How to fix an App Store Guideline 5.1.2 rejection

Guideline 5.1.2 is about what you do with data after you collect it: who you share it with and whether you track people. Most rejections involve App Tracking Transparency or an SDK that tracks without asking. Here is how to find the cause and fix it.

Published by Legiflare. General information, not legal advice.

What Guideline 5.1.2 says

The rejection is titled "Guideline 5.1.2 - Legal - Privacy - Data Use and Sharing". The guideline's first rule carries most of the weight. Among other things, it says:

"You must clearly disclose where personal data will be shared with third parties, including with third-party AI, and obtain explicit permission before doing so."
"You must receive explicit permission from users via the App Tracking Transparency APIs to track their activity."
"Your app may not require users to enable system functionalities (e.g. push notifications, location services, tracking) in order to access functionality, content, use the app, or receive monetary or other compensation, including but not limited to gift cards and codes."

Further rules say data collected for one purpose can't be repurposed without new consent, and that you can't build user profiles in secret or collect which other apps are installed for analytics or advertising.

What Apple counts as tracking

Apple defines tracking as linking user or device data collected from your app with data collected from other companies' apps, websites or offline properties, for targeted advertising or advertising measurement, or sharing that data with data brokers.

Analytics that stay inside your own app aren't tracking on their own. Showing personalized ads from an ad network, measuring ad installs with an attribution SDK, or sending identifiers to a data broker usually is.

Common causes

  1. Your App Privacy answers say you track, but there's no prompt. If you declared "Data Used to Track You" in App Store Connect, the reviewer expects to see the App Tracking Transparency prompt.
  2. The reviewer never sees the prompt. The request only appears while your app is active, and only once per install. If you call it too early or behind a screen the reviewer doesn't reach, it looks missing.
  3. Tracking continues after "Ask App Not to Track". An SDK keeps collecting identifiers, or a webview keeps setting tracking cookies, after the user declines.
  4. Gating or rewards. The app blocks features until people allow tracking, notifications or location, or offers a reward for allowing them.
  5. Undisclosed sharing. Data goes to a third party, including an AI service, without the app saying so and asking first.

Fix checklist

  1. Decide whether you track. List every ad, analytics and attribution SDK and check how each is configured.
  2. If you don't track, turn off ad personalization and identifier collection in those SDKs, and make your App Privacy answers say you don't track.
  3. If you do track, add NSUserTrackingUsageDescription to Info.plist with a specific reason and call ATTrackingManager.requestTrackingAuthorization before any tracking starts.
  4. Respect "Ask App Not to Track". When the status isn't authorized, stop collecting identifiers for tracking, in SDKs and webviews alike.
  5. Remove gates and incentives. The app must work the same whether or not people allow tracking, notifications or location.
  6. Ask before sharing with third parties, including AI services, and say so in the app.
  7. Update your privacy manifest. Set NSPrivacyTracking and list your tracking domains in NSPrivacyTrackingDomains. See the privacy manifest post.
  8. Update your privacy policy. Guideline 5.1.1(i) requires it to name all uses of data and the third parties you share it with. The template has sections for both.

Replying to App Review

Reply in App Store Connect and explain what changed. If you track, say exactly when the prompt appears, for example "on first launch, after the welcome screen", and attach a screenshot. If you don't track, say that you updated your App Privacy answers and turned off tracking in your SDKs, and name them.

Frequently asked questions

Do I need App Tracking Transparency if I only use analytics?

Not if the analytics data stays with you and isn't linked with other companies' data for advertising. Your App Privacy answers must then say you don't track, and your SDKs must be configured to match.

Can I show my own screen before the tracking prompt?

Yes, a screen that explains why you ask is allowed. It must not offer rewards, block the app, or look like the system prompt.

Does my privacy policy need to mention tracking?

Yes. Apple requires the policy to describe all uses of the data you collect and the third parties you share it with, which includes ad networks and attribution providers.

Describe your data use in a clear privacy policy

Start from the template and publish it on a permanent link for App Store Connect. Free.