能”)和 &(“功能”)。
示例:“Fitness Coach 收集活动数据,以实现分析和个性化指导。”
醒目披露声明还可能包含其他信息,以确保应用符合政策要求并向用户提供明确说明,但在适用情况下必须至少包含上述内容。
审核增强功能在实践中意味着什么?
如果您使用 Fit API,并且拥有超过 100 位用户,我们会在适当时间与您联系,以便开始验证流程。如果您请求对关联的任何读/写运行状况范围的读/写权限,则需要执行安全性评估。这包括您使用 Recording API 和 Sessions API 在 Android 上读取传感器数据(如步数)的情况。
如何查看用户数量是否超过 100?
您可以在 Cloud 控制台中查找您的项目。
我们将通过您在 Cloud 控制台中存储的联系电子邮件地址与您联系,因此请务必及时更新这些信息。
如何确定我的应用是否需要进行安全性评估?
如果您的应用使用关联的任何读/写运行状况范围,并且超出了 100 位用户的上限,则它需要接受安全性评估。在您需要接受验证和安全评估时,我们会单独通知您,并向您发出通知,说明您需要完成验证。如需详细了解所使用的安全标准,请参阅 App Defense Alliance 安全性评估常见问题解答。
如果我的应用需要接受安全性评估,我怎么进行此评估?
当您受邀进行验证时,会向您提供有关如何进行安全性评估的详细信息,并发出适当的通知,以完成验证。
如未另行说明,那么本页面中的内容已根据知识共享署名 4.0 许可获得了许可,并且代码示例已根据 Apache 2.0 许可获得了许可。有关详情,请参阅 Google 开发者网站政策。Java 是 Oracle 和/或其关联公司的注册商标。
最后更新时间 (UTC):2025-08-31。
[null,null,["最后更新时间 (UTC):2025-08-31。"],[[["\u003cp\u003eGoogle Fit API data is sensitive and protected; all scopes are restricted, requiring developers to follow verification steps.\u003c/p\u003e\n"],["\u003cp\u003eDevelopers must adhere to the Google Fit Developer and User Data Policy and address any gaps in their implementation.\u003c/p\u003e\n"],["\u003cp\u003eNew apps adding Google Fit scopes or existing apps with over 100 users will undergo a verification process, ensuring data security and user privacy.\u003c/p\u003e\n"],["\u003cp\u003eClear and prominent in-app disclosures are necessary, explaining data access, usage, and sharing practices related to Google Fit data.\u003c/p\u003e\n"],["\u003cp\u003eApps accessing specific read/write health scopes and exceeding the user threshold may require a security assessment to further enhance data protection.\u003c/p\u003e\n"]]],[],null,["# Verify your app for use with Google Fit API\n\nWe're conscious that health and fitness data is particularly sensitive to\nusers. Ensuring the security and privacy of that data is of utmost importance. To ensure security and privacy during the exchange of this data, all Google Fit API scopes are Restricted. Learn more about [requesting access to restricted OAuth scopes](https://support.google.com/cloud/answer/9110914#sensitive-restricted-scopes).\n\nWhat do you need to do?\n-----------------------\n\n- Read through the [Google Fit Developer and User Data Policy](/fit/policy)\n and address any gaps.\n\n- When you're going through the [OAuth verification process in the Google Cloud\n Platform console](https://console.cloud.google.com/apis/credentials/consent),\n follow the [appropriate verification\n steps](https://support.google.com/cloud/answer/9110914#ver-prep).\n\nWhen do you need to apply for verification?\n-------------------------------------------\n\n- **If you're adding a new Google Fit scope to your app** , follow the instructions to prepare for [restricted scope verification](https://support.google.com/cloud/answer/9110914#sensitive-restricted-scopes&zippy=%2Csteps-for-apps-requesting-sensitive-scopes).\n- **For existing apps**, wait until you're contacted by the Google team who will give you more information on the verification process and next steps. Until then, your app will continue to have access to the data and scopes it currently accesses.\n\nFAQs\n----\n\n### Which Google Fit APIs does the policy apply to?\n\n[The policy](/fit/policy) applies to both the REST and Android APIs.\n\n### What are the approved use cases for the Google Fit REST and Android APIs?\n\nApproved use cases for the Google Fit REST and Android APIs include fitness and wellness, rewards, fitness coaching, corporate wellness, medical care, health research, and games. Applications granted access to the Google Fit REST and Android APIs may not extend its use to undisclosed or non-permitted purposes.