Does your iOS app need a privacy policy?
Yes. Apple's App Store Review Guideline 5.1.1(i) says that all apps must include a link to their privacy policy, both in the App Store Connect metadata and inside the app, where users can easily find it. That applies to free apps, paid apps, games and utilities, and to apps that don't have accounts or collect any data. An app without a working privacy policy link is rejected in review.
Where to add the privacy policy URL
- App Store Connect: open your app, go to App Privacy and enter the URL in the Privacy Policy field. There is also an optional field for a page where users can manage their privacy choices.
- Inside the app: add a link in Settings, an About screen or your sign-up flow. Reviewers look for it.
- Your website: if the app has a marketing site, link the same policy from its footer.
The URL needs to open without a login, load on a phone, and stay at the same address. Documents that need sign-in, shared-drive files with restricted access or links that change between versions cause problems in review and for your users. A hosted Legiflare page gives you a permanent link that you can update without changing the URL.
What Apple requires the policy to say
Guideline 5.1.1(i) asks for a policy that clearly and explicitly:
- identifies what data the app or service collects, how it collects that data, and all the ways it uses it;
- confirms that any third party you share data with, such as analytics tools, ad networks and third-party SDKs, provides the same or equal protection of user data as your policy states;
- explains how long you keep data and how you delete it; and
- describes how users can revoke consent or request deletion of their data.
On top of that, the privacy laws that apply to your users add their own requirements, such as the GDPR in Europe and the CCPA in California. The privacy policy template includes sections for all of these.
Your privacy policy, privacy labels and SDKs
Apple also asks you to fill in the App Privacy details that appear on your App Store page, often called privacy nutrition labels. Your answers there and your privacy policy must tell the same story. If your labels say you collect crash data and email addresses, your policy should say so too.
Remember to include data collected by third-party SDKs, not just by your own code. Common examples in iOS apps are:
- Analytics: Firebase Analytics, Mixpanel, Amplitude
- Crash reporting: Firebase Crashlytics, Sentry
- Advertising: Google AdMob and mediation networks
- Sign-in and backend: Sign in with Apple, Firebase Authentication, Supabase
- Payments: in-app purchases are processed by Apple; external payments by providers such as Stripe
Apple also expects apps and many widely used SDKs to ship privacy manifests that describe the data they collect. Check each SDK's documentation and reflect it in your policy.
Tracking and App Tracking Transparency
If your app tracks users across apps and websites owned by other companies, for example to target or measure ads, you must ask for permission with the App Tracking Transparency prompt first. Your privacy policy should explain what tracking happens, which partners are involved and how users can change their choice.
Account deletion
If users can create an account in your app, Apple requires that they can also start deleting it from within the app. Describe the process in your privacy policy, including what is deleted, what you keep and for how long.
Checklist before you submit
- The policy lists everything your app and its SDKs collect.
- It matches your App Privacy answers in App Store Connect.
- It explains retention, deletion and how to withdraw consent.
- It has a contact email that someone reads.
- The URL is public, loads on mobile and is entered in App Store Connect.
- The same link is reachable from inside the app.
Frequently asked questions
Does a free app with no accounts need a privacy policy?
Yes. Apple requires a privacy policy link for every app. If your app really collects no data, the policy can be short and say exactly that, but it still needs to exist at a public URL.
Can I use the same privacy policy for iOS and Android?
Yes, if both versions collect the same data. One URL is easier to maintain. If the Android version uses different SDKs, make sure the policy covers both.
Do I need a website to publish my privacy policy?
No. You only need a public URL. Legiflare hosts your policy on a permanent link that you can paste into App Store Connect without buying a domain or setting up hosting.
What happens if I change the policy later?
Update the text and the date at the top. With a hosted page the URL stays the same, so you don't need to resubmit the link, but keep your App Privacy answers in sync.