All skills
dpearson2699 avatar

/app-store-review

@45c9085

Audits App Store submission readiness and rejection risk across current review guidelines, PrivacyInfo.xcprivacy and required-reason APIs, privacy labels, ATT, StoreKit payments, metadata, entitlements, widgets, and Live Activities. Use when preparing a submission, responding to rejection, reconciling privacy evidence, or separating upload blockers from cleanup.

Use this Skill: https://skilld.dev/gh/dpearson2699/swift-ios-skills/app-store-review

This session only. Nothing lands on disk.

referencesreview-checklists.md

≈2.2k tokens on demand. Your agent reads this file only when SKILL.md points to it.

App Store Review Checklists

Contents

  • Current Release Requirements
  • Entitlements and Usage Descriptions
  • Phased Release Schedule
  • App Review Information Checklist
  • Privacy Manifest Checklist
  • In-App Purchase Checklist
  • Metadata Compliance Checklist
  • HIG Compliance Checklist
  • Pre-Submission Checklist

Current Release Requirements

Treat this table as a dated release snapshot, not a durable policy source. Re-check the linked current Apple requirements at the start of every audit and record the checked date beside each blocker.

Requirement Current release evidence
Upload toolchain Uploads after April 28, 2026 require Xcode 26+ and the relevant platform SDK 26+.
iPhone screenshots As of May 2026, 6.9-inch screenshots are the primary accepted set; provide 6.5-inch only when the 6.9-inch set is absent or intentionally optimized as a fallback.
iPad screenshots Provide 13-inch screenshots when the app runs on iPad.
Metadata limits App name: 30 characters; subtitle: 30 characters; keyword field: up to 100 UTF-8 bytes, with comma-separated terms longer than two characters and no spaces after commas.

Sources: Upcoming requirements and Screenshot specifications.

Entitlements and Usage Descriptions

Every entitlement must be justified by an active feature and its release evidence:

Entitlement Review evidence
Camera Specific NSCameraUsageDescription tied to a visible feature
Location (Always) Clear user-facing reason for background location
Push Notifications Marketing notifications require user opt-in
HealthKit Meaningful use of the requested health data
Background Modes Every enabled mode is justified and exercised
App Groups Shared data and participating targets are documented
Associated Domains Universal links resolve and function

Use valid property-list entries with specific user-facing purposes:

<key>NSLocationWhenInUseUsageDescription</key>
<string>Your location is used to show nearby restaurants on the map.</string>
<key>NSCameraUsageDescription</key>
<string>The camera is used to scan barcodes for price comparison.</string>

Vague strings such as “This app needs your location” do not explain the feature or why the data is needed.

Phased Release Schedule

After approval, an automatic phased release uses this seven-day schedule:

Day Percentage of Users
1 1%
2 2%
3 5%
4 10%
5 20%
6 50%
7 100%

Users who manually request the update receive it immediately. App Store Connect can pause, resume, or complete the rollout.

App Review Information Checklist

Use this to avoid Guideline 2.1 rejections:

  • Demo credentials provided in App Review Information notes (if login required)
  • Demo mode available if credentials are impractical or account state is hard to reproduce
  • Demo account works and has access to all features
  • App Review notes explain login-gated, role-gated, region-gated, hardware-gated, or otherwise non-obvious features
  • All screens have real content (no placeholders or Lorem Ipsum)
  • No broken links or dead-end flows
  • All hardware-required features have fallback or reviewer instructions

Privacy Manifest Checklist

Verify PrivacyInfo.xcprivacy completeness:

  • PrivacyInfo.xcprivacy exists where app code, SDK code, executables, or dynamic libraries need it
  • All required-reason API categories in app and bundled SDK code are declared with approved reason codes
  • NSPrivacyTracking is true only if tracking occurs
  • Third-party SDK manifests present and up to date when SDKs collect data, use required-reason APIs, enable data collection, or contact tracking domains
  • Privacy nutrition labels match actual data collection
  • Audit runtime network traffic and SDK transmissions; observed behavior must match privacy labels, manifests, privacy policy, and ATT state

In-App Purchase Checklist

  • Digital goods and subscriptions use StoreKit IAP unless current storefront rules or approved entitlements allow otherwise
  • Subscription price, duration, billing frequency, auto-renewal terms, and any trial duration/post-trial price shown before purchase
  • Restore purchases button present and functional
  • No external purchase path, link, button, or call to action for digital goods unless current rules or approved entitlements allow it
  • Ask-to-buy and interrupted purchases handled
  • Transaction verification uses StoreKit 2 or server-side verification

Metadata Compliance Checklist

Keep this checklist about App Review compliance. Route keyword research, ranking, conversion optimization, screenshot ordering, and A/B testing to app-store-optimization.

