Complete Apple's privacy labels and SDK requirements

Work out what belongs in your privacy policy, what to enter in App Store Connect, and what your build needs to include.

By The Draftbit team · Updated
Sources checked

This guide is for iPhone/iPad apps and their analytics, authentication, advertising, payment, and other third-party integrations.

You’ve added a privacy policy, and Apple is still asking for privacy information. There are three separate parts to finish: the public policy, App Privacy answers in App Store Connect, and any required privacy information inside your build. We’ll help you work out which part needs attention.

Find out what your app collects

List the data your app handles, including its backend and third-party SDKs, the software development kits added to provide features such as analytics or sign-in. Your signup form is only part of the picture. For each data flow, record what the data is, why it’s used, how long it’s kept, who receives it, and whether it’s linked to a person or used for tracking.

Read Apple’s definitions before filling out App Privacy. Data that stays on the device is treated differently from data sent off-device and retained. Check each SDK provider’s documentation against the way you’ve configured that SDK in your app.

Complete the policy and App Privacy answers

Enter the answers under App Privacy and add a public privacy-policy URL. Both should describe what the app actually does, including relevant third-party practices.

You can correct the App Privacy questionnaire without releasing a new app update.

Check the information inside the build

Look up Apple’s list of SDKs that require privacy manifests. Binary SDKs on that list can also require signatures.

Ask your developer or build provider to check required-reason API declarations in the app and its dependencies. If the uploaded build is missing required information, update the affected library or configuration and rebuild. Changing a privacy-policy link won’t fix a missing declaration inside a binary.

Use the upload message to identify which part needs attention. You’re ready to continue when the policy and App Privacy answers match the app, and the uploaded build passes the SDK and required-reason API checks that apply to it.

Revisit the data list whenever you add analytics, ads, AI services, or another feature that handles data.

Messages this guide can help with

privacy manifest; required reason API; App Privacy; SDK signature; privacy nutrition label

Official sources

We checked these instructions against the sources below. The console layout may change, and your review decision may call for different steps.

Your next stepConnect your iOS bundle ID, signing, and app record