Does Firebase work in China?

Whether you can build on Firebase for a mainland-China audience is first a data-residency question — and, unusually, a reachability one too. Neither is about raw speed.

Firebase is Google's backend-as-a-service, and a Firebase project is a Google Cloud project. You choose one location for Cloud Firestore, the Realtime Database and Cloud Storage, and in Google's own words, "once you provision a database instance, you cannot change its location setting." None of the locations on offer is in mainland China, because Google Cloud operates no region there — so every account, record and file your app collects from Chinese users is stored offshore: a cross-border transfer of personal information PIPL governs. On top of that, Firebase's client SDKs reach Google-operated endpoints that are not consistently reachable from inside the mainland, so the app can fail to load, sign in or sync even when your code is correct. The table below is Google's own wording and the China rules it triggers — and the compliant, ICP-filed in-country path.

This is a risk picture, not a legal verdict — what you owe turns on your data volumes and your role. Our China team can map your Firebase exposure with you →

What actually decides whether you can build on Firebase in China

FactPrimary source
In Firebase's own documentation, each project stores its Cloud Firestore, Realtime Database and Cloud Storage data in a single location you choose, and "once you provision a database instance, you cannot change its location setting." Google advises you to "store your data close to the users and services that need it" — yet none of the locations Firebase offers is in mainland China, so there is no choice that keeps Chinese users' data on the mainland. Firebase Docs — Cloud Firestore locations, retrieved 2026-10-07
A Firebase project is a Google Cloud project, and Google Cloud operates no mainland-China region. In Google's own words you "can deploy workloads across 43 global regions and 130 zones," and those "SLA-backed regions let you innovate globally without compromising on data residency" — but not one of them sits inside mainland China. Wherever your Firebase data physically lands, it is offshore to China. Google Cloud — Cloud locations, retrieved 2026-10-07
Firebase Authentication, Cloud Firestore, the Realtime Database and Cloud Storage hold the accounts, profiles, records and files your app collects — personal information — and keep them in that offshore location. Data gathered from users in China is therefore transferred abroad: PIPL governs that cross-border transfer, and the personal-information handler (you, the Firebase customer — not Google) must give notice, obtain separate consent, and meet one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. For a CIIO or large-volume handler, personal information collected in China must be stored inside the mainland (PIPL Article 40; CSL Article 37) — which no Firebase location can satisfy. PIPL Chapter III, Articles 38–43 and Article 40; Cybersecurity Law Article 39 (formerly Article 37)
Because Firebase is built on Google infrastructure, its client SDKs connect to Google-operated endpoints — hosts under googleapis.com, gstatic.com and firebaseio.com, together with the Authentication and messaging services — to fetch configuration, sign users in and sync data. Google-operated endpoints are not consistently reachable from inside mainland China, so a China-facing app on Firebase can fail to initialize, authenticate or sync even when your own code and servers are healthy. That reachability exposure is a risk to verify for the specific services you use, not a speed metric. Firebase Docs — Understand Firebase projects (a Firebase project is a Google Cloud project)

Sources verified by the 21YunBox compliance team on 2026-10-07.

For a mainland-China audience, the first question about Firebase is not how quickly it loads — it is where the data it holds is allowed to live, and whether the app can even reach the services it depends on. Firebase is Google’s backend-as-a-service: Cloud Firestore, the Realtime Database, Authentication, Cloud Storage and Hosting, all running on Google Cloud. A Firebase project is a Google Cloud project, and that single fact sets up both of the problems this page is about. The data your app collects is stored in a Google Cloud location you pick — and none of the choices is in mainland China. The SDK your app ships with, meanwhile, talks to Google-operated endpoints to do its work — endpoints that are not dependable from inside the mainland. Neither is something you tune your way out of.

Google's Cloud Firestore locations documentation listing multi-region and regional locations across North America, Europe, Asia, Australia, South America, the Middle East and Africa, with no mainland-China location
Google's own Cloud Firestore locations documentation: “once you provision a database instance, you cannot change its location setting,” and the location menu spans North America, Europe, Asia, Australia, South America, the Middle East and Africa — with no mainland-China location. Source: firebase.google.com/docs/firestore/locations

Firebase in China at a glance

What decides it In Google's own terms — and the China rule it triggers
Where your data lives Each project keeps its Cloud Firestore, Realtime Database and Cloud Storage data in one location you choose, and Google warns that “once you provision a database instance, you cannot change its location setting.” None of the choices is in mainland China.
Why there is no China option A Firebase project is a Google Cloud project, and Google Cloud runs “43 global regions and 130 zones” — none inside mainland China. So wherever your data lands, it is offshore to China.
The cross-border transfer Accounts, profiles, records and files collected from users in China are written to that offshore location. That is a cross-border transfer of personal information PIPL governs — and the handler is you, the Firebase customer, not Google.
Data residency For a CIIO or large-volume handler, personal information collected in China must be stored inside the mainland (PIPL Article 40; CSL Article 37) — a duty no Firebase location can meet.
Can the app reach it? Firebase's SDKs depend on Google-operated endpoints (googleapis.com, gstatic.com, firebaseio.com and the Auth and messaging services) that are not consistently reachable inside mainland China — a reachability risk to verify, on top of the data question.