App Name and Subtitle

  • Name and subtitle meet the limits in Current Release Requirements
  • Name is unique and not only a generic category term
  • Name and subtitle omit prices, competitor names, and trademarks you do not own

Screenshots

  • 1-10 screenshots are uploaded for each required platform and localization
  • iPhone and iPad sets match Current Release Requirements
  • Screenshots show localized, actual app UI and no unavailable features
  • Overlays and marketing frames do not obscure or misrepresent the interface

Keywords

  • Keyword field meets the limit and delimiter format in Current Release Requirements
  • Terms do not duplicate the app name or subtitle
  • Terms use either singular or plural, not both
  • Terms omit competitors, trademarks, and irrelevant words

App Previews

  • Up to three previews per localization, each no longer than 30 seconds
  • Footage shows the actual app; framing and effects do not misrepresent it
  • Optional audio or narration complies with rights and metadata claims
  • The first frame works as the product-page poster frame

HIG Compliance Checklist

Navigation

  • NavigationStack used (not NavigationView)
  • System back chevron used; no custom back icons
  • Tab bar uses <= 5 tabs; use More tab if needed
  • Avoid hamburger menus

Modals and Sheets

  • Sheets have a visible dismiss control
  • Full-screen modals have close/done button
  • Alerts use system alert styles

System Feature Support

  • Dark Mode renders correctly
  • Dynamic Type supported throughout
  • iPad multitasking supported (Slide Over, Split View)
  • Dynamic Island / Live Activities render correctly when used
  • System gestures not disabled

Widgets and Live Activities

  • Widgets show real content (not placeholders)
  • Timelines update meaningfully
  • Live Activities show time-sensitive info
  • Lock Screen widgets are legible at small sizes

Pre-Submission Checklist

Completeness

  • No placeholder or test content
  • All features functional without special hardware
  • Demo credentials or demo mode provided, with App Review notes for gated or non-obvious features
  • No dead-end screens

Metadata

  • App name matches functionality
  • Screenshots are real app screenshots using the sets in Current Release Requirements
  • Description contains no prices or competitor mentions
  • Category is correct

Privacy

  • Privacy manifest present where required, with approved reason codes
  • Third-party SDK manifests verified
  • Privacy policy URL present and accessible
  • Audit runtime network traffic and SDK transmissions; nutrition labels, privacy manifest declarations, privacy policy, and observed behavior match actual data collection
  • ATT prompt only if tracking occurs

Payments

  • Digital content uses StoreKit IAP unless current rules or approved entitlements allow otherwise
  • Subscription price, duration, billing frequency, auto-renewal terms, and any trial duration/post-trial price visible before purchase
  • No external purchase paths, payment links, buttons, or calls to action unless current storefront rules or approved entitlements allow them
  • Free trial terms clear
  • Restore purchases implemented

Design

  • Standard navigation patterns used
  • Dark Mode supported
  • Dynamic Type supported
  • No custom alerts mimicking system alerts
  • Launch screen not an ad
  • Empty states provide guidance

Technical

  • Archive meets the upload toolchain floor in Current Release Requirements
  • No private API usage
  • No dynamic code execution
  • Entitlements justified with usage descriptions
  • Background modes justified and used
  • Deployment target is intentionally chosen and tested

Source: SKILL.md on GitHub

2 warnings16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill provides a framework for auditing iOS applications for App Store compliance. It references a third-party documentation site (sosumi.ai) for privacy manifest guidelines, which is an external domain outside the trusted vendor list. Additionally, it presents an indirect prompt injection surface as it analyzes untrusted application source code and configuration files without explicit boundary markers or sanitization instructions.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: MEDIUM · 1 issue

  • Runlayer6mo

    2/3 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 45c9085. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Steadyupdated 3 months ago
  • app-store-review
  • ios
  • swift
  • app-store-connect
  • privacy-manifest
  • att
  • storekit
  • iap
  • hig
  • submissions

README badge

README badge for dpearson2699/swift-ios-skills/app-store-review

Instructs on App Store review policies, privacy manifest requirements, ATT implementation, IAP rules, HIG compliance, and submission workflows to prevent rejections. Covers the most common rejection reasons (incomplete apps, private APIs, inaccurate metadata), StoreKit configuration, and EU DMA considerations for iOS developers preparing App Store submissions.

Generated from the current SKILL.md.

What are the most common App Store rejection reasons?
The most frequent rejections are for incomplete apps (placeholder content, broken links, missing demo credentials), inaccurate metadata (mismatched screenshots or descriptions), privacy manifest violations (missing reason codes for restricted APIs), and IAP rule violations (requiring Apple purchase for services that shouldn't). The skill covers preventable rejection patterns and how to avoid them.
Do I need a privacy manifest, and what does it require?
Yes, a privacy manifest is required if your app or any dependency uses certain APIs like file timestamp, system boot time, disk space, user defaults, or active keyboard. Every third-party SDK must ship its own privacy manifest, and your declarations must match App Store nutrition labels and actual network behavior.
When do I need to implement App Tracking Transparency (ATT)?
ATT is required only if your app tracks users across other companies' apps or websites. You must request permission before tracking, respect user denial, and not gate app functionality behind consent. If you do not track across apps, do not show the ATT prompt.
What digital content requires In-App Purchase?
All digital content and services require Apple IAP: premium features, subscriptions, virtual currency, ad removal, and tips. Physical products, ride-sharing, food delivery, and one-to-one services do not require IAP.
How long does App Store review typically take?
Average review time is under 24 hours, though you should allow 48 hours. Expedited review is available only for critical bug fixes, time-sensitive events, or security patches.

Generated from the current SKILL.md. These answers refresh after source changes.