App Store 5.1 rejection: Privacy
By The Draftbit team · Updated
Sources checked
This guide is for iPhone and iPad apps collecting, storing, using, or sharing personal information.
Apple’s privacy rules cover what the app does with information, not only the privacy policy on your website. Under 5.1, collection, sharing, health data, children’s information, and location have separate requirements.
Start with the actual data flow
Write down what enters the app, what leaves the device, where it’s stored, and who receives it. Include sign-in providers, analytics, advertising, and AI services. We’d compare that map with permission prompts, the privacy policy, and the App Store privacy answers.
For collection, login, and deletion, use 5.1.1. For sharing, tracking, and changes of purpose, use 5.1.2. The other child pages cover specialized data uses.
Fix behavior and disclosures together
Remove unnecessary collection, correct consent and access controls, and update inaccurate disclosures. Changing the document alone won’t stop an SDK sending information before consent.
Test with fresh accounts and declined permissions, using fictional data. Give Apple the specific clause, corrected flow, and steps to verify it. Use the Apple privacy guide to keep store disclosures and app behavior aligned.
Official sources
We checked these instructions against the sources below. The console layout may change, and your review decision may call for different steps.
- Apple App Review guideline 5.1 Checked 22 September 2026