SDKBox collects personally identifiable information (PII) without disclosure

Hello!
Yesterday I received a letter from Google:

We detected that the app(s) listed at the end of this email contain a
version of SDKBox that collects personally identifiable information
(PII) without disclosure. Apps like this may be considered in violation
of our User Data policy.

Action required: Your app(s) may be removed from
Google Play if the issue is not resolved within 10 days of receiving
this message. If the affected version is inactive, future submissions
will be rejected if you attempt to publish without first resolving the
issue.

You can resolve this issue by:

adding a privacy policy URL to your app listing and within the app, notifying the user that their PII is collected; orremoving any such functionality from your app. You may need to
contact your SDK provider for an updated, policy compliant version to
include in your app.

After resolving the issue, you’ll need to sign in to your Developer Console and submit the updated version of your app.

We’re here to help
If you feel we have sent this warning in error, you can contact our developer support team.

Regards,

The Google Play Team"

Someone received such a letter? What I need to do?
Please help to solve the problem, thank you!

@uapp__ukraine

Try update your SDKBOX to latest version, 2.2.4.14

Really sorry about that, it was a issue we fixed on 2.2.2.12 however got reintroduced in 2.2.3, please update to the latest version.

Thank you!
Today I will update.

Thank you!

Today I received the following letter:

Hello Google Play Developer,

On July 7, we notified you that your app(s) contain a version of an
SDK that allows the collection of personally identifiable information
(PII). When collecting PII, proper disclosure is required for your app
to be compliant with Google Play policy.

If your app does not currently request the GET_ACCOUNTS permission in the app manifest, no further action is required. If you’ve removed this permission from your app manifest, you can sign in to your Developer Console and submit the app again.

If you wish to continue collecting user account data:

You must add a privacy policy URL to your app listing and notify the user their PII is being collected within the app.

Beginning July 18th, we will reject any updates that are not
compliant with the above requirements, but your live app will remain on
Google Play. To allow you time to submit a compliant version, we will
only remove non-compliant apps starting August 8th.

If you’ve reviewed the policy and feel this warning may have been in error, you can contact our developer support team.

Sincerely,

The Google Play Team

©2016 Google Inc. 1600 Amphitheatre Parkway, Mountain View, CA 94043

Email preferences: You have received this mandatory email service
announcement to update you about important changes to your Google Play
Developer account.

What I need to do?

You have to upgrade SDKBOX to the 2.2.4 version and resubmit your app.

I’m using SDKBOX 2.3.1.1 and Google deleted my app with following email

SDKBox

Your app(s) contain a version of SDKBox that allows the collection of personally identifiable information (PII).

If you wish to continue collecting user account data, read through the Personal and Sensitive Information policy and add a privacy policy URL to your Store Listing.

Sorry this happened to your game, we verified with google that SDKBOX should be complaint with their policy, But sometimes the update process somehow didn’t update sdkbox.jar

Can you download the latest sdkbox package and replace sdkbox.jar with the latest version?

Did your app pass the review after update?