Skip to content

[ Guideline 5.1.2 · Legal – Privacy – Data Use and Sharing ]

Guideline 5.1.2 and third-party AI: disclosing OpenAI, Claude and Gemini in your app

Short answer

If your app sends anything personal to OpenAI, Anthropic, Google or another AI provider, 5.1.2 requires you to tell the user which provider gets it and get their explicit permission before sending it. Apple names third-party AI in the guideline. Most AI-built apps call a model API straight from the first chat message with no disclosure, and that’s the rejection.

What the rejection says

Guideline 5.1.2 – Legal – Privacy – Data Use and Sharing

The app shares the user’s personal data with a third-party AI service but does not clearly disclose this or obtain the user’s permission before doing so.

Wording varies, but when an AI feature is involved it comes down to disclosure and consent.

What Apple actually means

The guideline now says: “You must clearly disclose where personal data will be shared with third parties, including with third-party AI, and obtain explicit permission before doing so.”

That sentence is why AI features that were approved a year ago get rejected on their next update.

The same section also says your app “may not require users to enable system functionalities (e.g. push notifications, location services, tracking) in order to access functionality,” and that tracking needs permission through the App Tracking Transparency APIs.

Why AI-built apps hit it so often

  • The AI call is wired in on the first prompt. Builders generate a chat screen that posts user text straight to the model API with no disclosure step.
  • The provider isn’t named anywhere. The user can’t tell whether their journal entry, photo or symptoms go to OpenAI, Anthropic or Google.
  • Health, finance and journaling apps send the most sensitive data and get the closest review.
  • The privacy policy doesn’t mention the AI provider at all, or the App Privacy answers in App Store Connect say “data not collected”.

How to fix it

  1. Add a consent screen before the first AI request. Say in one or two sentences what is sent (“your messages and any photos you attach”), who receives it (“OpenAI, to generate replies”), and what they do with it. Offer Allow and Not now.
  2. Store the choice and respect it. If they decline, the rest of the app should still work; only the AI feature is unavailable.
  3. Let users change their mind in Settings.
  4. Name the provider in the privacy policy and describe retention: yours and the provider’s API policy.
  5. Update App Privacy in App Store Connect so the data types you send are declared.
  6. Send only what the feature needs. Strip account details and identifiers from prompts where you can.
  7. Keep the API key on your server. A model key in the app bundle or client JavaScript is a separate, more expensive problem (see our key scanner).

What to write back to App Review

Hello App Review,

We now show a disclosure screen before any personal data is sent to a
third-party AI service. It explains that [data types] are sent to
[Provider] to [purpose], and the user must tap "Allow" before the first
request. Users can withdraw consent at Settings > AI features.

The privacy policy and App Privacy details have been updated to match.

How we handle a 5.1.2

We add the consent flow, move model calls behind your own server if they aren’t already, clean personal identifiers out of prompts, and bring the privacy policy and App Privacy answers in line with the code. If we find the model key exposed in the client, that gets fixed first.

Questions

Does this apply if I don’t store the data?
Yes. The rule is about sharing personal data with a third party, and sending a prompt to a model provider is sharing, even if neither of you keeps it.
Is a line in the privacy policy enough?
Not on its own. The guideline asks for clear disclosure and explicit permission before sharing. Put a short consent screen in the app before the first AI request, and keep the privacy policy consistent with it.
What counts as personal data here?
Anything that could relate to a person: messages they type, photos, voice, health or fitness data, location, contacts, and account details. If the AI feature takes user input, assume it’s in scope.
What about App Tracking Transparency?
ATT is a separate part of 5.1.2 about tracking across other companies’ apps and websites. If you use advertising or attribution SDKs that track, you need the ATT prompt as well.

Last reviewed 2026-09-23. Guideline quotes are from Apple’s App Review Guidelines; Apple can change them at any time.

Next step

Stuck in App Review? Send us the message.

Tell us what you built it with and paste Apple’s rejection. You get a plain-English diagnosis and a fixed price within one business day.