All rejection guidesGuideline 5.1.1

5.1.1

Guideline 5.1.1 rejection: privacy policy and permission prompts

Your privacy policy is missing or vague, or a permission prompt doesn’t clearly say why the app needs access.

“Ensure your purpose strings clearly and completely describe your use of the data.”
App Review Guidelines, 5.1.1 Data Collection and Storage

Why apps get rejected for it

  • ×No privacy policy link in App Store Connect, or none inside the app.
  • ×A policy that doesn’t list what data is collected, which third parties get it and how to delete it.
  • ×Vague permission texts like “This app needs your location.”
  • ×Asking for permissions on launch before the user knows why.
  • ×Paid features that only work if the user allows tracking or data access.
  • ×Requiring personal details that the core feature doesn’t need.

How to fix it

  1. 01Link the privacy policy in App Store Connect and in the app, usually in Settings.
  2. 02List every kind of data collected, every SDK that receives it, retention, and how to request deletion.
  3. 03Rewrite each purpose string with the reason and an example: for example “We use your location to show the air quality where you are.”
  4. 04Ask for each permission at the moment the feature needs it.
  5. 05Check the App Privacy answers in App Store Connect match the policy and the SDKs in the build.

What to tell App Review

Describe each change: “Updated the location purpose string to explain X, added the privacy policy link in Settings.” Purpose strings live in the build, so submit a new one.

Want a second pair of eyes before you resubmit?

The App Launch Audit checks your app against 5.1.1 and every other common rejection reason, and gives you a READY / NOT READY report with the exact fixes within 48 hours.

Not affiliated with Apple. The guidelines change; the full text on Apple's site is what counts. Last checked 5 October 2026.