App Store Privacy Policy: What Apple Checks and How to Speed Review

By Paul Cranmer, Founder · Last verified August 2026 · App Store Connect · complete guide

Apple will not treat a missing or vague privacy policy lightly. App Store Connect requires a Privacy Policy URL for every app, App Privacy details that match that page, and an easy way for reviewers and users to open the same policy. This guide consolidates what to put on the page, where to paste the URL, and how to avoid the review loops that slow indie releases.

Who this is for

  • iOS and macOS developers preparing first submission or a major update
  • Teams fixing Guideline 5.1.1-style privacy feedback from App Review
  • Builders who want one stable HTTPS policy URL across App Store and Play

Not for

  • Meta, Google Ads, or LinkedIn lead form blockers (use the paid ads how-tos)
  • A substitute for counsel on kids apps or health data edge cases

What the platform requires

  • App Store Connect lists Privacy Policy URL as required for all apps (iOS and macOS).
  • Enter the URL under App Privacy. A User Privacy Choices URL is optional.
  • App Privacy data-type answers must stay consistent with the policy text and SDKs you ship.
  • Keep the URL public for as long as the app is on the store, and make the same policy easy to open inside the app.

Get a live URL first

Mobile App is on our free path. Choose App (iOS / Android) in the wizard, get a live HTTPS privacy policy URL, paste it into App Store Connect, then finish App Privacy. Soft side door: account deletion URLs stay free on Delete Account URL. Ads, lead forms, and stores stay on the $9.99/yr hosted plan.

Get free app URL

What to do

  1. Write for reviewers, not for legalese. Name your company and app, list what you collect, why, who you share it with, retention, and how users contact you or request deletion. Plain English beats dense boilerplate.
  2. Host a stable HTTPS page. Use a public web page, not a PDF or shortener. Keep one canonical URL so every future build points at the same address while you update the text.
  3. Paste into App Privacy. In App Store Connect, open App Privacy, edit Privacy Policy URL, paste the link, optionally add a User Privacy Choices URL, and Save. Details live in the step-by-step how-to.
  4. Match App Privacy labels. Complete the nutrition-label style questionnaire so declared data types match the policy and third-party SDKs. Mismatches are a frequent rejection pattern.
  5. Link inside the app. Put the same URL in Settings, Help, or account screens. Reviewers often open the in-app link, not only the Connect field.
  6. Test on an iPhone, then submit. Open the URL in Safari private mode. Confirm fast load, no login wall, and visible contact details. Then submit the version and watch Resolution Center notes.

Field labels to look for

Privacy Policy URL
Required in App Privacy / App Information for iOS and macOS.
User Privacy Choices URL
Optional public page for privacy choices, access, or deletion flows.
App Privacy details
Data types and purposes shown on the product page. Must align with the policy.

Common reasons the form fails

  • Missing or broken Privacy Policy URL
  • Policy that never names the app or developer
  • App Privacy answers that contradict the page or SDKs
  • Kids or family apps with vague parental contact language
  • Link shorteners or URLs that change every submission
  • Sending Meta lead-ad traffic to this free app guide

How this guide fits

This is the deep guide. For the field-by-field paste path, use the App Store Connect how-to. Google Play has its own how-to and guide. Free Mobile App path only; do not cannibalize the homepage head term Privacy Policy URL.

FAQ

Is a Privacy Policy URL required for every App Store app?

Yes. App Store Connect marks Privacy Policy URL as required for all apps.

Do kids apps need special wording?

Yes. Call out parental contact and how child data is handled. Vague family-category policies are commonly rejected.

Can one URL cover iOS, iPadOS, and macOS?

Yes. Keep one canonical HTTPS URL and name each product on the page if you ship multiple binaries.

What about tvOS?

tvOS often uses privacy policy text in App Store Connect. Keep disclosures consistent with your public page for other platforms.

Is Privacy Policy URL free for App Store apps?

Yes on our Mobile App path. Ads, lead forms, and stores use $9.99/yr.

Do I also need a delete-account URL?

If users can create an account, Apple expects a clear deletion path. That is separate from the privacy policy URL. Soft free option: Delete Account URL, or the App Store URL pack from the free Privacy Policy URL final step.

Do App Privacy labels have to match the policy?

Yes. Update both when you add SDKs or change collection. Reviewers compare them.

Can I use a link shortener?

Avoid shorteners. Use a clean, permanent HTTPS URL you can edit in place.

Where is the short step-by-step?

See How to add a Privacy Policy URL in App Store Connect for the field path and mobile checks.

Related

Sources