How to fix an App Store Guideline 5.1.1 rejection

Guideline 5.1.1 is about data collection and storage. Most privacy policy rejections come down to a missing link, a link that does not work, or a policy that leaves out what Apple asks for. Here is how to find the cause and fix it.

Last reviewed September 2026. General information, not legal advice.

What the rejection means

The message usually starts with "Guideline 5.1.1 - Legal - Privacy - Data Collection and Storage". Guideline 5.1.1 contains several rules, including:

  • 5.1.1(i), privacy policies: every app needs a privacy policy link in App Store Connect and inside the app;
  • 5.1.1(ii), permission: apps must ask for consent and explain clearly why they need data;
  • 5.1.1(iii), data minimization: only request data the app actually needs;
  • 5.1.1(v), account sign-in: don't force a login for features that don't need one, and let users delete accounts they create in the app.

Read the reviewer's note carefully. It usually names the specific rule and sometimes includes a screenshot of the problem.

Common privacy policy causes

  1. No URL in App Store Connect. The Privacy Policy field under App Privacy is empty or has a placeholder.
  2. No link inside the app. The policy has to be easy to find in the app itself, for example in Settings or on the sign-up screen.
  3. The link doesn't work for the reviewer. It returns an error, needs a login, redirects to a home page or is blocked in their region.
  4. The policy isn't about this app. It's a generic text, belongs to another app, or names a different company.
  5. Required content is missing. Apple expects the policy to say what data is collected, how and why; that third parties you share data with protect it as well as you do; how long data is kept and how it's deleted; and how users can revoke consent or request deletion.
  6. It contradicts your App Privacy answers. Your privacy labels say one thing and the policy says another.

Other 5.1.1 causes that look similar

  • Vague permission messages. The text shown when the app asks for the camera, location or contacts must explain specifically why the app needs it.
  • No in-app account deletion. If users can create an account in the app, they must be able to start deleting it from within the app.
  • Unnecessary login. If the app's main features don't depend on an account, Apple expects people to be able to use them without signing in.

Fix checklist

  1. Publish the policy on a public page that loads without a login. See free hosting options.
  2. Make sure it names your app and the same developer or company as your App Store listing.
  3. Cover every item Apple lists, including data collected by SDKs. The template has a section for each.
  4. Compare it with your App Privacy answers and fix any differences.
  5. Enter the URL in App Store Connect and add a visible link inside the app.
  6. Open the link in a private browser window and on a phone before you resubmit.

Replying to App Review

Reply to the rejection in App Store Connect and explain what you changed. If the link was already in the app, say exactly where it is, for example "Settings > Privacy Policy", and attach a screenshot. Clear, specific replies help the reviewer confirm the fix quickly.

Frequently asked questions

Do I need a new build to fix a 5.1.1 privacy policy rejection?

Only if something inside the app has to change, such as adding the in-app link or account deletion. If the problem was the URL or the policy text, update those, reply to App Review and resubmit.

My policy link works for me. Why did the reviewer say it doesn't?

You may be signed in to the site that hosts it, or the page may block some regions or automated traffic. Test it in a private window and from another network.

Does my app need a privacy policy if it collects no data?

Yes. See privacy policies for apps that collect no data for what it should say.

Fix your privacy policy link today

Publish a complete policy on a permanent URL and resubmit with confidence. Free.