\n\n\u003cbr /\u003e\n\n|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|\n| Approved use cases \u003cbr /\u003e |\n| **Fitness and Wellness** \u003cbr /\u003e Applications that allow users to track their fitness / wellness and progress to their goals using phone sensors, manual journalling or participating in digital classes and guided sessions. |\n| **Rewards** \u003cbr /\u003e Applications that encourage users to adopt and maintain healthy habits in exchange for financial rewards. |\n| **Fitness Coaching** \u003cbr /\u003e Applications that feature virtual human fitness coaching helping users to achieve a health or fitness goal. Human coaches have access to user data to check on progress and provide guidance and support. |\n| **Corporate Wellness** \u003cbr /\u003e Enterprise focused platforms that enable wellness managers to distribute and manage wellness programs for employees. |\n| **Medical Care** \u003cbr /\u003e Applications that help users receive and manage clinical care. These applications may provide services that exchange health and fitness data with clinical teams, such as condition management apps focused on medical conditions like diabetes or hypertension. |\n| **Health Research** \u003cbr /\u003e Applications give users the opportunity to donate their data for health research studies. These studies are typically approved by an Institutional Review Board (IRB) or Ethics Committee (EC) and collect user consent for conducting health research. |\n| **Games** \u003cbr /\u003e Applications where a user's progress in a game is influenced or impacted by their fitness and/or wellness. These are games that collect a user's activity data as a way to advance game play. |\n\n### What are the requirements for the in-app disclosure of data access, collection, use, and sharing?\n\nThe in-app disclosure:\n\n- Must be within the app itself, not only in the app description or on a website;\n- Must be displayed in the normal usage of the app and not require the user to navigate into a menu or settings;\n- Must describe the data being accessed or collected;\n- Must explain how the data will be used and/or shared;\n- Cannot only be placed in a privacy policy or terms of service; and\n- Cannot be included with other disclosures unrelated to Google Fit data collection.\n- Does not need explicit consent such as an \"accept\" or \"I understand\" granted by the user as this is done in the runtime prompt that immediately follows; enabling the user to close or swipe away are acceptable ways to migrate out of the disclosure.\n\nRecommended disclosure statement formats:\nTo meet the policy requirements, it's recommended that you reference the following example format:\n\"(This app) collects health and fitness data to enable (\"feature\"), (\"feature\"), \\& (\"feature\").\"\n\nExample: *\"Fitness Coach collects activity data to enable analytics and personalized coaching.\"*\n\nThe prominent disclosure may include other information to ensure compliance to policy requirements and clarity for users but must at least include the above, where relevant.\n\n### What do the review enhancements mean in practice?\n\nIf you access Fit APIs and have more than 100 users, you will be contacted in\ndue course to begin a verification process. If you request read/write access to\nany of the linked\n[read/write health scopes](https://support.google.com/cloud/answer/9110914#sensitive-restricted-scopes),\nyou will also be required to carry out a security assessment. This includes\ncases where you are reading sensor data, such as steps, using the Recording API\nand Sessions APIs on Android.\n\n### How can I check whether I have 100 or more users?\n\nYou can look that up for your project in [Cloud Console](https://console.cloud.google.com/apis/credentials/consent).\n\n### How will I be informed that I need to go through verification?\n\nYou will be contacted via the [contact email addresses that you have stored in\nCloud Console](https://console.cloud.google.com/iam-admin/essential-contacts),\nso please make sure these are kept up to date.\n\n### How do I determine if my app needs a security assessment?\n\nIf your app uses any of the linked\n[read/write health scopes](https://support.google.com/cloud/answer/9110914?#zippy=%2Cwhat-are-restricted-api-scopes),\nand has exceeded the 100-user cap then it will need a security assessment.\nYou will be separately informed that you need to go through verification and\nsecurity assessment, and will be given ample notice to complete it. For more\ninformation about the security standards used, see\n[App Defense Alliance security assessment FAQ](https://appdefensealliance.dev/casa).\n\n### How do I get a security assessment if my app needs one?\n\nWhen you are invited to go through verification, you will be provided with\ndetails of how to get a security assessment with ample notice to complete it."]]