Skip to content

[ Guideline 4.8 · Design – Login Services ]

Guideline 4.8 Login Services: when you need Sign in with Apple

Short answer

If people can sign in to your app with Google, Facebook, X, LinkedIn or another third-party account, you must also offer an equivalent privacy-focused login: one that only collects name and email, lets users hide their email, and doesn’t track them for ads. Sign in with Apple meets all three and is the usual fix. Apps that only use their own email and password login don’t need it.

What the rejection says

Guideline 4.8 – Design – Login Services

The app uses a third-party login service, but does not appear to offer an equivalent login option with the following features…

What Apple actually means

Apps that use a third-party or social login “to set up or authenticate the user’s primary account with the app must also offer as an equivalent option another login service” that:

  • limits data collection to the user’s name and email address;
  • allows users to keep their email address private as part of setting up their account; and
  • does not collect interactions with your app for advertising purposes without consent.

It’s not required if your app only uses your own company’s account system, is an education or enterprise app that requires an existing school or work account, uses a government or industry-backed ID, or is a client for a specific third-party service (for example, a mail app that signs in to that mail account).

Why AI-built apps hit it so often

Supabase and Firebase starter templates, and the auth screens AI builders generate, default to “Continue with Google” because it’s one click on the web. Wrapped or ported to iOS, that is precisely the 4.8 pattern.

How to fix it

  1. Enable Sign in with Apple for your App ID in the Apple Developer portal and create the key your auth provider needs.
  2. Turn on the Apple provider in Supabase, Firebase or your own auth, and configure the service ID and key.
  3. Use the native button and flow (AuthenticationServices on iOS; expo-apple-authentication in Expo; sign_in_with_apple in Flutter) and exchange the identity token with your backend.
  4. Handle private relay emails (@privaterelay.appleid.com). Don’t treat them as invalid, and make sure transactional email reaches them.
  5. Handle the name only arriving on first sign-in. Apple sends the user’s name once. Save it then.
  6. Place the button as an equal option next to Google.
  7. Account deletion: when users delete their account, revoke the Apple token too (see 5.1.1).

What to write back to App Review

Hello App Review,

Sign in with Apple is now offered as an equivalent option alongside
Google on the sign-in and sign-up screens. It limits data collection to
name and email, supports Hide My Email, and is not used for advertising.

How we handle a 4.8

We set up the Apple key and service ID, add the native flow to your auth provider, handle relay emails and first-login names, and test sign-up, sign-in and deletion on a real device before we resubmit.

Questions

Do I have to use Sign in with Apple specifically?
The guideline asks for a login service with specific privacy features. Sign in with Apple is the most common way to meet it and the one reviewers expect, but it isn’t the only one.
My app only has email and password. Do I need Sign in with Apple?
No. Apps that exclusively use their own account system are exempt.
Where should the Apple button go?
Next to your other login options, as an equal choice. It shouldn’t be hidden below the fold or behind a ‘more options’ link.
Does Supabase support Sign in with Apple?
Yes. Supabase and Firebase both support it. On iOS you should use the native Apple sign-in flow and pass the identity token to your auth provider rather than a web redirect.

Last reviewed 2026-09-23. Guideline quotes are from Apple’s App Review Guidelines; Apple can change them at any time.

Next step

Stuck in App Review? Send us the message.

Tell us what you built it with and paste Apple’s rejection. You get a plain-English diagnosis and a fixed price within one business day.