What the rejection says
Guideline 4.8 – Design – Login Services
The app uses a third-party login service, but does not appear to offer an equivalent login option with the following features…
What Apple actually means
Apps that use a third-party or social login “to set up or authenticate the user’s primary account with the app must also offer as an equivalent option another login service” that:
- limits data collection to the user’s name and email address;
- allows users to keep their email address private as part of setting up their account; and
- does not collect interactions with your app for advertising purposes without consent.
It’s not required if your app only uses your own company’s account system, is an education or enterprise app that requires an existing school or work account, uses a government or industry-backed ID, or is a client for a specific third-party service (for example, a mail app that signs in to that mail account).
Why AI-built apps hit it so often
Supabase and Firebase starter templates, and the auth screens AI builders generate, default to “Continue with Google” because it’s one click on the web. Wrapped or ported to iOS, that is precisely the 4.8 pattern.
How to fix it
- Enable Sign in with Apple for your App ID in the Apple Developer portal and create the key your auth provider needs.
- Turn on the Apple provider in Supabase, Firebase or your own auth, and configure the service ID and key.
- Use the native button and flow (
AuthenticationServiceson iOS;expo-apple-authenticationin Expo;sign_in_with_applein Flutter) and exchange the identity token with your backend. - Handle private relay emails (
@privaterelay.appleid.com). Don’t treat them as invalid, and make sure transactional email reaches them. - Handle the name only arriving on first sign-in. Apple sends the user’s name once. Save it then.
- Place the button as an equal option next to Google.
- Account deletion: when users delete their account, revoke the Apple token too (see 5.1.1).
What to write back to App Review
Hello App Review,
Sign in with Apple is now offered as an equivalent option alongside
Google on the sign-in and sign-up screens. It limits data collection to
name and email, supports Hide My Email, and is not used for advertising.
How we handle a 4.8
We set up the Apple key and service ID, add the native flow to your auth provider, handle relay emails and first-login names, and test sign-up, sign-in and deletion on a real device before we resubmit.
Questions
Do I have to use Sign in with Apple specifically?
My app only has email and password. Do I need Sign in with Apple?
Where should the Apple button go?
Does Supabase support Sign in with Apple?
Last reviewed 2026-09-23. Guideline quotes are from Apple’s App Review Guidelines; Apple can change them at any time.

