Prepare sign-in and account deletion for review
Build and test the deletion routes your app needs, then check the separate rules for third-party sign-in.
By The Draftbit team · Updated
Sources checked
This guide is for Apps that create user accounts or use third-party login; requirements depend on the actual account and sign-in flows.
You’ve added a delete-account button, but the store needs the whole process to work. A privacy-policy sentence or a button that only disables login won’t complete account deletion. We’ll cover the routes people need and what to test behind the button.
Map account creation, sign-in, subscriptions, stored data, and external processors. Identify anything you must retain and why. Use a disposable test account when checking deletion.
Provide the deletion routes each store requires
For Apple, an app that supports account creation needs an easy-to-find way to start deletion inside the app. If you link to a website, send the user directly to the deletion flow. Non-regulated apps generally can’t require a phone call or email to support.
For Google, covered apps need an in-app route and a working external web route. The web page must identify the app or developer and remain usable after the app is uninstalled.
If your app links to account creation on the web, check the store’s applicability criteria. Don’t assume that puts it outside the requirement.
Connect the request to actual deletion
Delete the account and associated data, including data with relevant service providers. Explain legitimate retention and the expected processing time to the user.
If you use Sign in with Apple, revoke the user’s tokens during deletion. Explain what happens to an active subscription, too.
Test the request, appropriate identity confirmation, completion, and the next login attempt. A reviewer should be able to find and complete the applicable flows, with disclosures that match the backend’s behavior.
Check login choices separately
Apple’s rule for third-party or social primary login has exceptions. It doesn’t require every app to add Apple login.
If deletion fails review, check whether the problem is a broken link or missing backend behavior. Updating the deletion URL in the console won’t fix a flow that only deactivates the account.
Follow the store’s specific check
- For an Apple deletion rejection, test the route through backend completion and subscription handling.
- For Google’s external URL, build and test a request page that works after uninstalling.
- For a 4.8 rejection, check whether your primary login needs an equivalent option.
- If reviewers can’t get in, prepare access for OTP, magic links, or social login before resubmitting.
Official sources
We checked these instructions against the sources below. The console layout may change, and your review decision may call for different steps.
- Offer account deletion in your app Checked 22 September 2026
- Google account deletion requirements Checked 22 September 2026
- Apple App Review Guidelines Checked 22 September 2026