Skip to content

Is Google Analytics Allowed in a Chrome Extension? The Web Store Policy Answer

7 min readModerok team

Yes, with conditions. What the Limited Use policy, the Manifest V3 code rules, and Google's own Analytics terms require of an extension.

Yes, Google Analytics is allowed in a Chrome extension, and Google publishes its own guide for wiring it up. What is not allowed is the part most developers reach for first, the gtag.js snippet. Chrome's Use Google Analytics guide says, as of October 2026, "Since Manifest V3, Chrome Extensions are not allowed to execute remote hosted code. This means you have to use the Google Analytics Measurement Protocol for tracking extension events." Three policy obligations then attach the moment data leaves the browser: a posted privacy policy, a Privacy practices disclosure, and data that stays inside your extension's single purpose.

TL;DR: Allowed, with conditions. POST to the GA4 Measurement Protocol instead of loading the tag, because Chrome's Manifest V3 requirements list a <script> tag pointing outside the package as a violation, as of October 2026. Then satisfy the User Data FAQ, as of October 2026: privacy policy posted, Privacy practices tab filled in, collection proportionate. Google's Analytics Terms of Service separately bars passing it anything it "could use or recognize as personally identifiable information," as of October 2026, outside the hashed-data carve-out quoted below.

The 30-second comparison

QuestionWhat the rule saysSource (read October 2026)
Send extension usage data to GA4?Yes: Via the Measurement Protocol, which "lets you send events directly to Google Analytics servers with HTTP requests"Use Google Analytics
Load gtag.js from Google's CDN?No: "Including a <script> tag that points to a resource that is not within the extension's package" is a listed violationManifest V3 requirements
Is analytics a permitted purpose?Yes: Where "reasonably necessary to ... measure the performance and reliability of the extension's disclosed functionality"User Data FAQ
Privacy policy required?Yes: Must "Post a privacy policy in the Chrome Web Store Developer Dashboard"User Data FAQ
Send URLs of pages users visit?Only as "required for a user-facing feature described prominently in the Product's Chrome Web Store page and in the Product's user interface"Limited Use
Send raw email addresses?No: You may not pass Google anything it "could use or recognize as personally identifiable information," except under a GA feature's own terms and "only if" the data "is hashed using industry standards"Analytics Terms of Service
A GA property for store-listing traffic?Yes: Opt in from the Developer Dashboard. "Data retention is set to two months."Web Store and Google Analytics

Round 1The code rule bans the tag, not the data

The Manifest V3 requirements page frames this as a reviewability rule, not a privacy one. As of October 2026 it says "the full functionality of an extension must be easily discernible from its submitted code" and that external resources "must not contain any logic."

A fetch() to https://www.google-analytics.com/mp/collect loads no logic. It posts JSON and ignores the response. That is why the Measurement Protocol survives review while the tag does not, and why smuggling gtag.js into a popup or content script does not help: the violation is the external <script> tag, not the context around it. The page does exempt "contexts that are isolated from extension APIs (such as iframes and sandboxed pages)" from the remote-code restriction, while adding that "the interaction must still comply with our user data policies, including Limited Use and the extension's Privacy Policy."

Winner

The Measurement Protocol. It is what Chrome's extension guide tells an MV3 extension to use, as of October 2026.

Round 2What the Chrome Web Store policy says about Google Analytics in a Chrome extension

Once data is leaving the browser, Limited Use decides compliance. Two clauses matter, both as of October 2026.

The scope rule: "Extensions may only collect, use, or transmit user data that is necessary for the extension's disclosed single purpose, including related operational purposes, such as maintaining, securing, or measuring the performance and reliability of those features." Product analytics can sit inside that carve-out, and the User Data FAQ attaches three duties to it, as of October 2026: "Clearly disclose the data collection to users", "Limit collection to data that is proportionate to the stated purpose", and "Avoid collecting data unrelated to the extension's functionality or operational needs". It does not stretch further: the User Data FAQ says "Data collection for unrelated advertising, profiling, or generalized market research purposes is not considered necessary."

