App Rejected due to third Party AI Service.

Hi All, We are facing App Rejection from Apple due to this -

Guidelines 5.1.1(i) - Legal - Privacy - Data Collection and 5.1.2(i) - Legal - Privacy - Data Use Issue Description

The app appears to share the user’s personal data with a third-party AI service but the app does not clearly explain what data is sent and identify who the data is sent to before sharing the data.

Apps may only use, transmit, or share personal data after they meet all of the following requirements:

  • Disclose what data will be sent
  • Specify who the data is sent to
  • Obtain the user’s permission before sending data
  • Identify in the privacy policy what data the app collects, how it collects that data, all uses of that data, and confirm any third party the app shares data with provides the same or equal protection

Next Steps

If the app sends user data to a third-party AI service, revise the app to explain what data is sent and identify who the data is sent to before sharing personal data with a third-party AI service.

If it does not already, the app’s privacy policy must also identify what data the app collects, how it collects that data, and all uses of that data, including if it is shared with a third-party AI service.

If the app does not send user data to a third-party AI service or does not include a third-party AI service, reply to this rejection to confirm and add this information to the App Review Information section of App Store Connect.

We have updated on privacy policy and ATT as well as Nutrition Labels and we have added a consent screen for explicitly taking the user consent for AI Services. However we are still seeing the rejection.

Has some else faced a similar issue and what are the steps they followed for this.

Answered by App Review in 876627022

Thank you for your post. We believe we have resolved this issue. If you continue to experience issues during review, please contact us.

Also running Into the same issue. Apple is not clear exactly on what needs to be done as I’ve followed the guides and disclosed as I should but still got rejected.

Same issue, and App Review hasn't given any clarity if we need to permission gate it or not.

Thank you for your post. We believe we have resolved this issue. If you continue to experience issues during review, please contact us.

I’m experiencing the same issue. I just received a rejection today without any clear details about what’s missing. This is the third rejection for a version that only changes the storefront images. Please help, I’ve already submitted a contact form.

Same issue as @luisamom is having. We are updating our app and trying to adhere to the guidelines but keep getting rejected without clarity.

@App Review please advise

I'm also facing the same problem problem, we're unable to update our app, and we don't get a clear response on what we need to do to get the approval

We are experiencing the same issue. No new functionality for the chat was added. Should we just update the policy or add additional permission asking pop up?

@App Review I had same issue . App was rejected twice. i even mentioned the ai providers name and also mentioned they dont use the data in training in privacy policy and even took consent checkbox when user signs up or logins. Still same issue. Please if anyone solved this issue guide us.

Getting the same issue! Not sure what @App Review is looking for here, would appreciate some clarity.

same here, very unclear as usual

Our version was just approved! I took the following action in case it works for you as well:

  1. Rewrite the Privacy Policy to specify that we do not share or sell data to third-party AI providers, also listing our AI data processors.

  2. Add the following paragraph to the app description:

We use Google Cloud Vertex AI to securely process user messages and relevant financial data in order to provide AI-powered insights. Google Cloud acts solely as a data processor and does not use this data to train its models.

  1. Add a consent screen in the onboarding process, explaining that we how and which AI data processors we use.

  2. Add release notes with the following info:

We do not sell, monetize, or share users' personal data with third parties for advertising, profiling, or any other purposes. We use Google Cloud Vertex AI solely as a data processor to provide AI-powered features such as financial insights, forecasting, and conversational analysis. Google Cloud processes user messages and relevant financial data (such as transactions and balances) strictly on behalf of us under Google Cloud’s enterprise data processing terms. Google Cloud does not use our customer data to train foundation models or for model improvement. All AI processing occurs only after the user provides explicit in-app consent by tapping “Continue with AI” on the dedicated consent screen. We retain full control over user data and determine the purposes and means of processing. Google Cloud acts solely as an infrastructure provider and processor."

Hope this is helpful and @App Review approved easily for future versions.

My version was just approved! I took the following action in case it works for you as well:

Note: This applies to us, as we don't sell or share customer data with AI processors.

  1. Rewrite the Privacy Policy to specify that we do not share or sell data to third-party AI providers, also listing our AI providers.

  2. Add

App Rejected due to third Party AI Service.
 
 
Q