App Store 2.5.13 rejection: Facial recognition for authentication
By The Draftbit team · Updated
Sources checked
This guide is for iPhone and iPad apps using facial recognition to sign people into an account.
Using the camera to recognize a face isn’t automatically an acceptable replacement for system authentication. Under 2.5.13, Apple requires LocalAuthentication where possible and an alternative method for users under 13.
Identify the sign-in method
Ask your developer whether the app uses the system authentication framework or its own face-recognition implementation, including ARKit. We’d check enrollment, sign-in, and recovery separately because different components can handle each step.
Use an appropriate authentication route
Move supported authentication to LocalAuthentication and provide the required alternative for younger users. Check the fallback for a device without the biometric capability or a user who can’t complete the biometric check. Avoid collecting facial information merely to duplicate a system capability.
Test success, cancellation, failure, and the alternate method using test accounts. Give Apple the framework used and the route to the alternative. If you believe system authentication isn’t possible for the feature, explain the specific technical limitation and the actual account flow.
Official sources
We checked these instructions against the sources below. The console layout may change, and your review decision may call for different steps.
- Apple App Review guideline 2.5.13 Checked 22 September 2026