---
title: "Guideline 5.1.2 Data Use and Sharing: How to Fix It"
canonical: "https://asoitis.com/app-review/guideline-5-1-2-data-use-and-sharing"
description: "Rejected under App Store Guideline 5.1.2? What counts as tracking, when ATT is required, the third-party AI consent rule from Nov 2025, and how to fix each."
kind: "reference-library/app-review"
published: "2026-10-05"
lastUpdated: "2026-10-05"
verifiedAgainst: "Apple's App Review Guidelines (last updated June 8, 2026), Apple's User Privacy and Data Use page and Apple Developer News (Nov 13, 2025), on Oct 5, 2026"
author: "Ahmed Gagan (https://asoitis.com/about)"
---

# Guideline 5.1.2 Data Use and Sharing: tracking, SDKs, third-party AI and permission walls

> Guideline 5.1.2 controls what you do with personal data. You need permission before sharing it, App Tracking Transparency consent before tracking, and — since November 13, 2025 — clear disclosure and explicit permission before sending personal data to third-party AI. You also can't make features depend on enabling tracking, notifications or location. Most rejections trace back to an SDK or an AI call the developer didn't think of as sharing.

The privacy rejection that isn't about your privacy policy — it's about where user data goes after you collect it.

> According to ASOitis, the 5.1.2 rejections indie apps get now are rarely about ad networks: they come from analytics SDKs that count as tracking, and from AI features that send user text or photos to a third-party model without asking first.

Guideline: [5.1.2 — Data Use and Sharing](https://developer.apple.com/app-store/review/guidelines/#data-use-and-sharing) (5. Legal; Apple text last updated June 8, 2026)

## Key facts

- **Sub-points:** 7 — 5.1.2(i) to (vii)
- **Third-party AI rule:** Nov 13, 2025 — Disclose and get explicit permission first
- **SDK responsibility:** Yours — "Developers are responsible for all code included in their apps"
- **Gating on permissions:** Not allowed — Tracking, notifications or location

## What 5.1.2 covers

[Guideline 5.1.1](https://asoitis.com/app-review/guideline-5-1-1-data-collection) is about collecting data: privacy policies, purpose strings, account deletion. 5.1.2 starts once you have the data and asks where it goes. It has seven sub-points; the first one causes nearly every rejection.

**The seven parts of Guideline 5.1.2**

| Sub-point | Rule, in short | Typical trigger |
| --- | --- | --- |
| 5.1.2(i) | Permission before using or sharing personal data; disclose sharing, including with third-party AI; ATT for tracking; no gating on system permissions | An analytics or attribution SDK, an AI API call, a "enable notifications to continue" screen |
| 5.1.2(ii) | Data collected for one purpose can't be repurposed without further consent | Using support emails for a marketing list |
| 5.1.2(iii) | No covert profiles; no re-identifying anonymous users | Fingerprinting devices across reinstalls |
| 5.1.2(iv) | No contact databases from Contacts or Photos; no logging which apps are installed | Uploading the address book to "find friends" and keeping it |
| 5.1.2(v) | Only message contacts at the user's explicit, individual initiative; no Select All | Invite flows that pre-select every contact |
| 5.1.2(vi) | No marketing or data mining with HealthKit, HomeKit, ClassKit or face and depth data | Sending health data to an ad or analytics SDK |
| 5.1.2(vii) | Apple Pay data only shared to deliver goods and services | Adding Apple Pay customers to a mailing list |

## Tracking and App Tracking Transparency

> Tracking refers to the act of linking user or device data collected from your app with user or device data collected from other companies' apps, websites, or offline properties for targeted advertising or advertising measurement purposes. Tracking also refers to sharing user or device data with data brokers.
>
> — [Apple — User Privacy and Data Use](https://developer.apple.com/app-store/user-privacy-and-data-use/)

If anything in your app does that, you need the App Tracking Transparency prompt and a "yes" before it runs. The part indie developers miss is that Apple counts SDKs whose behavior you don't control. Its list of tracking examples includes "placing a third-party SDK in your app that combines user data from your app with user data from other developers' apps to target advertising or measure advertising efficiency, even if you don't use the SDK for these purposes."

