Earlier quoted context omitted.
> Of course I expect to find a privacy policy. If the app store allowed you to specific in app metadata that no data leaves the device, and that was enforced by device policy, I wouldn't expect a privacy policy.
Device policies are actually harder than it may seem (to enforce that no data leaves the device). Here is a comment by a Google employee. It is about the internet access permission, but this part illustrates that side channels exist. > Requests to be able to remove internet access are almost always really requests to “make sure this app can’t get any data off the device.” However, just removing this permission does n…
If an explicit "privacy policy" is required (for legal reasons or w/e), when an app submits "no data to be exfiltrated", the app store could say "here is the privacy policy you're agreeing to follow, no further action required".