App Store 5.1.2 rejection: Data use, sharing, and tracking

By The Draftbit team · Updated
Sources checked

This guide is for iPhone and iPad apps using or sharing personal information, including with advertising or AI services.

A privacy policy can describe sharing without giving the person the choice Apple requires. Guideline 5.1.2 covers permission, onward use, profiling, and data from sensitive APIs. We’d follow the data from the first interaction to every recipient.

5.1.2(i): permission before sharing

Explain how and where personal data is used and obtain the required permission before transfer. Apple explicitly includes third-party AI. For tracking covered by App Tracking Transparency, use that system permission too. An AI-consent screen and an ATT prompt address different requirements.

Avoid making access or rewards depend on enabling tracking or other system capabilities in the ways prohibited by the clause. Test refusal. See the AI data-sharing guide for a practical request-by-request check.

5.1.2(ii): a new purpose

Data collected for one purpose needs further consent before repurposing unless the law explicitly permits otherwise. Review new analytics, advertising, or model-training uses rather than treating the original collection as unlimited permission.

5.1.2(iii): hidden profiles and reidentification

Remove covert profiling and attempts to identify people from data represented as anonymous or aggregated. Check joins between datasets and third-party enrichment, not just individual fields.

5.1.2(iv): contact databases and installed apps

Don’t turn Contacts, Photos, or similar access into a database for your own unrelated use or distribution. Collecting installed-app information for analytics or advertising is also prohibited here.

5.1.2(v): contacting other people

The user must initiate contacts individually and see what the recipient will receive and who appears as sender. Remove select-all or preselected-all invitations. Test with fictional contacts so the check doesn’t send real invitations.

5.1.2(vi): sensitive framework data

Data from the listed health, home, classroom, depth, and face-mapping tools can’t be used for marketing, advertising, or behavior-based data mining, including by third parties. Inspect SDK payloads for accidental sharing.

5.1.2(vii): Apple Pay data

Share information acquired through Apple Pay only to support or improve delivery of the goods or services. Keep unrelated advertising and profiling systems outside that flow.

Verify before replying

Test consent, refusal, and withdrawal with safe accounts, and inspect when each request occurs. Update disclosures to match the corrected implementation. Give Apple the specific recipient, purpose, and screen involved, with credentials and real personal data removed from evidence.

Messages this guide can help with

App Store 5.1.2 rejection; app store 5.1.2 denial; Guideline 5.1.2; Data use, sharing, and tracking; 5.1.2(i); 5.1.2(ii); 5.1.2(iii); 5.1.2(iv); 5.1.2(v); 5.1.2(vi); 5.1.2(vii)

Official sources

We checked these instructions against the sources below. The console layout may change, and your review decision may call for different steps.

Your next stepSubmit your iPhone or iPad app for review