> We noticed you collect data to track after the user selects "Ask App Not to Track" on the App Tracking Transparency permission request.
>
> — [App Review rejection under 5.1.2, posted on Apple Developer Forums, February 2022](https://developer.apple.com/forums/thread/701508)

That rejection came from cookies in a web view the developer owned. The same thing happens with attribution SDKs, ad networks and some analytics tools that initialize at launch, before the ATT answer is known. There are two clean fixes:

**If you track**
- Show the ATT prompt before any tracking SDK starts
- Initialize ad and attribution SDKs only after authorization
- Run them in non-tracking mode when the answer is no
- Declare tracking in your App Privacy details in App Store Connect

**If you don't need to track**
- Remove ad and attribution SDKs you aren't using
- Switch analytics to a tool that doesn't share data across apps
- Set tracking to "No" in App Privacy details
- Skip the ATT prompt entirely — it isn't required without tracking

> **Apple's own fix list includes your App Privacy answers.** A 5.1.2 rejection from [August 2021](https://developer.apple.com/forums/thread/688582) told the developer to update the app privacy information to disclose tracking, implement App Tracking Transparency, and "indicate in the Review Notes where the permission request is located." Make the privacy details, the build and the review notes agree.

## Third-party AI: the November 2025 rule

> You must clearly disclose where personal data will be shared with third parties, including with third-party AI, and obtain explicit permission before doing so.
>
> — [App Store Review Guidelines, 5.1.2(i)](https://developer.apple.com/app-store/review/guidelines/#data-use-and-sharing)

Apple added "including with third-party AI" on [November 13, 2025](https://developer.apple.com/news/?id=ey6d8onl). Personal data shared with a third party always needed permission; the change makes it explicit that an AI provider is a third party. If your app sends a user's text, photos, voice, health entries or documents to an outside model API, this applies to you.

**An AI consent screen that answers the reviewer's questions**

- [ ] Shown before the first request that contains the user's data, not after
- [ ] Names who receives the data — the provider, not just "our AI partner"
- [ ] Says what is sent: the photo, the journal entry, the voice recording
- [ ] Says what it's used for, and whether the provider may keep it
- [ ] Has a real choice — declining doesn't break the rest of the app
- [ ] Matches your privacy policy and App Privacy details

A link to the privacy policy alone is weak evidence of "explicit permission". A short in-app screen with an Allow button is what reviewers can see and test. On-device models, such as Apple's Foundation Models framework, don't send data to a third party, so this disclosure isn't triggered by them.

## You can't make people enable notifications, location or tracking

> Your app may not require users to enable system functionalities (e.g. push notifications, location services, tracking) in order to access functionality, content, use the app, or receive monetary or other compensation, including but not limited to gift cards and codes.
>
> — [App Store Review Guidelines, 5.1.2(i)](https://developer.apple.com/app-store/review/guidelines/#data-use-and-sharing)

- **No permission walls in onboarding.** A screen that won't continue until notifications are on is a rejection. Ask, accept "no", and let people carry on.
- **No rewards for saying yes.** Apple's [privacy FAQ](https://developer.apple.com/app-store/user-privacy-and-data-use/) answers the question "Can I gate functionality on agreeing to allow tracking, or incentivize users to agree?" with "No".
- **Feature-level asks are fine.** A reminder feature can ask for notification permission when the user turns reminders on. A map can ask for location when opened. What's banned is requiring the permission for the app as a whole.
- **A pre-prompt screen is fine too.** Explaining why before the system dialog is allowed, as long as both "yes" and "not now" lead somewhere.

## Contacts, health data and other people's information

> We continue to find that your app collects information about the user's friends, contacts, or other third-party persons without the knowledge or consent of those parties.
>
> — [App Review rejection under 5.1.2, posted on Apple Developer Forums, December 2022](https://developer.apple.com/forums/thread/721466)

Invite and "find friends" features are where most indie apps meet sub-points (iv) and (v). Use the system contact picker so users choose individual people, never upload the whole address book to keep, and show exactly what the invite message will say and who it will come from, as 5.1.2(v) requires.

Health and fitness apps have a stricter line: data from HealthKit, Clinical Health Records, ClassKit, HomeKit or face and depth mapping "may not be used for marketing, advertising or use-based data mining, including by third parties." Keep that data out of analytics events entirely. For calorie and habit apps, this matters more than it seems — see how the leaders position themselves in our [calorie tracker snapshot](https://asoitis.com/aso/calorie-tracking-apps).

## Fixing a 5.1.2 rejection and replying

1. **List every SDK and outbound API** — Analytics, attribution, ads, crash reporting, AI providers, chat and support widgets. For each one, write down what data it sends and to whom.
2. **Classify each as tracking, sharing or neither** — Use Apple's definition of tracking. Anything that sends personal data to a third party, including an AI model, needs disclosure and permission.
3. **Fix the order of operations** — Ask for ATT before tracking SDKs start, and show the AI consent screen before the first request with user data.
4. **Remove every permission wall** — Search onboarding and paywalls for screens that require notifications, location or tracking to continue.
5. **Align App Privacy details** — Update the answers in App Store Connect so they describe the new build exactly.

