Microsoft Store Policies
Document version: 7.9
Document date: August 6, 2018
For a summary of recent changes to this agreement, see Change history.
Thank you for your interest in developing apps for the Microsoft Store1. We’re committed to a diverse catalog of apps for customers worldwide. Apps on the Store must meet our certification standards, offer customers a truly useful and engaging experience, and provide a good fit for the Store.
A few principles to get you started:
- Offer unique and distinct value within your app. Provide a compelling reason to download your app from the Store.
- Don’t mislead our joint customers about what your app can do, who is offering it, etc.
- Don’t attempt to cheat customers, the system or the ecosystem. There is no place in our Store for any kind of fraud, be it ratings and review manipulation, credit card fraud or other fraudulent activity.
Adhering to these policies should help you make choices that enhance your app’s appeal and audience.
Your apps are crucial to the experience of hundreds of millions of customers. We can’t wait to see what you create and are thrilled to help deliver your apps to the world.
If you have feedback on the policies, please let us know by commenting in our forum. We will consider every comment.
Table of Contents
- 10.1 Distinct Function & Value; Accurate Representation
- 10.2 Security
- 10.3 App is Testable
- 10.4 Usability
- 10.5 Personal Information
- 10.6 Capabilities
- 10.7 Localization
- 10.8 Financial Transactions
- 10.9 Notifications
- 10.10 Advertising Conduct and Content
- 10.11 Mobile Voice Plans
- 10.12 Edge Extensions
- 10.13 Gaming and Xbox
- 10.14 Account Type
- 11.1 General Content Requirements
- 11.2 Content Including Names, Logos, Original and Third Party
- 11.3 Risk of Harm
- 11.4 Defamatory, Libelous, Slanderous and Threatening
- 11.5 Offensive Content
- 11.6 Alcohol, Tobacco, Weapons and Drugs
- 11.7 Adult Content
- 11.8 Illegal Activity
- 11.9 Excessive Profanity and Inappropriate Content
- 11.10 Country/Region Specific Requirements
- 11.11 Age Ratings
10.1 Distinct Function & Value; Accurate Representation
Your app and its associated metadata must accurately and clearly reflect the source, functionality, and features of your app.
All aspects of your app should accurately describe the functions, features and any important limitations of your app, including required or supported input devices. Your app may not use a name or icon similar to that of other apps, and may not claim to be from a company, government body, or other entity if you do not have permission to make that representation.
Your app must be fully functional and must provide appropriate functionality for each targeted device family, file type and protocol.
Search terms may not exceed seven unique terms and should be relevant to your app.
Your app must have distinct and informative metadata and must provide a valuable and quality user experience. Your app must also have an active presence in the Store.
Your app must not jeopardize or compromise user security, or the security or functionality of the device, system or related systems.
Your app must not attempt to change or extend the described functionality through any form of dynamic inclusion of code that is in violation of Store Policies. Your app should not, for example, download a remote script and subsequently execute that script in a manner that is not consistent with the described functionality.
Your app must not contain or enable malware as defined by the Microsoft criteria for Unwanted and Malicious Software.
Your app may contain fully integrated middleware (such as third-party cross-platform engines and third-party analytics services), but must not deliver or install non-integrated third-party owned or branded apps or modules unless they are fully contained in your app package.
Your app may depend on non-integrated software (such as another app or module) to deliver its primary functionality, subject to the following requirements:
- You disclose the dependency at the beginning of the description metadata
- The dependent software is available in the Store
All of your apps and in-app products that are available for purchase from the Store must be installed and updated only through the Store.
10.3 App is Testable
The app must be testable. If it is not possible to test your app for any reason, including, but not limited to, the items below, your app may fail this requirement.
If your app requires login credentials, provide us with a working demo account using the Notes to Tester field.
If your app requires access to a server, the server must be functional to verify that it's working correctly.
If your app allows a user to add a gift card balance, give us a gift card number that can be used in the testing.
Your app must meet Store standards for usability, including, but not limited to, those listed in the subsections below.
The app must run on devices that are compatible with the software, hardware and screen resolution requirements specified by the application. If an app is downloaded on a device with which it is not compatible, it should detect that at launch and display a message to the customer detailing the requirements.
Apps must continue to run and remain responsive to user input. Apps must shut down gracefully and not close unexpectedly. The app must handle exceptions raised by any of the managed or native system APIs and remain responsive to user input after the exception is handled.
The app must start up promptly and must stay responsive to user input.
Where applicable, pressing the back button should take the user to a previous page/dialog. If the user presses the back button on the first page of the app, then the app terminates (unless it is allowed to run in the background).
