Every Play app completes the Data safety form and links a privacy policy. In Google's terms, data is collected when it leaves the device, whether your code or a library's sends it, and shared when it goes to a third party. Data used only on the device isn't declared, nor is data processed ephemerally, held in memory just long enough to answer one request. Start from the permissions in the release manifest, which show what the app could reach:
APK=android/app/build/outputs/apk/release/app-release.apk
aapt2 dump permissions $APK | grep -c "uses-permission"
aapt2 dump permissions $APK | grep -o "android\.permission\.[A-Z_]*" | cut -d. -f3 | sort -u \
| paste -sd' ' | fold -s -w 9034 ACCESS_COARSE_LOCATION ACCESS_FINE_LOCATION ACCESS_NETWORK_STATE ACCESS_WIFI_STATE CAMERA FOREGROUND_SERVICE FOREGROUND_SERVICE_MEDIA_PLAYBACK INTERNET MODIFY_AUDIO_SETTINGS POST_NOTIFICATIONS READ_APP_BADGE RECEIVE_BOOT_COMPLETED USE_BIOMETRIC USE_FINGERPRINT VIBRATE WAKE_LOCK
Most of the 34 come from libraries' manifests, 16 of them launcher-badge permissions for other vendors' home screens. Then trace what each feature sends:
| Feature (section) | Data sent off the device | Form entry |
|---|---|---|
| Checkout (Forms and Validation) | Name, email, street address | Personal info: collected, for app functionality |
| Orders, sign-in (3.18, Authentication) | Books ordered, account name | Purchase history; user IDs |
| Push (Push Notifications) | Expo 6,418 push token | Device or other IDs |
| Cover upload (Camera and Media) | A photo the reader picks | Photos and videos: collected, optional |
| Store locator (Maps and Location) | Nothing: distances are computed on the device | Not declared |
The location permissions serve the store locator, but BookNest sorts the shops on the device, so its own code collects no location; the Google Maps 1 SDK behind react-native-maps 15,999 has its own Data safety guidance, which you must read too. The form also asks about encryption in transit: the release allows plain HTTP to 10.0.2.2 only because the Detox 12,028 plugin's network_security_config.xml permits it, so a store build points EXPO_PUBLIC_API_URL at an HTTPS server and drops that plugin.