All skills
dpearson2699 avatar

/app-store-review

@45c9085

Audits App Store submission readiness and rejection risk across current review guidelines, PrivacyInfo.xcprivacy and required-reason APIs, privacy labels, ATT, StoreKit payments, metadata, entitlements, widgets, and Live Activities. Use when preparing a submission, responding to rejection, reconciling privacy evidence, or separating upload blockers from cleanup.

Use this Skill: https://skilld.dev/gh/dpearson2699/swift-ios-skills/app-store-review

This session only. Nothing lands on disk.

referencesprivacy-manifest.md

≈1.5k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Privacy Manifest Reference

Contents

  • When a Privacy Manifest Is Required
  • Privacy Manifest Structure
  • Required API Reason Codes
  • Privacy Manifest Keys Reference
  • Third-Party SDK Manifests
  • Collected Data Types Declaration
  • Sources To Re-Check

When a Privacy Manifest Is Required

A PrivacyInfo.xcprivacy file is required if your app or any dependency uses these API categories:

  • File timestamp APIs (NSPrivacyAccessedAPICategoryFileTimestamp)
  • System boot time APIs (NSPrivacyAccessedAPICategorySystemBootTime)
  • Disk space APIs (NSPrivacyAccessedAPICategoryDiskSpace)
  • User defaults (NSPrivacyAccessedAPICategoryUserDefaults)
  • Active keyboard APIs (NSPrivacyAccessedAPICategoryActiveKeyboards)

Apple updates required-reason API coverage over time. Before final submission or release, re-check the current NSPrivacyAccessedAPIType and NSPrivacyAccessedAPITypeReasons documentation and do not invent broad or convenient reasons.

Privacy Manifest Structure

<!-- PrivacyInfo.xcprivacy -->
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN"
  "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
    <key>NSPrivacyTracking</key>
    <false/>
    <key>NSPrivacyTrackingDomains</key>
    <array/>
    <key>NSPrivacyCollectedDataTypes</key>
    <array>
        <!-- Declare every data type you collect -->
    </array>
    <key>NSPrivacyAccessedAPITypes</key>
    <array>
        <dict>
            <key>NSPrivacyAccessedAPIType</key>
            <string>NSPrivacyAccessedAPICategoryUserDefaults</string>
            <key>NSPrivacyAccessedAPITypeReasons</key>
            <array>
                <string>CA92.1</string>
            </array>
        </dict>
    </array>
</dict>
</plist>

Required API Reason Codes

Use the exact approved reason that matches the app or SDK behavior. Do not use a broad reason code because it is convenient; Apple requires the declared reason to match the presented functionality and derived-data use.

Before final submission, re-check Apple's current required-reason API documentation. Reason-code coverage can change, and invented or overly broad reasons are not acceptable.

API Category Code Reason
FileTimestamp DDA9.1 Display file timestamps to the person using the device
FileTimestamp C617.1 Access timestamps, size, or metadata for files in the app, app group, or CloudKit container
FileTimestamp 3B52.1 Access timestamps, size, or metadata for user-granted files or directories
FileTimestamp 0A2A.1 Third-party SDK wrapper around file timestamp APIs, only when called by the app
SystemBootTime 35F9.1 Measure elapsed time between events
SystemBootTime 8FFB.1 Calculate absolute timestamps for events that occurred within the app
SystemBootTime 3D61.1 Include system boot time in an optional user-submitted bug report
DiskSpace 85F4.1 Display disk space information to the person using the device
DiskSpace E174.1 Check available or low disk space before writes or cleanup
DiskSpace 7D9E.1 Include disk space information in an optional user-submitted bug report
DiskSpace B728.1 Health research app detects low disk space impacting research data collection
ActiveKeyboards 3EC4.1 Custom keyboard app checks active keyboards
ActiveKeyboards 54BD.1 Present UI that visibly changes based on active keyboards
UserDefaults CA92.1 Read/write information accessible only to the app itself
UserDefaults 1C8F.1 Read/write information accessible only within the same App Group
UserDefaults C56D.1 Third-party SDK wrapper around UserDefaults APIs, only when called by the app
UserDefaults AC6B.1 Managed app configuration or managed feedback keys for MDM

