Guideline 5.1.2: Data use & sharing
Your app sends user data somewhere without asking first, often via an analytics or ad SDK the founder never knew was in the build.
What Apple sent you
Guideline 5.1.2 - Legal - Privacy - Data Use and Sharing We noticed that your app collects and shares user data with third parties without first obtaining the user's permission. Specifically, the app privacy information you provided in App Store Connect does not accurately reflect the data collected by your app and its third-party SDKs. Apps that collect data in order to track users across apps and websites owned by other companies must also request permission using the App Tracking Transparency framework.
What it actually means
Apple's rule is simple: you may not use, transmit, or share someone's personal data without their permission first. You have to tell users where their data goes, including any third parties, and explicitly including third-party AI services, and get their consent before sharing it. Data collected for one purpose can't quietly be reused for another.
There's a second layer for tracking, meaning following a user's activity across apps and websites owned by other companies, usually for advertising. That requires an explicit yes through Apple's App Tracking Transparency system, the "Allow this app to track you?" popup you've seen in other apps. And your app can't punish users who decline: Apple bars apps from requiring tracking, notifications, or location access in exchange for features or rewards.
The rejection usually arrives with a mismatch attached: the privacy questionnaire you filled out in App Store Connect (which becomes the "privacy label" on your store page) says one thing, and the reviewer's analysis of your app's network traffic says another.
Why AI-built apps hit this
You almost certainly didn't write code that sells user data. But your app may still contain it. AI builders and templates routinely bundle analytics SDKs, crash reporters, and ad frameworks: prewritten packages that phone home with device data the moment the app launches. You never see it happen; Apple's automated review does.
Then comes the privacy questionnaire. A founder who doesn't know an SDK is collecting data answers "we collect nothing," and the label is now inaccurate, which is a rejection on its own. If any bundled SDK uses the device's advertising identifier, that's tracking, and tracking without the App Tracking Transparency prompt is exactly what this guideline forbids.
How to fix it
- Find out what's actually in your app. Ask your AI tool directly: "List every third-party SDK, analytics service, or advertising framework in this project, and what data each one collects or sends." Read the list. This is the inventory Apple already has.
- Remove what you don't need. If an analytics or ads SDK came with the template and you're not using its dashboard, tell your tool to remove it entirely. The least data you can leak is data you don't collect.
- Ask permission for what stays. For anything that counts as tracking, tell your tool to add the App Tracking Transparency prompt and to only start tracking after the user agrees. For other data sharing, the app must disclose it and get consent, and your privacy policy must say where the data goes.
- Redo the privacy questionnaire. In App Store Connect, update your app's privacy responses so they match the SDK inventory from step 1. Each SDK's website usually publishes exactly what to declare: search "[SDK name] privacy label" or ask your AI tool.
- Resubmit and explain. Use the review notes to say what you removed and what you now disclose, so the reviewer isn't left to rediscover it.
What to write in Resolution Center
Adapt this to what you actually changed; don't send it unmodified:
Hello,
Thank you for the feedback. We've reviewed the data our app collects and
made these changes:
- Removed the [SDK name] SDK, which was included by our development
template and was collecting [data type] without our knowledge
- [If applicable] Added the App Tracking Transparency prompt, and the app
no longer tracks users who decline
- Updated our App Store Connect privacy information to accurately reflect
the data collected by the app and its remaining SDKs
The app now only collects [data types], with user permission, as
disclosed in our privacy policy at [URL]. We'd appreciate a second look.
Thank you,
[Your name]
How to avoid it next time
Treat every package your AI tool adds as a potential data collector, and ask it to justify each one before you ship: what does this SDK send, and to whom? Re-run that inventory before each submission, since templates and dependency updates can add collectors you didn't ask for, and update the privacy questionnaire whenever the answer changes. If you don't need analytics yet, ship without them; you can always add an SDK later, with the disclosure done properly.
Related guides: 5.1.1: Data collection & storage (collecting more data than the app needs, or without a privacy policy) and 2.1: App completeness (the other rejection that comes from reviewers probing what your app actually does).