10.5 Personal Information
The following requirements apply to apps that access personal information. Personal information includes all information or data that identifies or could be used to identify a person, or that is associated with such information or data. Examples of personal information include: name and address, phone number, biometric identifiers, location, contacts, photos, audio & video recordings, documents, SMS, email, or other text communication, screenshots, and in some cases, combined browsing history.
Additionally, apps that receive device location must provide settings that allow the user to enable and disable the app's access to and use of location from the Location Service API. For Windows Phone 8 and Windows Phone 8.1 apps, these settings must be provided in-app. For Windows Mobile 10 apps, these settings are provided automatically by Windows within the Settings App (on the Settings > Privacy > Location page).
You may publish the personal information of customers of your app to an outside service or third party through your app or its metadata only after obtaining opt-in consent from those customers. Opt-in consent means the customer gives their express permission in the app user interface for the requested activity, after you have:
- described to the customer how the information will be accessed, used or shared, indicating the types of parties to whom it is disclosed, and
- provided the customer a mechanism in the app user interface through which they can later rescind this permission and opt-out.
If you publish a person’s personal information to an outside service or third party through your app or its metadata, but the person whose information is being shared is not a customer of your app, you must obtain express written consent to publish that personal information, and you must permit the person whose information is shared to withdraw that consent at any time. If your app provides a customer with access to another person’s personal information, this requirement would also apply.
If your app collects, stores or transmits personal information, it must do so securely, by using modern cryptography methods.
The capabilities you declare must legitimately relate to the functions of your app, and the use of those declarations must comply with our app capability declarations. You must not circumvent operating system checks for capability usage.
For more information about app capability declarations, see App capability declarations.
You must localize your app for all languages that it supports. The text of your app’s description must be localized in each language that you declare. If your app is localized such that some features are not available in a localized version, you must clearly state or display the limits of localization in the app description. The experience provided by an app must be reasonably similar in all languages that it supports.
10.8 Financial Transactions
If your app includes in-app purchase, subscriptions, virtual currency, billing functionality or captures financial information, the following requirements apply:
You must use the Microsoft Store in-app purchase API to sell digital items or services that are consumed or used within your app. Your app may enable users to consume previously purchased digital content or services, but must not direct users to a purchase mechanism other than the Microsoft Store in-app purchase API.
In-app products sold in your app cannot be converted to any legally valid currency (e.g. USD, Euro, etc.) or any physical goods or services.
You must use the Microsoft payment request API or a secure third party purchase API for purchases of physical goods or services, and a secure third party purchase API for payments made in connection with real world gambling or charitable contributions. If your app is used to facilitate or collect charitable contributions or to conduct a promotional sweepstakes or contest, you must do so in compliance with applicable law. You must also state clearly that Microsoft is not the fundraiser or sponsor of the promotion.
The following requirements apply to your use of a secure third party purchase API:
- At the time of the transaction or when you collect any payment or financial information from the customer, your app must identify the commerce transaction provider, authenticate the user, and obtain user confirmation for the transaction.
- The app can offer the user the ability to save this authentication, but the user must have the ability to either require an authentication on every transaction or to turn off in-app transactions.
- If your app collects credit card information or uses a third-party payment processor that collects credit card information, the payment processing must meet the current PCI Data Security Standard (PCI DSS).
If your app accesses financial account information, you must submit that app from a company account type.
Your app and its associated metadata must provide information about the types of in-app purchases offered and the range of prices. You may not mislead customers and must be clear about the nature of your in-app promotions and offerings including the scope and terms of any trial experiences. If your app restricts access to user-created content during or after a trial, you must notify users in advance. In addition, your app must make it clear to users that they are initiating a purchase option in the app.
Your app may promote or distribute software only through the Microsoft Store.
You must use the Microsoft recurring billing API to bill for subscriptions of digital goods or services, and the following guidelines apply:
- You may add value to a subscription but may not remove value for users who have previously purchased it.
- If you discontinue an active subscription, you must continue to provide purchased digital goods or services until the subscription expires.
Your app must respect system settings for notifications and remain functional when they are disabled. This includes the presentation of ads and notifications to the customer, which must also be consistent with the customer’s preferences, whether the notifications are provided by the Microsoft Push Notification Service (MPNS), Windows Push Notification Service (WNS) or any other service. If the customer disables notifications, either on an app-specific or system-wide basis, your app must remain functional.
If your app uses MPNS or WNS to transmit notifications, it must comply with the following requirements:
Because notifications provided through WNS or MPNS are considered app content, they are subject to all Store Policies.
