All rejection guidesGuideline 5.1.1
5.1.1
Guideline 5.1.1 rejection: privacy policy and permission prompts
Your privacy policy is missing or vague, or a permission prompt doesn’t clearly say why the app needs access.
“Ensure your purpose strings clearly and completely describe your use of the data.”
Why apps get rejected for it
- ×No privacy policy link in App Store Connect, or none inside the app.
- ×A policy that doesn’t list what data is collected, which third parties get it and how to delete it.
- ×Vague permission texts like “This app needs your location.”
- ×Asking for permissions on launch before the user knows why.
- ×Paid features that only work if the user allows tracking or data access.
- ×Requiring personal details that the core feature doesn’t need.
How to fix it
- 01Link the privacy policy in App Store Connect and in the app, usually in Settings.
- 02List every kind of data collected, every SDK that receives it, retention, and how to request deletion.
- 03Rewrite each purpose string with the reason and an example: for example “We use your location to show the air quality where you are.”
- 04Ask for each permission at the moment the feature needs it.
- 05Check the App Privacy answers in App Store Connect match the policy and the SDKs in the build.
What to tell App Review
Describe each change: “Updated the location purpose string to explain X, added the privacy policy link in Settings.” Purpose strings live in the build, so submit a new one.
Want a second pair of eyes before you resubmit?
The App Launch Audit checks your app against 5.1.1 and every other common rejection reason, and gives you a READY / NOT READY report with the exact fixes within 48 hours.
Not affiliated with Apple. The guidelines change; the full text on Apple's site is what counts. Last checked 5 October 2026.