What the rejection says
Guideline 5.1.1 – Legal – Privacy – Data Collection and Storage
The app supports account creation but does not include an option to initiate account deletion.
Other versions point to a missing privacy policy link, a permission request whose purpose string doesn’t explain the use, or an app that requires registration before showing features that don’t need an account.
What Apple actually means
5.1.1 has several parts. These are the ones that sink most apps:
- (i) Privacy policies. “All apps must include a link to their privacy policy in the App Store Connect metadata field and within the app in an easily accessible manner.” The policy must say what you collect, how, why, who you share it with, and how users can revoke consent or request deletion.
- (ii) Permission. “Ensure your purpose strings clearly and completely describe your use of the data.” Paid features can’t depend on the user granting data access.
- (iii) Data minimization. Only request what the feature needs. Apple prefers the out-of-process photo picker or share sheet over full Photos or Contacts access.
- (v) Account sign-in. “If your app doesn’t include significant account-based features, let people use it without a login. If your app supports account creation, you must also offer account deletion within the app.”
Why AI-built apps hit it so often
- Auth templates stop at sign-up. Supabase and Firebase starter flows give you sign-up, sign-in and password reset. Delete-account is almost never generated.
- Generated permission strings are generic. “This app requires access to your camera” fails; “Take a photo of your receipt to add it to an expense” passes.
- Privacy policies from generators that don’t match what the app actually does, especially when it sends data to analytics or AI services.
- Login walls by default. Builders often put auth in front of everything, even a calculator or a content browser.
- Over-broad permissions: full photo library access to set one avatar, contacts access for an “invite” button.
How to fix it
- Add in-app account deletion. A clearly labelled “Delete account” in Settings, a confirmation step, and a backend job that actually deletes the user and their data (for Supabase, a server-side function using the service role, never the client). Sign the user out afterwards.
- Link the privacy policy in App Store Connect and inside the app. Make sure it names every third party that receives data: analytics, crash reporting, payments, AI providers.
- Rewrite every purpose string in Info.plist as what and why, specific to your feature.
- Ask for permissions at the moment they’re needed, not all at once on first launch.
- Remove the login wall from anything that doesn’t need an account, or add a guest mode.
- Use the system photo picker instead of requesting full library access where you can.
- Update the App Privacy answers in App Store Connect so they match the policy and the code.
What to write back to App Review
Hello App Review,
We have addressed Guideline 5.1.1:
- Account deletion: Settings > Account > Delete account. Deletion removes
the account and associated data from our servers.
- Privacy policy: linked in App Store Connect and at Settings > Privacy.
- Updated the camera purpose string to explain it is used to [specific use].
Demo account: [email] / [password]
How we handle a 5.1.1
We add the deletion flow end to end (UI, confirmation and server-side delete), fix the purpose strings, line up the privacy policy with what the code really sends, update the App Privacy answers and resubmit. If your app sends user content to an AI model, we also fix the disclosure and consent that 5.1.2 now requires.
Questions
Is a ‘contact us to delete your account’ email enough?
Where does the privacy policy link need to be?
What is a purpose string?
Do I need login at all?
Last reviewed 2026-09-23. Guideline quotes are from Apple’s App Review Guidelines; Apple can change them at any time.

