What the rejection says
Guideline 5.1.2 – Legal – Privacy – Data Use and Sharing
The app shares the user’s personal data with a third-party AI service but does not clearly disclose this or obtain the user’s permission before doing so.
Wording varies, but when an AI feature is involved it comes down to disclosure and consent.
What Apple actually means
The guideline now says: “You must clearly disclose where personal data will be shared with third parties, including with third-party AI, and obtain explicit permission before doing so.”
That sentence is why AI features that were approved a year ago get rejected on their next update.
The same section also says your app “may not require users to enable system functionalities (e.g. push notifications, location services, tracking) in order to access functionality,” and that tracking needs permission through the App Tracking Transparency APIs.
Why AI-built apps hit it so often
- The AI call is wired in on the first prompt. Builders generate a chat screen that posts user text straight to the model API with no disclosure step.
- The provider isn’t named anywhere. The user can’t tell whether their journal entry, photo or symptoms go to OpenAI, Anthropic or Google.
- Health, finance and journaling apps send the most sensitive data and get the closest review.
- The privacy policy doesn’t mention the AI provider at all, or the App Privacy answers in App Store Connect say “data not collected”.
How to fix it
- Add a consent screen before the first AI request. Say in one or two sentences what is sent (“your messages and any photos you attach”), who receives it (“OpenAI, to generate replies”), and what they do with it. Offer Allow and Not now.
- Store the choice and respect it. If they decline, the rest of the app should still work; only the AI feature is unavailable.
- Let users change their mind in Settings.
- Name the provider in the privacy policy and describe retention: yours and the provider’s API policy.
- Update App Privacy in App Store Connect so the data types you send are declared.
- Send only what the feature needs. Strip account details and identifiers from prompts where you can.
- Keep the API key on your server. A model key in the app bundle or client JavaScript is a separate, more expensive problem (see our key scanner).
What to write back to App Review
Hello App Review,
We now show a disclosure screen before any personal data is sent to a
third-party AI service. It explains that [data types] are sent to
[Provider] to [purpose], and the user must tap "Allow" before the first
request. Users can withdraw consent at Settings > AI features.
The privacy policy and App Privacy details have been updated to match.
How we handle a 5.1.2
We add the consent flow, move model calls behind your own server if they aren’t already, clean personal identifiers out of prompts, and bring the privacy policy and App Privacy answers in line with the code. If we find the model key exposed in the client, that gets fixed first.
Questions
Does this apply if I don’t store the data?
Is a line in the privacy policy enough?
What counts as personal data here?
What about App Tracking Transparency?
Last reviewed 2026-09-23. Guideline quotes are from Apple’s App Review Guidelines; Apple can change them at any time.

