Reference library · App Review

Guideline 5.1.1 Data Collection and Storage: account deletion, purpose strings and forced logins

5.1.1 has ten sub-points, but indie apps keep failing the same four. Each has a specific, quick fix.

Guideline 5.1.15. Legal · Data Collection and StorageApple text last updated June 8, 2026
Updated 7 min read

Checked against Apple's App Review Guidelines (last updated June 8, 2026), Apple's account-deletion support page and permission documentation, on Oct 1, 2026.

The short answer

Guideline 5.1.1 governs how apps collect and store personal data. Most indie rejections come from four gaps: account creation without in-app account deletion, purpose strings that don't say what the data is for, requiring sign-up for features that aren't account-based, and a missing or vague privacy policy. Fix the specific gap, update your App Privacy details if they changed, and reply with exact steps.

Sub-points
10
(i) through (x)
In-app account deletion
Required
Since June 30, 2022, if you allow sign-up
Deactivation instead
Not enough
Apple's own wording: insufficient
Crypto exchanges
Regulated
Added to 5.1.1(ix) on Nov 13, 2025

01What 5.1.1 covers, and the parts that catch indie apps

Guideline 5.1.1 sits under 5.1 Privacy in the Legal section and runs from (i) to (x). Some sub-points rarely touch a small app — (vii) on SafariViewController, (viii) on compiling personal data from public sources. Five of them account for nearly every indie rejection we see:

The sub-points that reject indie apps
Sub-pointWhat it requiresTypical failure
(i) Privacy PoliciesA privacy policy linked in App Store Connect and inside the app, covering what you collect, who you share it with, retention and deletionNo in-app link, or a template policy that doesn't mention your analytics and SDKs
(ii) PermissionConsent for data collection and purpose strings that "clearly and completely describe your use of the data"A camera or photos string that says what you access but not why
(iii) Data MinimizationRequest only what the core feature needs; prefer system pickersFull Photos library access for a single image upload
(iv) AccessDon't manipulate or force consent; offer alternativesBlocking the app until the user grants location or notifications
(v) Account Sign-InNo login unless there are account-based features; in-app account deletion if you allow sign-upSign-up wall before any content; no delete-account option
The (ix) sub-point also bars individual developers from shipping apps in highly regulated fields — banking, healthcare, gambling, legal cannabis, air travel and, since November 2025, crypto exchanges. Those must come from a legal entity that provides the service.
The finding, in one line
According to ASOitis's reading of Guideline 5.1.1, four gaps cause most indie rejections: no in-app account deletion, purpose strings that don't say why data is needed, sign-up required for non-account features, and a privacy policy that omits third-party SDKs.

02Account deletion: the requirement most indie apps miss

If your app supports account creation, you must also offer account deletion within the app.
— App Store Review Guidelines, 5.1.1(v)

This has applied to every app submitted since June 30, 2022, and the rejection is blunt: "The app supports account creation but does not include an option to initiate account deletion." Apple's support page sets out what counts:

What Apple accepts as account deletion

  • Easy to find — Apple suggests account settings — and started from inside the app
  • Deletes the account and associated data you aren't legally required to keep. Apple says "only offering to temporarily deactivate or disable an account is insufficient"
  • No phone call, email or support ticket required, unless you're in a highly regulated industry
  • Confirmation and re-authentication are fine; making it "unnecessarily difficult" is not
  • If deletion completes on your website, the app links straight to that page
  • Automatically created guest accounts must be deletable too, along with the user's own content
  • If the user has an auto-renewing subscription, tell them billing continues through Apple until they cancel
  • If you offer Sign in with Apple, revoke the user's tokens with the Sign in with Apple REST API

03Purpose strings: say why, not just what

Every protected resource your code touches — camera, photos, microphone, location, contacts — needs a usage description in Info.plist. A missing one fails at upload (ITMS-90683), sometimes because an SDK references the API even if you never call it. A vague one fails in review. The rejection developers get reads: "One or more purpose strings in the app do not sufficiently explain the use of protected resources."

Rejected

  • "This app requires permission to access the camera."
  • "We need your location."
  • "Allow access to Photos to continue."

Specific enough

  • "Take a photo of your meal so we can estimate its calories. Photos stay on your device unless you share them."
  • "Use your location to show gyms within walking distance. You can also type an address instead."
  • "Choose a photo to use as your profile picture."
  • Ask when the feature is used, not at launch. Apple's Human Interface Guidelines say to avoid requesting permission at launch unless the app can't function without it.
  • Use system pickers where you can. 5.1.1(iii) prefers the out-of-process photo picker or a share sheet to full library access — and the picker needs no permission at all.
  • Pre-permission screens have rules. One button, not labelled "Allow", and no way to dismiss it that tricks a quick tap into consent.
  • Never gate the app on consent. 5.1.1(ii) says paid functionality must not depend on granting data access, and 5.1.2(i) bars requiring notifications, location or tracking to use features.

