Apple rejected your app for sharing data with third-party AI
Explain what personal data goes to an AI provider, obtain permission before sending it, and verify what happens when someone declines.
By The Draftbit team · Updated
Sources checked
This guide is for Apple apps sending personal data to third-party AI services, directly or through the app's backend.
Your AI feature works, but Apple says users haven’t agreed to where their data goes. A privacy-policy link alone may leave that choice missing from the feature. Check what leaves the app and when it leaves.
Guideline 5.1.2 explicitly addresses disclosure and permission before personal data is shared with third-party AI. This concerns the app’s handling of user data. Using AI to help write the app’s code doesn’t itself establish that the app sends user data to an AI service.
Trace the request beyond your own server
Ask your developer to list the fields in an AI request: the prompt, attachments, account identifiers, conversation history, and any context added on the server. Record each recipient and what its current service terms say about retention and use.
If your server sends the data on to an AI provider, explain that step too. We recommend using a sample request with invented data so you can inspect everything the request sends without exposing a customer’s message.
Put the choice before the transfer
Write the disclosure around the feature the person is about to use. Name the recipient, identify what will be sent, explain the purpose, and provide a real choice before anything is sent.
For illustration, a receipt-summary feature might need to explain:
To summarize this receipt, we’ll send its image and your question to [provider name]. The image may contain names, addresses, or payment details. You can continue with the AI summary or return without sending it. Read our privacy policy for how the data is handled.
Replace the placeholder and describe the data your app actually sends. This example isn’t an approved consent script and doesn’t cover every app’s legal obligations. If your server also sends prior messages or profile details, that needs to be reflected in the explanation and your data handling.
Verify both choices
Test the submitted build while observing the relevant app and backend requests:
- Before the choice, the covered personal data hasn’t been sent to the AI recipient.
- After permission, the data sent and the service receiving it match the explanation.
- After refusal, that transfer doesn’t happen and the app explains the available next step.
- Returning to the feature follows the consent behavior you’ve actually designed.
Check App Privacy disclosures and the privacy policy against the same data map. App Tracking Transparency concerns tracking as Apple defines it; its system prompt doesn’t replace this feature’s AI-sharing explanation.
In the review reply, give the steps to reach the disclosure, explain what happens when someone declines, and identify the corrected build. Review access should let Apple exercise both paths with safe sample data.
Official sources
We checked these instructions against the sources below. The console layout may change, and your review decision may call for different steps.
- Apple App Review Guidelines Checked 22 September 2026
- Apple App Privacy disclosures Checked 22 September 2026
- Apple user privacy and App Tracking Transparency Checked 22 September 2026