**Reply in App Store Connect — Guideline 5.1.2**

```text
Hello App Review team,

Thank you for the feedback on Guideline 5.1.2.

Changes in build [number]:
- [SDK name] now starts only after the user allows tracking in the
  App Tracking Transparency prompt. If they decline, it does not run.
- Before any [photo / text] is sent to [AI provider] for [feature],
  the app shows a consent screen naming the provider and the data
  sent. Users who decline can use the rest of the app.
- Onboarding no longer requires notifications; "Not now" continues.
- App Privacy details in App Store Connect have been updated to match.

To see the consent screen: launch the app > tap [feature].

Thank you,
[Name]
```

> **The Review Check ($49).** We read your build's SDK list, AI calls and onboarding against 5.1.1 and 5.1.2 before you submit — $49, two business days. https://checkout.dodopayments.com/buy/pdt_0NmV5JBcX1kDqIGUTko9k?quantity=1&redirect_url=https%3A%2F%2Fasoitis.com%2Fcheckout%2Fsuccess%3Fplan%3Dreview

## Frequently asked questions

### Do I need App Tracking Transparency if I only use analytics?

Only if the analytics data is used for tracking as Apple defines it — linked with other companies' data for ads or ad measurement, or shared with a data broker. Analytics kept for your own app doesn't need ATT, but check what each SDK does with the data.

### Do I need user consent to send data to OpenAI or another AI API?

Yes, if the data is personal. Since November 13, 2025, Guideline 5.1.2(i) says you must clearly disclose sharing with third-party AI and obtain explicit permission before doing so. An in-app consent screen before the first request is the clearest way to show it.

### Can I require push notifications to use my app?

No. 5.1.2(i) says apps may not require users to enable system functionalities such as push notifications, location services or tracking to access functionality or content. Ask for permission when a feature needs it, and let people decline.

### Am I responsible for what a third-party SDK does with data?

Yes. Apple's privacy FAQ says developers are responsible for all code included in their apps, and its tracking examples include SDKs that combine your users' data with other apps' data, even if you don't use those features.

### Can I offer a reward for allowing tracking?

No. Apple's answer to whether you can incentivize users to allow tracking is no, citing 5.1.2(i). The guideline also bans tying monetary or other compensation, including gift cards and codes, to enabling system features.

## Sources

1. [App Store Review Guidelines — 5.1.2 Data Use and Sharing](https://developer.apple.com/app-store/review/guidelines/#data-use-and-sharing) — Apple Developer
2. [User Privacy and Data Use](https://developer.apple.com/app-store/user-privacy-and-data-use/) — Apple Developer
3. [Updated App Review Guidelines now available (Nov 13, 2025)](https://developer.apple.com/news/?id=ey6d8onl) — Apple Developer News
4. [Forum: tracking after "Ask App Not to Track" (5.1.2)](https://developer.apple.com/forums/thread/701508) — Apple Developer Forums
5. [Forum: cookies in a web view without ATT (5.1.2)](https://developer.apple.com/forums/thread/688582) — Apple Developer Forums
6. [Forum: collecting information about third parties (5.1.2)](https://developer.apple.com/forums/thread/721466) — Apple Developer Forums

## Related

- [Guideline 5.1.1: Data Collection](https://asoitis.com/app-review/guideline-5-1-1-data-collection) — The collection side: privacy policy, purpose strings and account deletion.
- [Guideline 4.8: Login Services](https://asoitis.com/app-review/guideline-4-8-login-services) — The privacy-focused login you need if you offer Google or Facebook sign-in.
- [Guideline 2.1: App Completeness](https://asoitis.com/app-review/guideline-2-1-app-completeness) — Review notes that show the reviewer your consent screens.
- [The Review Check — $49](https://asoitis.com/fixes) — Your SDKs, AI calls and onboarding checked before Apple sees them.
- [All app review fixes](https://asoitis.com/app-review)


## Have it done for you

**The Review Check — $49 one-time.** Send us your TestFlight build. We trace where user data goes — SDKs, AI calls, web views — and tell you exactly which prompts and disclosures 5.1.2 needs.

- Buy: https://checkout.dodopayments.com/buy/pdt_0NmV5JBcX1kDqIGUTko9k?quantity=1&redirect_url=https%3A%2F%2Fasoitis.com%2Fcheckout%2Fsuccess%3Fplan%3Dreview
- 15-minute founder call: https://cal.com/ahmedgagan/asoitis-chat

## About ASOitis

ASOitis is a founder-run App Store Optimization (ASO) and Generative Engine Optimization (GEO) agency for indie iOS apps. iOS only; organic ASO + GEO + funnel work, implemented for you. Reference library: https://asoitis.com/app-review, https://asoitis.com/reviews, https://asoitis.com/compare, https://asoitis.com/glossary, https://asoitis.com/aso