04Forced sign-up: let people in before you ask who they are

If your app doesn't include significant account-based features, let people use it without a login.
— App Store Review Guidelines, 5.1.1(v)

The rejection usually says the app "requires users to register or log in to access features that are not account based." Sign-up walls are common in subscription apps because they make attribution and win-back emails easier — but App Review judges the feature, not your funnel.

  1. Separate account features from everything else

    Sync across devices, sharing and social features need an account. Browsing, logging on one device, or trying the core feature usually don't.

  2. Add a guest path

    Let people use the app locally and offer an account at the moment it adds something — backup, sync, a second device. Guest accounts you create automatically must still be deletable.

  3. Keep purchases account-free where possible

    Apple has rejected apps that required registration before in-app purchases unrelated to account features. StoreKit purchases work without your own login.

  4. Make contact details optional

    5.1.1(x) allows asking for a name and email only if it's optional and nothing depends on it.

05Privacy policy, App Privacy details and privacy manifests

Three different artefacts, often confused. Only the first is 5.1.1 itself, but reviewers look at all three together.

Which privacy artefact does what
ArtefactWhere it livesWhat goes wrong
Privacy policy — 5.1.1(i)A URL in App Store Connect and a link inside the appMissing in-app link; no mention of third parties, retention or how to request deletion
App Privacy details (nutrition label)App Store Connect → App PrivacyAnswers don't match the app; data collected "for app functionality" left out — Apple says it still must be declared
Privacy manifestPrivacyInfo.xcprivacy in the app and each SDKMissing required-reason declarations — App Store Connect has refused these uploads since May 1, 2024, before review
Inaccurate privacy information can also fall under Guideline 2.3, which requires all metadata, including privacy information, to reflect the app accurately. App Privacy answers can be updated without a new app version.

A practical rule: every SDK you add — analytics, crash reporting, attribution, a subscription backend — is a third party in your privacy policy and a line in your App Privacy answers. Audit both whenever the dependency list changes.

06Replying to a 5.1.1 rejection

5.1.1 rejections are usually factual, so the reply should be too: what you changed and exactly where the reviewer can see it.

Reply in App Store Connect — Guideline 5.1.1text
Hello App Review team,

Thank you for the feedback on Guideline 5.1.1([sub-point]).

Changes in build [number]:
- Account deletion: Settings > Account > Delete Account. Deletion removes the
  account and its data immediately; subscribers are told billing continues
  through Apple until they cancel.
- Purpose strings: the camera string now reads "[new string]".
- Sign-up is now optional. Core features work as a guest; an account is only
  offered for sync across devices.

Demo account (for the account features): [email] / [password]

Thank you,
[Name]

Frequently asked questions

Do I need account deletion if I only use Sign in with Apple?

Yes. If your app creates an account, it must offer deletion in the app, whatever the sign-in method. With Sign in with Apple you should also revoke the user's tokens through Apple's REST API when they delete.

Can account deletion just deactivate the account?

No. Apple's support page says offering only to temporarily deactivate or disable an account is insufficient. Deletion can be delayed or manual, as long as you tell the user how long it will take.

Is a missing privacy manifest a 5.1.1 rejection?

Usually not. Missing required-reason declarations are caught when you upload the build to App Store Connect, which has refused those uploads since May 1, 2024. 5.1.1 rejections come from App Review looking at the running app and its metadata.

Can I require an email address to use my app?

Only if it's directly relevant to core functionality or required by law. 5.1.1(x) allows asking for a name and email as long as it's optional and no feature depends on it.

Can an individual developer publish a finance or health app?

Apps providing services in highly regulated fields — banking and financial services, healthcare, gambling, legal cannabis, air travel and crypto exchanges — should be submitted by a legal entity that provides the service, not an individual, under 5.1.1(ix).

Where to go next

Sources

  1. App Store Review Guidelines — 5.1.1 Data Collection and Storage — Apple Developer
  2. Offering account deletion in your app — Apple Developer
  3. Requesting access to protected resources — Apple Developer Documentation
  4. Human Interface Guidelines — Privacy — Apple Developer
  5. Describing use of required reason API — Apple Developer Documentation
  6. App privacy details on the App Store — Apple Developer
  7. Updated App Review Guidelines (Nov 13, 2025) — Apple Developer News
  8. Forum: rejection for missing account deletion — Apple Developer Forums
  9. Forum: purpose strings rejected as insufficient — Apple Developer Forums
  10. Forum: registration required for non-account features — Apple Developer Forums

Published Oct 1, 2026 · last checked Oct 1, 2026. Found something out of date? Tell us and we'll fix it within a day. Machine-readable version: /app-review/guideline-5-1-1-data-collection.md