You may not obscure or try to disguise the source of any notification initiated by your app.
You may not include in a notification any information a customer would reasonably consider to be confidential or sensitive.
Notifications sent from your app must relate to the app or to other apps you publish in the Store catalog, may link only to the app or the Store catalog listing of your other apps, and may not include promotional messages of any kind that are not related to your apps.
10.10 Advertising Conduct and Content
For all advertising related activities, the following requirements apply:
- The primary purpose of your app should not be to get users to click ads.
- Your app may not do anything that interferes with or diminishes the visibility, value, or quality of any ads it displays.
- Your app must respect advertising ID settings that the user has selected.
If you purchase or create promotional ad campaigns to promote your apps through the “Promote Your App” capability in Dev Center, all ad materials you provide to Microsoft, including any associated landing pages, must comply with Microsoft’s Creative Specifications Policy and Creative Acceptance Policy.
Any advertising content your app displays must adhere to Microsoft’s Creative Acceptance Policy.
If your app displays ads, all content displayed must conform to the advertising requirements of the App Developer Agreement, including the following requirements:
The primary content of your app may not be advertising, and advertising must be clearly distinguishable from other content in your app.
If your app is directed at children under the age of 13 (as defined in the Children’s Online Privacy Protection Act), you must notify Microsoft of this fact in Dev Center and ensure that all ad content displayed in your app is appropriate for children under the age of 13.
10.11 Mobile Voice Plans
Your app may not sell, link to, or otherwise promote mobile voice plans.
10.12 Edge Extensions
Edge Extensions are subject to these additional requirements:
- Your Extension must have a single purpose with narrowly scoped functionality that is clearly explained in the product description.
- Your Extension may collect personal information only as part of a prominently disclosed, user-facing feature.
- If your Extension collects web browsing activity, it must do so only if required by and only for use in a prominently disclosed, user-facing feature.
- The Extension must not programmatically alter, or appear to alter, browser functionality or settings including, but not limited to: the address bar search provider and suggestions, the start or home page, the new tab page, and adding or removing favorites and reading list items.
10.13 Gaming and Xbox
For apps that are primarily gaming experiences or target Xbox One, the following requirements apply:
Games that allow cross-player communication or synchronous network play on Xbox One devices must use Xbox Live and be approved through the ID@Xbox program.
Games on Xbox One must not present an alternate friends list obtained outside Xbox Live.
Apps published to Xbox One must not:
- Include the sale of Xbox games, Xbox consoles or Xbox console accessories outside the Store.
- Request or store Microsoft Account usernames or passwords.
Games that use Xbox Live must:
- Automatically sign the user in to Xbox Live, or offer the user the option to sign in, before gameplay begins.
- Display the user's Xbox gamertag as their primary display and profile name.
Games that use Xbox Live and offer multiplayer gameplay, user generated content or user communication:
- Must not allow gameplay until the user signs in to Xbox Live.
- Must respect parental and service controls.
Games must gracefully handle errors with or disconnection from the Xbox Live service. When attempting to retry a connection request following a failure, games must honor the retry policies set by Xbox Games. When they are unable to retrieve configuration information for or communicate with any non-Microsoft service, games must not direct users to Microsoft support.
Games must not store user information sourced from Xbox Live, such as profile data, preferences, or display names, beyond a locally stored cache used to support loss of network connectivity. Any such caches must be updated on the next available connection to the service.
Xbox Live games must comply with the following requirements for service usage:
- Do not link or federate the Xbox Live user account identifier or other user account data with other services or identity providers.
- Do not provide services or user data in a way that it could be included in a search engine or directory.
- Keep your secret key and access tokens private, except if you share them with an agent acting to operate your app and the agent signs a confidentiality agreement.
- Do not duplicate the Xbox Live Friends service.
Apps that emulate a game system are not allowed on any device family.
The following privacy requirements apply to Xbox Live user data:
- Services and user data are only for use in your game by you. Don't sell, license, or share any data obtained from us or our services. If you receive personal data of end users through Xbox Live, you are an independent controller of such data and must have a privacy statement (or policy) in place with end users governing your use of personal data, as required by the Application Developer Agreement. We recommend you include a link to your privacy statement on your website and on the Microsoft Store pages for your games.
- Services and user data must be used appropriately in games. This data includes (without limitation) usage data, account identifiers and any other personally identifiable data, statistics, scores, ratings, rankings, connections with other users, and any other data relating to a user’s social activity.
