5.1.1BlockerVerified against Apple's guidelines 2026-08-12

Guideline 5.1.1: Data collection & storage

Your app collects data without the required privacy plumbing: a privacy policy, honest permission prompts, or the in-app account deletion Apple requires.

What Apple sent you

Guideline 5.1.1 - Legal - Privacy - Data Collection and Storage

We noticed that your app supports account creation but does not include an
option to initiate account deletion.

Apps that support account creation must also offer account deletion to
give App Store users more control of the data they've shared while using
an app.

What it actually means

Guideline 5.1.1 is Apple's privacy rulebook, and your app is missing one of its required pieces. The rejection email will point at one (or several) of these:

  • No account deletion. If people can create an account in your app, they must be able to delete it from inside the app too. A support email address or a link that says "contact us" doesn't count; deletion has to start in the app. This is rule 5.1.1(v), and since 2022 it's been one of the most-enforced rules on the store.
  • No privacy policy. Every app needs a working privacy policy link in App Store Connect that says what you collect, how it's used, and how people can get it deleted.
  • Vague permission prompts. When your app asks for the camera, location, photos, or contacts, iOS shows your explanation (the "purpose string"). "This app needs camera access" gets rejected; you have to say why.
  • Collecting more than you need. Requiring personal information the app doesn't actually need to function, like demanding a full profile to use a calculator, is itself a violation.

Why AI-built apps hit this

AI builders wire up authentication in one prompt ("add user accounts") and every popular auth service makes sign-up effortless. Nobody prompts for account deletion, so it never gets built, and it's invisible in your own testing because you never try to leave your own app.

Privacy policies have the same shape: they're not a screen, so no screen- generating tool creates one. And permission prompts default to whatever boilerplate the template contained, which is exactly the vague phrasing Apple rejects.

How to fix it

  1. Add a "Delete account" option in your app's settings. Tell your AI tool explicitly: "Add a Delete Account button in settings. It must delete the user's account and their data from [your auth service/database], ask for confirmation first, and sign the user out afterwards." Verify it really deletes the record; Apple may test it.
  2. If some data must legally be kept (payment records, for instance), delete everything else and tell the user what's retained and why.
  3. Publish a privacy policy. Write it in plain language: what you collect, what it's for, what third-party services receive it (your auth provider, analytics, hosting), how someone gets their data deleted. Host it on your website and paste the URL into App Store Connect → App Privacy.
  4. Fix your purpose strings. For each permission your app requests, write one sentence that names the feature: "Your camera is used to scan receipts so you don't have to type them." If you can't name the feature, your app shouldn't request the permission.
  5. Match your privacy labels to reality. In App Store Connect's App Privacy section, declare what your app and its SDKs actually collect. Analytics tools count even if you never look at the dashboard.

What to write in Resolution Center

Hello,

We've made the following changes to comply with Guideline 5.1.1:

- Added account deletion in Settings → Account → Delete Account. It removes
  the user's account and associated data from our systems after
  confirmation. (Demo account: [credentials], if you'd like to verify.)
- Published our privacy policy at [URL] and added it in App Store Connect.
- Updated all permission purpose strings to explain the specific feature
  each permission enables.

A new build ([build number]) is submitted. Thank you for reviewing again.

[Your name]

How to avoid it next time

The moment you add accounts to any future app, add deletion in the same sitting: one prompt to your AI tool instead of a rejection later. Keep a privacy policy template you reuse: the services you build with (auth, database, analytics) barely change between projects, so neither does the policy. And before submitting, open iOS Settings → your app and read every permission it requests; each one needs a reason you can say out loud.

Related guides: 5.1.2: Data use & sharing (what you're allowed to do with collected data) and 4.8: Sign in with Apple (required if you offer social logins).

Related guides

Stop rejections before they happen

The free check runs findings like these against your real App Store Connect data. The paid plan will fix them on every release. Join the list to hear when it launches.

One email when it launches. Unsubscribe any time.