The third-party rule permits transfers only "If necessary to providing or improving your single purpose," to comply with law, to fight abuse, or in a merger with prior consent. Google Analytics is a third party, so your analytics traffic has to land in that first bucket. Limited Use also requires "An affirmative statement that your use of the data complies with the Limited Use restrictions" on "a website belonging to your extension", and offers as its example "a link on a homepage to a dedicated page or privacy policy".

Then the clause most likely to catch an analytics integration. A content script that reads the URL of every page a user visits and sends it as a GA4 event parameter is collecting web browsing activity. Google's best practices to avoid sending PII page warns from the other direction, as of October 2026: "PII is often inadvertently sent in these URLs and titles."

Winner

Nobody, this is table stakes. The policy applies identically to every analytics vendor you could pick, Moderok included.

Round 3Google's terms add obligations the Web Store does not

Section 7 of the Analytics Terms of Service is short and specific. As of October 2026 it says "You must post a Privacy Policy and that Privacy Policy must provide notice of Your use of cookies, identifiers for mobile devices (e.g., Android Advertising Identifier or Advertising Identifier for iOS) or similar technology used to collect data. You must disclose the use of Google Analytics, and how it collects and processes data."

That bites in an extension. The client_id is yours to generate, and Chrome's Use Google Analytics guide says, as of October 2026, to keep it in browser.storage.local because "The ID should stay the same, as long as the extension is installed on a user's browser." That is a persistent identifier you created and control, and the terms above make naming Google Analytics in your privacy policy a condition of using the service.

One trap sits in Chrome's own error sample, which posts event.reason.message and event.reason.stack to GA4. The page cautions, as of October 2026: "Logging exceptions might accidentally leak personal information." Extension stack traces can carry URLs and user input.

Winner

Nobody. Google's terms impose a disclosure duty the Web Store does not, and you have to satisfy both.

What to put on the Privacy practices tab

The disclosure is a publishing gate. The User Data FAQ states, as of October 2026, "Every item will need to provide these data collection disclosures and limited use certification in order to be updated or published." Inconsistency is itself a violation: a discrepancy between dashboard disclosures, your privacy policy, and your item's behavior "can result in the suspension of all the items owned by the publisher" and a ban of the publisher entity. What you tick depends on what your event parameters carry, so read your own fetch body first.

The other Google Analytics for extensions

Separately from anything you instrument, the Chrome Web Store offers an "integration with Google Analytics" for your listing: opt in from the Store listing page under Additional metrics, and as of October 2026 the documentation says "You should have access to a new property which has been named with your extension ID." It sends page_view, session_start, first_visit and user_engagement, plus a custom install event that "is only sent if a user accepts the permission prompt to complete the install." Its documented limits: "Data retention is set to two months", "Data de-identification is enabled, which limits access to non aggregated data to prevent tracking an individual user", you get the Marketer role and "This can't be changed", and linking to Google Ads is "not currently possible".

When Google Analytics is the right choice

If your extension is one surface of a product that already runs GA4 on its website, a single property seeing both is worth real friction. The Measurement Protocol route is documented by Chrome itself in the extension guide, as of October 2026, so no reviewer will be surprised by it.

The cost is that an extension is not a website. Chrome's guide says, as of October 2026, that "In Chrome extensions, unlike in normal websites, there is no clear notion of a user session," and cautions that "Using the Measurement Protocol means that some information, such as geolocation, won't be included." Uninstalls reach neither property on their own: Chrome's runtime reference documents setUninstallURL as a way to "do analytics", but you have to wire it up. Those gaps are mapped in the Chrome extension analytics roundup and head to head in Moderok vs Google Analytics.

Whichever you pick, the policy work is the same. Moderok's SDK is built around a random anonymous profile ID, kept with chrome.storage.local and mirrored to chrome.storage.sync so it can be recovered when Chrome Sync is on, which means it is not confined to one device and your disclosure should say so. It sets no cookies and does no fingerprinting, but it is not a reason to stop thinking about PII: custom properties are whatever you pass to track(), captureError() or captureLastError(), and automatic error capture, on unless you pass trackErrors: false, forwards the error message, stack and filename. Chrome's stack-trace caution applies to every vendor, Moderok included. Read exactly what it stores and sends in the privacy docs before you write your disclosure.