What a privacy manifest is
A privacy manifest is a file named PrivacyInfo.xcprivacy in your app or in an SDK. Apple introduced it at WWDC23 to describe privacy practices in one standard format. It can declare:
- the types of data the code collects (
NSPrivacyCollectedDataTypes); - whether it tracks users (
NSPrivacyTracking) and which domains it uses for tracking (NSPrivacyTrackingDomains); - which "required reason" APIs it uses and why (
NSPrivacyAccessedAPITypes).
Your app has its own manifest, and each SDK should ship its own. Xcode combines them into a privacy report when you archive.
ITMS-91053: Missing API declaration
This email means your app's code, or code bundled into it, calls an API that Apple says needs an approved reason, and the reason isn't declared. Required reason APIs fall into categories such as:
- file timestamps (
NSPrivacyAccessedAPICategoryFileTimestamp); - system boot time (
NSPrivacyAccessedAPICategorySystemBootTime); - disk space (
NSPrivacyAccessedAPICategoryDiskSpace); - active keyboards (
NSPrivacyAccessedAPICategoryActiveKeyboards); - user defaults (
NSPrivacyAccessedAPICategoryUserDefaults).
Apple started sending these emails on March 13, 2024. Since May 1, 2024, you need the reasons in place to upload a new app or update.
To fix it:
- In Xcode, choose File > New > File and add an App Privacy file to your app target, if you don't have one.
- For each category named in the email, add an entry to
NSPrivacyAccessedAPITypeswith the category and an approved reason code from Apple's list. Pick the reason that matches what your code really does. - If the API call comes from an SDK, update the SDK instead. Its own manifest should declare its reasons.
For example, an app that reads and writes its own settings with UserDefaults declares:
<key>NSPrivacyAccessedAPITypes</key>
<array>
<dict>
<key>NSPrivacyAccessedAPIType</key>
<string>NSPrivacyAccessedAPICategoryUserDefaults</string>
<key>NSPrivacyAccessedAPITypeReasons</key>
<array>
<string>CA92.1</string>
</array>
</dict>
</array>
ITMS-91061: Missing privacy manifest
This email lists SDKs in your app that are on Apple's list of commonly used third-party SDKs but have no privacy manifest. Since February 12, 2025, a new app that includes one of these SDKs, or an update that adds one, needs the SDK's manifest. Where the SDK is a binary dependency, it also needs a signature.
The list includes widely used SDKs such as Firebase, the Facebook SDKs, GoogleSignIn, OneSignal, Alamofire and AFNetworking. The full list is on Apple's third-party SDK requirements page.
To fix it:
- Note the SDK names and paths in the email.
- Update each SDK to a version that includes a privacy manifest. In Flutter, React Native or Unity projects, that often means updating the plugin and then its CocoaPods or Swift packages.
- If no updated version exists, ask the SDK provider or replace the SDK.
- Don't copy an SDK's practices into your own app's manifest to silence the email. Your manifest should only describe your own code.
Manifests, privacy labels and your privacy policy
A privacy manifest doesn't replace a privacy policy. Apple still requires a policy link in App Store Connect and inside the app under Guideline 5.1.1(i). The three should agree:
- the manifests describe what your code and SDKs do;
- your App Privacy answers in App Store Connect summarize it for the product page;
- your privacy policy explains it to people in full.
After you archive, open the archive in Xcode's Organizer and choose Generate Privacy Report. It lists what every manifest in the build declares, which is a good checklist for both your App Privacy answers and your privacy policy.
Frequently asked questions
Is ITMS-91053 a warning or a rejection?
It started as a warning in March 2024. Since May 1, 2024, Apple requires approved reasons for these APIs before it accepts a new app or update, so treat it as blocking.
My code doesn't call any of these APIs. Why did I get the email?
An SDK or framework in your app probably does. Update your dependencies to versions that ship their own privacy manifests, then upload again.
Do I still need a privacy policy if I have a privacy manifest?
Yes. The manifest is for Apple's tooling. Guideline 5.1.1(i) still requires a privacy policy link in App Store Connect and inside the app.