Skip to content

[ Guideline 5.1.1 · Legal – Privacy – Data Collection and Storage ]

Guideline 5.1.1 Data Collection and Storage: account deletion, privacy policy and permissions

Short answer

5.1.1 covers how your app collects personal data. The five most common failures: no way to delete an account inside the app, a missing or mismatched privacy policy, vague permission prompts (“This app needs camera access”), forcing a login the app doesn’t need, and asking for more data than the feature uses.

What the rejection says

Guideline 5.1.1 – Legal – Privacy – Data Collection and Storage

The app supports account creation but does not include an option to initiate account deletion.

Other versions point to a missing privacy policy link, a permission request whose purpose string doesn’t explain the use, or an app that requires registration before showing features that don’t need an account.

What Apple actually means

5.1.1 has several parts. These are the ones that sink most apps:

  • (i) Privacy policies. “All apps must include a link to their privacy policy in the App Store Connect metadata field and within the app in an easily accessible manner.” The policy must say what you collect, how, why, who you share it with, and how users can revoke consent or request deletion.
  • (ii) Permission. “Ensure your purpose strings clearly and completely describe your use of the data.” Paid features can’t depend on the user granting data access.
  • (iii) Data minimization. Only request what the feature needs. Apple prefers the out-of-process photo picker or share sheet over full Photos or Contacts access.
  • (v) Account sign-in. “If your app doesn’t include significant account-based features, let people use it without a login. If your app supports account creation, you must also offer account deletion within the app.”

Why AI-built apps hit it so often

  • Auth templates stop at sign-up. Supabase and Firebase starter flows give you sign-up, sign-in and password reset. Delete-account is almost never generated.
  • Generated permission strings are generic. “This app requires access to your camera” fails; “Take a photo of your receipt to add it to an expense” passes.
  • Privacy policies from generators that don’t match what the app actually does, especially when it sends data to analytics or AI services.
  • Login walls by default. Builders often put auth in front of everything, even a calculator or a content browser.
  • Over-broad permissions: full photo library access to set one avatar, contacts access for an “invite” button.

How to fix it

  1. Add in-app account deletion. A clearly labelled “Delete account” in Settings, a confirmation step, and a backend job that actually deletes the user and their data (for Supabase, a server-side function using the service role, never the client). Sign the user out afterwards.
  2. Link the privacy policy in App Store Connect and inside the app. Make sure it names every third party that receives data: analytics, crash reporting, payments, AI providers.
  3. Rewrite every purpose string in Info.plist as what and why, specific to your feature.
  4. Ask for permissions at the moment they’re needed, not all at once on first launch.
  5. Remove the login wall from anything that doesn’t need an account, or add a guest mode.
  6. Use the system photo picker instead of requesting full library access where you can.
  7. Update the App Privacy answers in App Store Connect so they match the policy and the code.

What to write back to App Review

Hello App Review,

We have addressed Guideline 5.1.1:

- Account deletion: Settings > Account > Delete account. Deletion removes
  the account and associated data from our servers.
- Privacy policy: linked in App Store Connect and at Settings > Privacy.
- Updated the camera purpose string to explain it is used to [specific use].

Demo account: [email] / [password]

How we handle a 5.1.1

We add the deletion flow end to end (UI, confirmation and server-side delete), fix the purpose strings, line up the privacy policy with what the code really sends, update the App Privacy answers and resubmit. If your app sends user content to an AI model, we also fix the disclosure and consent that 5.1.2 now requires.

Questions

Is a ‘contact us to delete your account’ email enough?
No. If the app lets people create an account, Apple requires that they can start account deletion from inside the app. Linking to a web page that completes deletion can be acceptable, but the path has to start in the app and actually delete the account, not just deactivate it.
Where does the privacy policy link need to be?
In two places: the Privacy Policy URL field in App Store Connect, and somewhere easy to find inside the app, usually Settings or the sign-up screen.
What is a purpose string?
It’s the sentence iOS shows in the permission prompt, set in Info.plist (for example NSCameraUsageDescription). Apple wants it to say specifically why the app needs the permission and what it does with the data.
Do I need login at all?
Only if your core features are account-based. Apple’s rule: if the app doesn’t have significant account-based features, let people use it without logging in.

Last reviewed 2026-09-23. Guideline quotes are from Apple’s App Review Guidelines; Apple can change them at any time.

Next step

Stuck in App Review? Send us the message.

Tell us what you built it with and paste Apple’s rejection. You get a plain-English diagnosis and a fixed price within one business day.