If you just got a rejection that cites Guideline 5.1.2, and your app added a chatbot, a photo generator, a writing assistant, or any feature that sends user input to a model, this page is for you. The reference number is easy to misread as a vague privacy complaint. It is usually more specific than that: your app moves user data somewhere — often to a model provider — and Apple can't see, on your public surface, that you told users and handled the data the way you said you would.
Guideline 5.1.2 lives in the Privacy section of Apple's App Review Guidelines, under Data Use and Sharing. It is not an AI-specific rule, but AI features are one of the most common ways to trip it, because a prompt, a photo, or a document leaving the device is exactly the kind of data flow the section is about. Below is what the rule covers, why AI features attract it, what a reviewer checks, and a concrete way to fix and re-verify before you resubmit. Read this as orientation — the authoritative wording is in Apple's official guidelines, and you should confirm against them.
What Guideline 5.1.2 actually covers
In plain terms, 5.1.2 is about how your app collects, uses, and shares personal data, and whether users have given informed consent for it. The parts that matter most for an AI app:
- Data must be used for its disclosed purpose — you tell users what you collect and why, and you don't quietly repurpose it.
- Sharing with third parties needs to be appropriate and disclosed — sending user content to an outside model provider is a data flow that belongs in your privacy policy.
- Consent should be clear — permission prompts and purpose strings should match the real reason the app needs the data.
None of that is exotic. The trouble is that AI features often add a new data flow after the rest of the app's disclosures were written, so the public surface quietly falls out of sync with what the app now does.
How AI features trigger it
A few patterns account for most 5.1.2 rejections on AI apps:
- User input leaves the device — prompts, uploaded photos, voice, or documents are sent to a model, and the privacy policy never mentions it.
- A third-party model provider processes the data — but the policy names no such sharing, so a reviewer can't confirm the flow is disclosed.
- Generated content and stored chats — history is retained or used to improve a service, without that being explained to the user.
- Permission strings don't match the AI use — the camera or microphone prompt says one thing while the feature does another.
The through-line: the app does something with user data that its public-facing disclosures don't say. That gap is what a reviewer sees.
What a reviewer looks for on your public surface
Some of what governs 5.1.2 lives inside App Store Connect — your privacy questionnaire answers, which a scan can't read. But a large part is on your reachable, logged-out public surface, and that is where you can catch problems yourself:
- A linked privacy policy that describes the AI data use — what input is sent, to which third-party model providers, and how it is retained. → maps to privacy policy
- An in-context indication that a feature is AI — so a user knows, in the moment, that they're interacting with a model. → maps to AI interaction disclosure
- Permission clarity — purpose strings and prompts that state the real reason the AI feature needs a camera, photos, microphone, or location.
- Consistency with your declared privacy labels — the data types and sharing you claimed in App Store Connect should match reality. → maps to App Store privacy
A pass-and-fix checklist
Work through these before you resubmit. Each is something you can confirm on your own site or in your own build.
- Your privacy policy names the AI data flow — what user input is sent to a model, which third-party providers receive it, and how long it is kept. → privacy policy
- An in-context AI notice is present — short, plain, visible before a user relies on the feature (e.g. "This uses AI; responses may be inaccurate"). → AI interaction disclosure
- Permission purpose strings match the real use — no generic "access your photos" when the feature sends those photos to a model.
- Your App Store Connect privacy answers match the app's behavior — declared data types and third-party sharing reflect what actually leaves the device. → App Store privacy
- The privacy policy is reachable — linked, loading, and not behind a login, so a reviewer and a scan both see it.
- Your resubmission note points to the fixes — tell the reviewer where the updated policy, the AI notice, and the corrected strings are.
What LaunchTrust checks for this framework
LaunchTrust does not decide whether your app is "5.1.2 compliant" — no scanner can, and much of the rule depends on answers only you and Apple can see. What it does is fetch your public page and report the observable signals a privacy-minded reviewer checks first:
- The privacy policy detector reports whether a policy appears present and linked on the page an anonymous visitor receives.
- The AI interaction disclosure detector reports detected when it finds a disclosure snippet or plain wording such as "this uses AI," and not detected when neither is present. A bare marketing label like "AI-powered" does not count.
Each result is a signal, not a judgment. "Detected" means the wording or link is on the page; it does not confirm the policy is worded correctly, or that your app meets 5.1.2 as applied to your product. LaunchTrust can't read your App Store Connect answers and does not guarantee approval.
Check this in 30 seconds
Run your URL through LaunchTrust's free scanner. It fetches your live page and reports whether a privacy policy and an AI disclosure are detected, not detected, or unable to determine — so you can spot a missing 5.1.2 signal before a reviewer does. No signup, no crawl of private pages: it reads the same public HTML your visitors and a reviewer get. If a signal is missing, fix it, then re-scan and confirm it flips to detected.
FAQ
What does App Store Guideline 5.1.2 actually cover? Guideline 5.1.2 sits in the Privacy section and deals with Data Use and Sharing: how your app collects, uses, and shares personal data, whether users have consented, and whether third parties (including model providers) receive that data appropriately. AI features often touch it because user input is sent to a model, sometimes to an outside provider. The exact wording is in Apple's official App Review Guidelines — treat this page as orientation, not a substitute for reading them.
Why do AI apps get rejected under 5.1.2 specifically? A common pattern is an app that sends user prompts, photos, or documents to a model provider without a privacy policy that names that data flow, without an in-context notice that the feature is AI, or without matching the disclosures in the app's privacy questionnaire. Reviewers can see the gap between what the app does and what the public surface says it does. Closing that gap is usually what a resubmission needs.
What does a reviewer look at on my public surface? The reachable, logged-out things: a linked privacy policy that describes AI data use and any third-party model providers, an in-context indication that a feature uses AI, and permission prompts whose purpose strings match what the app actually does. These are the signals a reviewer — and an automated scan — can confirm without an account, so they are the first place to look when 5.1.2 is cited.
Does LaunchTrust guarantee my app will pass review? No. LaunchTrust surfaces observable signals on your public page — whether a privacy policy and AI disclosure appear present and linked — so you can spot gaps before you resubmit. It does not prove your app is compliant, cannot see your App Store Connect privacy answers, and does not guarantee approval. It is a compliance aid, not legal advice or certification. For your specific situation, confirm against Apple's guidelines and, where needed, a qualified professional.
Compliance aid, not legal advice. LaunchTrust reports signals, not a verdict or certification, and does not guarantee App Store approval.