Privacy Manifest Keys Reference

Key Type Purpose
NSPrivacyTracking Boolean Whether the app tracks users (triggers ATT requirement)
NSPrivacyTrackingDomains Array of strings Domains used for tracking (connected only after ATT consent)
NSPrivacyCollectedDataTypes Array of dicts Each data type collected, its purpose, and whether it is linked to identity
NSPrivacyAccessedAPITypes Array of dicts Each required-reason API used and the justification codes

Third-Party SDK Manifests

  • Verify each SDK, executable, or dynamic library that uses required-reason APIs includes PrivacyInfo.xcprivacy in the bundle containing that code
  • Ensure SDK reason codes match actual SDK usage; an SDK cannot rely on the host app's manifest to report the SDK's own required-reason API use
  • Update SDK versions when required manifests or reason declarations are missing
  • Keep the app's manifest focused on app code and app-level collected data/tracking declarations

Collected Data Types Declaration

Each NSPrivacyCollectedDataTypes entry must specify:

  • NSPrivacyCollectedDataType (category)
  • NSPrivacyCollectedDataTypeLinked (linked to identity)
  • NSPrivacyCollectedDataTypeTracking (used for tracking)
  • NSPrivacyCollectedDataTypePurposes (purposes array)

Keep manifests, privacy nutrition labels, SDK behavior, and app functionality consistent. Mismatches cause rejection.

Sources To Re-Check

Source: SKILL.md on GitHub

2 warnings17d5 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    The skill provides a framework for auditing iOS applications for App Store compliance. It references a third-party documentation site (sosumi.ai) for privacy manifest guidelines, which is an external domain outside the trusted vendor list. Additionally, it presents an indirect prompt injection surface as it analyzes untrusted application source code and configuration files without explicit boundary markers or sanitization instructions.

  • Socket17d

    No alerts

  • Snyk17d

    Risk: MEDIUM · 1 issue

  • Runlayer6mo

    2/3 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 45c9085. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Steadyupdated 3 months ago
  • app-store-review
  • ios
  • swift
  • app-store-connect
  • privacy-manifest
  • att
  • storekit
  • iap
  • hig
  • submissions

README badge

README badge for dpearson2699/swift-ios-skills/app-store-review

Instructs on App Store review policies, privacy manifest requirements, ATT implementation, IAP rules, HIG compliance, and submission workflows to prevent rejections. Covers the most common rejection reasons (incomplete apps, private APIs, inaccurate metadata), StoreKit configuration, and EU DMA considerations for iOS developers preparing App Store submissions.

Generated from the current SKILL.md.

What are the most common App Store rejection reasons?
The most frequent rejections are for incomplete apps (placeholder content, broken links, missing demo credentials), inaccurate metadata (mismatched screenshots or descriptions), privacy manifest violations (missing reason codes for restricted APIs), and IAP rule violations (requiring Apple purchase for services that shouldn't). The skill covers preventable rejection patterns and how to avoid them.
Do I need a privacy manifest, and what does it require?
Yes, a privacy manifest is required if your app or any dependency uses certain APIs like file timestamp, system boot time, disk space, user defaults, or active keyboard. Every third-party SDK must ship its own privacy manifest, and your declarations must match App Store nutrition labels and actual network behavior.
When do I need to implement App Tracking Transparency (ATT)?
ATT is required only if your app tracks users across other companies' apps or websites. You must request permission before tracking, respect user denial, and not gate app functionality behind consent. If you do not track across apps, do not show the ATT prompt.
What digital content requires In-App Purchase?
All digital content and services require Apple IAP: premium features, subscriptions, virtual currency, ad removal, and tips. Physical products, ride-sharing, food delivery, and one-to-one services do not require IAP.
How long does App Store review typically take?
Average review time is under 24 hours, though you should allow 48 hours. Expedited review is available only for critical bug fixes, time-sensitive events, or security patches.

Generated from the current SKILL.md. These answers refresh after source changes.