Guideline5.1.1

Privacy

5.1.1 is about what you collect and how you explain it. A permission you never use, a vague purpose string, or tracking without ATT is enough.

§ 01What this rejection usually means

  • Apple is not debating your product. They are rejecting the data request or the explanation.
  • Privacy Nutrition Labels that disagree with the binary are in the same family of problems.
  • Some 5.1.1 notes can be answered with a reply (why you need the data). Unused entitlements need a new build.

§ 02Common causes

  • Camera, photos, contacts, tracking, or location requested without a precise purpose string.
  • A permission in Info.plist that the current build never calls.
  • Clipboard, pasteboard, or tracking used before a prompt.
  • App Privacy answers that do not match the SDK list.
  • ATT missing when a third-party SDK fingerprints or requests IDFA.

§ 03How to diagnose your case

  1. Dump Info.plist purpose keys and match each to a user-visible feature.
  2. If a key has no feature, remove it and ship a new build.
  3. If the feature is real but the string is vague, a tighter string plus a short reply can be enough.

§ 05What to inspect in your project

Checklist

  • NSCameraUsageDescription and every other purpose string
  • PrivacyInfo / Privacy Manifest for third-party SDKs
  • App Privacy answers in App Store Connect
  • ATT prompt timing vs. first tracking call
  • Pasteboard and contacts access on first launch

§ 06What not to do

Do not

  • Do not copy a generic “for a better experience” purpose string.
  • Do not leave an unused permission “for later.”
  • Do not tell the reviewer you will add ATT in the next version. Add it now.

§ 07Questions people ask next

Is ATT always Guideline 5.1.1?
Tracking usually lands in 5.1.2, but reviewers often write 5.1.1 and mention tracking in the same note. Treat the wording as the signal.

Related rejection wording