App Store 5.4 rejection: VPN apps

By The Draftbit team · Updated
Sources checked

This guide is for iPhone and iPad apps offering VPN services or using NEVPNManager for an approved related purpose.

A working VPN connection is only part of Apple’s review. Guideline 5.4 covers the developer’s organization, the networking API, disclosure before use, strict data handling, and local licensing.

Check the provider and the first-use screen

VPN providers must be enrolled as organizations and use NEVPNManager. Before purchase or use, explain on an app screen what data is collected and how it’s used. We’d test a clean installation and inspect what happens before that screen appears.

Apple’s rule places strict limits on selling, using, or disclosing VPN data to third parties and requires a corresponding privacy-policy commitment. Inspect analytics and advertising libraries against that restriction. Approved parental-control, content-blocking, and security providers can also use the API under the stated conditions.

Verify the territory and data flow

Confirm relevant local laws and include required VPN license information in Notes for Review for territories needing a license. Get qualified advice about your service’s coverage.

Test connection, disconnection, disclosure, and data transmission with a safe account. Give Apple the provider identity, API, privacy information, licenses, and steps to verify the corrected flow.

Messages this guide can help with

App Store 5.4 rejection; app store 5.4 denial; Guideline 5.4; VPN apps

Official sources

We checked these instructions against the sources below. The console layout may change, and your review decision may call for different steps.

Your next stepSubmit your iPhone or iPad app for review