Where your Firebase data actually lives

Firebase is a managed backend, and the stores that matter for China — Cloud Firestore, the Realtime Database and Cloud Storage — each sit in a single location you set when you create them. That location is a one-way door. In Google’s own Firestore documentation:

Be aware that once you provision a database instance, you cannot change its location setting.

Google’s advice on the same page is to “store your data close to the users and services that need it.” For a China audience that advice has no answer, because the menu you choose from contains no mainland-China location — the nearest options sit in Northeast and Southeast Asia. The moment your app serves users in China, the data it writes is kept abroad, and that, not latency, is what China’s data law reacts to.

Serve China from Firebase and your users’ data crosses the border

Firebase Authentication holds your users’ login identities; Firestore and the Realtime Database hold the records they create; Cloud Storage holds their files. All of it is personal information, and all of it lands in that one offshore location. Under China’s Personal Information Protection Law, storing it outside the mainland is a cross-border transfer, and the obligation falls on the personal-information handler — you, as the Firebase customer, not Google as the platform. PIPL asks that handler to give affected users notice, obtain their separate consent for the transfer, and clear one transfer mechanism: a CAC security assessment, the CAC standard contract, or certification. “We already run on Firebase” answers none of that.

How heavy the duty is depends on who you are and how much you hold. A small app moving a modest volume of non-sensitive personal information has a lighter path than a CIIO or a large-volume handler, which carries a data-residency duty: personal information collected in China must be stored inside the mainland (Cybersecurity Law Article 39 (formerly Article 37); PIPL Article 40). No Firebase location can satisfy that, because none is in China. This is a risk map, not a verdict — where you land turns on your data volumes and your role, and it is a question to settle with counsel before you build.

The second problem: the Google endpoints Firebase depends on

Even setting the data question aside, Firebase carries a reachability risk that most offshore backends do not. Because it is built on Google infrastructure, the Firebase SDK your app ships with reaches Google-operated endpoints to do its everyday work — fetching remote configuration, signing users in, and syncing database and storage reads and writes. Those requests travel to hosts under googleapis.com, gstatic.com and firebaseio.com, along with the Authentication and messaging services.

Google-operated endpoints are not consistently reachable from inside mainland China. The practical consequence is that a China-facing app built on Firebase can hang on startup, fail to sign users in, or stop syncing — not because your code is wrong, but because the services it calls cannot be relied on from where your users are. This is why a quick test from outside China tells you very little: the honest question is not whether Firebase works on your desk, but whether the specific Firebase services your app depends on resolve for a real user in the mainland. Treat that as an exposure to verify per service, not a number to quote.

Where 21YunBox fits — a compliant overlay, not a migration

You keep building on Firebase; we do not ask you to migrate off it or rewrite your app. What a compliance-first overlay adds is the layer a Google-hosted backend cannot provide from inside China: compliant, ICP-filed in-country delivery standing in front of your existing origin — no rebuild and no second codebase — so the endpoints you control resolve for users in the mainland. First, our China team maps your exposure: which parts of your Firebase stack hold personal information, where that data is stored, and whether your entity and data volumes pull you into the cross-border-transfer or data-residency tiers. Then, where the law requires Chinese users’ data to remain on the mainland, we help you plan an in-country data path for those records rather than leaving them in an offshore Firebase location. The reachability question and the residency question get worked through together, and your origin stays where it already runs.

Get a compliance assessment →


Related reading:

Frequently Asked Questions

Does Firebase store Chinese users' data in China?
No. A Firebase project is a Google Cloud project, and you pick one location for Cloud Firestore, the Realtime Database and Cloud Storage from a menu that holds no mainland-China option — because Google Cloud runs no region there. So the accounts, records and files collected from users in China are stored offshore, and by Google's own documentation that location cannot be changed once the database is provisioned.
Is it against the law to build a China-facing app on Firebase?
Not inherently — but two things need assessing. First, storing Chinese users' personal information offshore is a cross-border transfer PIPL governs, which calls for notice, separate consent and a transfer mechanism, plus in-country storage for a CIIO or large-volume handler. Second, Firebase depends on Google-operated endpoints that are not consistently reachable inside the mainland, so the app may not function reliably for Chinese users regardless of the legal analysis. Treat both as risks to work through with counsel for your data volumes and role, not a blanket prohibition.
Can 21YunBox help make our Firebase app work compliantly in China?
Yes. Our China team can map your cross-border and data-residency exposure against your entity and data volumes, and provide compliant, ICP-filed in-country delivery in front of your existing origin — no rebuild — so the parts you control resolve for users in the mainland. Where the law requires Chinese users' data to stay on Chinese soil, we help you plan an in-country data path rather than leaving those records in an offshore Firebase location. Get in touch to work through your specific setup.