App Store 4.7.3 rejection: Consent for sharing with hosted software
By The Draftbit team · Updated
Sources checked
This guide is for iPhone and iPad apps sharing user data or privacy permissions with individual hosted software items.
A person granting access to your host app hasn’t necessarily agreed to share it with every mini app. Under 4.7.3, sharing data or privacy permissions with an individual hosted item requires explicit consent in each instance.
Follow the first handoff
Open a hosted item with a new test account. What data or permissions does it receive before the person sees a choice? We’d inspect the request itself, since a consent screen can appear after information has already been sent.
Explain and control the sharing
Make the specific item and sharing understandable before obtaining consent. Keep refusal workable and avoid silently passing along all permissions the host already holds. Review how repeated use and changed data requests are handled against the actual policy.
Test consent, refusal, and a second hosted item. Verify that declining the first doesn’t still transfer its requested data, and that agreeing to one doesn’t automatically authorize another. Give Apple the sequence and safe test evidence. Native API exposure also has separate approval requirements under 4.7.2.
Official sources
We checked these instructions against the sources below. The console layout may change, and your review decision may call for different steps.
- Apple App Review guideline 4.7.3 Checked 22 September 2026