App Store 1.6 rejection: Data security
By The Draftbit team · Updated
Sources checked
This guide is for iPhone and iPad apps collecting, storing, or transmitting user information.
Apple has raised a security concern, and a privacy-policy edit won’t fix an exposed account or data flow. Guideline 1.6 requires appropriate protection against unauthorized access, use, or disclosure of user information.
Reproduce the reported exposure safely
Use test accounts and test data. Check whether one account can read another account’s records, whether files are publicly accessible, and whether credentials or personal information appear in logs or app responses. We’d have the developer follow the exact request or screen Apple identified before making a broad claim that the issue is fixed.
Include third-party services and SDKs, which are libraries included in your app. A secure app screen doesn’t protect information that a backend sends to the wrong person.
Correct the boundary and test it
Repair the access control, storage setting, or transmission issue responsible for the exposure. Retest both the intended user and an account that should be refused access. Check the app’s privacy disclosures against its corrected behavior.
Give Apple a concise explanation of the fix and safe reproduction steps. Keep credentials and customer records out of screenshots and review notes. If the investigation identifies an actual incident, involve the people responsible for security and privacy obligations.
Official sources
We checked these instructions against the sources below. The console layout may change, and your review decision may call for different steps.
- Apple App Review guideline 1.6 Checked 22 September 2026