- Don’t store any Xbox Live social graph data (e.g., friends lists), except for account identifiers for users who’ve linked their Xbox Live account with your game.
- Delete all account identifiers, when you remove your game from our service, or when a user unlinks their Xbox Live account from your game. Do not share services or user data (even if anonymous, aggregate, or derived data) to any ad network, data broker or other advertising or monetization-related service.
- When Microsoft receives requests from end users to delete their personal data, we will communicate the requests to you by providing a list of end user identifiers. You must check the list at least every 30 days to ensure you receive all delete requests and must use the information provided on the list only to satisfy the delete requests of end users. You can find details about this process at Deleted Account List Tools.
10.14 Account Type
Beginning April 17, 2018, newly published apps that require authentication to access primary functionality must use a secure dedicated third party authentication provider or be published from a company account type. Note that all apps must use a company account if they access financial account information as described in policy 10.8.3.
The following policies apply to content and metadata (including publisher name, app name, app icon, app description, app screenshots, app trailers and trailer thumbnails, and any other app metadata) offered for distribution in the Store. Content means the app name, publisher name, app icon, app description, the images, sounds, videos and text contained in the app, the tiles, notifications, error messages or ads exposed through your app, and anything that’s delivered from a server or that the app connects to. Because apps and the Store are used around the world, these requirements will be interpreted and applied in the context of regional and cultural norms.
11.1 General Content Requirements
Metadata and other content you submit to accompany your app may contain only content that would merit a rating of PEGI 12, ESRB EVERYONE 10+, or lower.
11.2 Content Including Names, Logos, Original and Third Party
All content in your app and associated metadata must be either originally created by the application provider, appropriately licensed from the third-party rights holder, used as permitted by the rights holder, or used as otherwise permitted by law.
11.3 Risk of Harm
Your app must not contain any content that facilitates or glamorizes the following real world activities: (a) extreme or gratuitous violence; (b) human rights violations; (c) the creation of illegal weapons; or (d) the use of weapons against a person, animal, or real or personal property.
Your app must not: (a) pose a safety risk to, nor result in discomfort, injury or any other harm to end users or to any other person or animal; or (b) pose a risk of or result in damage to real or personal property. You are solely responsible for all app safety testing, certificate acquisition, and implementation of any appropriate feature safeguards. You will not disable any platform safety or comfort features, and you must include all legally required and industry-standard warnings, notices, and disclaimers in your app.
11.4 Defamatory, Libelous, Slanderous and Threatening
Your app must not contain any content that is defamatory, libelous, slanderous, or threatening.
11.5 Offensive Content
Your app and associated metadata must not contain potentially sensitive or offensive content. Content may be considered sensitive or offensive in certain countries/regions because of local laws or cultural norms. In addition, your app and associated metadata must not contain content that advocates discrimination, hatred, or violence based on considerations of race, ethnicity, national origin, language, gender, age, disability, religion, sexual orientation, status as a veteran, or membership in any other social group.
11.6 Alcohol, Tobacco, Weapons and Drugs
Your app must not contain any content that facilitates or glamorizes excessive or irresponsible use of alcohol or tobacco products, drugs, or weapons.
11.7 Adult Content
Your app must not contain or display content that a reasonable person would consider pornographic or sexually explicit.
11.8 Illegal Activity
Your app must not contain content or functionality that encourages, facilitates or glamorizes illegal activity in the real world.
11.9 Excessive Profanity and Inappropriate Content
- Your app must not contain excessive or gratuitous profanity.
- Your app must not contain or display content that a reasonable person would consider to be obscene.
11.10 Country/Region Specific Requirements
Content that is offensive in any country/region to which your app is targeted is not allowed. Content may be considered offensive in certain countries/regions because of local laws or cultural norms. Examples of potentially offensive content in certain countries/regions include the following:
- Prohibited sexual content
- Disputed territory or region references
- Providing or enabling access to content or services that are illegal under applicable local law
11.11 Age Ratings
You must obtain an age rating for your app or game when you submit it in Dev Center. You are responsible for accurately completing the rating questionnaire to obtain the appropriate rating.
If your app provides content (such as user-generated, retail or other web-based content) that might be appropriate for a higher age rating than its assigned rating, you must enable users to opt in to receiving such content by using a content filter or by signing in with a pre-existing account.
1"Store" or "Microsoft Store" means a Microsoft owned or operated platform, however named, through which Apps may be offered to or acquired by Customers. Unless otherwise specified, Store includes the Microsoft Store, the Windows Store, the Xbox Store, Microsoft Store for Business, and Microsoft Store for Education.