Guideline 4.8: Sign in with Apple (login services)
Your app offers Google or Facebook login but no privacy-focused option. Apple requires an equivalent choice, and Sign in with Apple satisfies it.
What Apple sent you
Guideline 4.8 - Design - Login Services We noticed that your app uses a third-party login service but does not offer as an equivalent option another login service with the following features: - The login service limits data collection to the user's name and email address. - The login service allows users to keep their email address private as part of setting up their account. - The login service does not collect interactions with your app for advertising purposes without consent. Next Steps Please revise your app to offer an equivalent login option that meets the requirements above.
What it actually means
Your app lets people sign in with a third-party service (Google, Facebook, X, LinkedIn, Amazon, or WeChat) but offers no alternative that respects their privacy. Apple's rule: if you use a third-party or social login to set up the user's primary account, you must also offer another login option that limits data collection to name and email, lets users keep their email address private, and doesn't collect their interactions with your app for advertising without consent.
Sign in with Apple meets all three requirements, which is why everyone calls this "the Sign in with Apple rule", but the guideline is written around the requirements, not the button.
Two exemptions worth knowing. If your app only uses your own email and password system, with no Google button at all, the rule doesn't apply. And if your app is a client for one specific service (say, an app that only works with a Google account because it manages Google data), users signing in to that service directly is fine. The rejection means Apple decided neither exemption fits your app.
Why AI-built apps hit this
Ask an AI builder for authentication and you get the industry default: email plus a "Continue with Google" button, because that's what every web app ships and what Supabase, Firebase, and Clerk enable in one click. On the web that's the finish line. On iOS, that Google button is precisely the trigger for 4.8, and Sign in with Apple never gets added because it's meaningless on the web, so no tool includes it unprompted.
The result is an app that's one login button short of compliant, built by a founder who had no reason to know the button was required.
How to fix it
- Decide: add Apple, or drop the social logins. Both paths comply. If Google login isn't actually pulling its weight, removing it (and keeping just email/password) exempts you from the rule entirely and is the fastest fix. Otherwise, add Sign in with Apple alongside it.
- Tell your AI tool to add Sign in with Apple through your auth provider. Supabase, Firebase, and Clerk all support it natively. A prompt like "add Sign in with Apple as a login option using our existing [Supabase/Firebase/Clerk] auth" is usually enough for the app side.
- Configure the Apple side in the browser. Your auth provider's docs have a step-by-step page for this: you create the identifiers and keys in Apple's developer portal (a website, no code involved) and paste the values into your provider's dashboard. Budget half an hour and follow it exactly; this is where typos hide.
- Test the private email option. Sign in with Apple offers "Hide My Email," which gives your app a relay address. Make sure account creation works when the user picks it; apps that break on relay addresses get re-rejected.
- Place the button with the others and resubmit. Sign in with Apple should appear as a peer of your Google or Facebook buttons on the same screen, not buried behind a "more options" link.
What to write in Resolution Center
Adapt this to what you actually changed; don't send it unmodified:
Hello,
Thank you for the feedback. We've added Sign in with Apple as an
equivalent login option alongside [Google/Facebook] login:
- It appears on the same sign-in screen as the other login options
- It limits data collection to name and email address
- Users can keep their email address private via Hide My Email
The new build is [build number]. We'd appreciate a second review.
Thank you,
[Your name]
How to avoid it next time
Treat login options as an iOS decision, not a web default. Before you submit, look at your sign-in screen: if any third-party or social login button is on it, Sign in with Apple (or another option meeting the privacy requirements) needs to be there too. Cheapest of all is asking for it up front: "set up auth with email, Google, and Sign in with Apple" costs one extra clause in your first prompt.
Related guides: 5.1.1: Data collection and storage (asking for more data at sign-up than the app needs) and 5.1.2: Data use and sharing (what you're allowed to do with the data once you have it).