Apple App Store · Guideline 5.1.1 — Data Collection and Storage

How to Fix App Store Guideline 5.1.1 Privacy Rejection

Audit privacy policy, permissions, disclosures, data minimization, retention, and deletion after an Apple Guideline 5.1.1 rejection.

Policy-grounded recovery guideOfficial policy ↗
Have the rejection message open?Get a free diagnosis now. Upgrade to the complete $29 Fix Pack only if it is useful.
Analyze this rejection →

Direct answer

Reconcile the whole data flow, not only the privacy-policy wording. The app, embedded SDKs, permission prompts, App Store privacy answers, consent, retention, and deletion behavior must describe the same reality. Remove unnecessary collection and permissions before trying to explain them.

Official sources checked

Match the wording in your rejection

Registration is required before non-account-based features can be used

Remove the mandatory data gate or demonstrate why an account is directly relevant to the core functionality or legally required.

A permission purpose string is unclear or incomplete

Name the protected data and the specific user-facing feature that needs it. A generic sentence may fail even when the permission is technically configured.

Privacy policy or App Privacy answers do not match app behavior

Inventory first-party and SDK collection, then align product behavior, disclosures, sharing, retention, and deletion.

What this rejection usually means

A 5.1.1 rejection usually indicates that the app’s collection, permissions, policy, disclosures, consent, retention, or deletion controls do not align. Treat it as a full data-flow reconciliation rather than editing one privacy-policy sentence.

Likely rejection signals

  • Privacy policy does not name collected data and purposes
  • Permission request is broader than the core feature needs
  • App Privacy answers conflict with SDK behavior
  • Consent, deletion, or withdrawal path is missing

Recovery plan

  1. Inventory data collected by the app, backend, analytics, advertising, authentication, and every embedded SDK.
  2. Match each data element to a feature, legal basis, purpose, retention period, sharing recipient, and deletion path.
  3. Remove unnecessary permissions and use narrower pickers or system flows where possible.
  4. Align the in-app policy, App Store Connect privacy answers, purpose strings, and prominent disclosures.
  5. Test consent denial, withdrawal, account deletion, and data deletion end to end.

Evidence to prepare

  • Current data-flow inventory including SDKs
  • Screenshots of consent and permission context
  • Accessible privacy policy and deletion instructions
  • App Privacy answers matched to production behavior

Appeal or fix first?

APPEAL / CLARIFY

Clarify when Apple attributed data collection to the app that does not occur in the submitted build and you can prove the SDK and network behavior.

FIX BEFORE RESUBMITTING

Fix first whenever documentation, App Privacy answers, permissions, or actual production collection do not match.

Choose the next action

What you can verifyRecommended path
The app or an SDK collects data that is missing from disclosuresFix first: update behavior and every disclosure surface, then retest consent and deletion.
The app requests data or permission that the feature does not needRemove or narrow the collection rather than defending it.
Apple attributed collection that does not occur in the submitted buildClarify with SDK configuration, network evidence, and the exact build behavior.

Reviewer response framework

Your response should be factual, short, and limited to the submitted build. Cover these points:

  1. Identify the affected data type and feature.
  2. List the verified policy, disclosure, or code changes.
  3. Explain how users can refuse or delete data where applicable.
  4. Point to the exact in-app and public policy locations.

Frequently asked questions

Is a privacy-policy URL enough?

No. The policy, App Store Connect disclosures, permission purpose strings, consent flows, SDK behavior, retention, and deletion controls must agree.

Do analytics SDKs count?

They can. Include every SDK that accesses, collects, or shares user or device data in the audit.

Need a rejection-specific plan?

Start with the free diagnosis. The $29 Fix Pack adds the prioritized remediation plan, evidence checklist, reviewer-ready reply, and preflight.

Analyze my rejection

Source: Apple App Review Guidelines — 5.1.1 Privacy. Platform policies change. Verify the official rule before submitting. Resubmit AI provides technical and editorial decision support, not an approval guarantee or legal advice.