Your "we use AI" line is now a consent screen. Apple's rule 5.1.2(i) has been live since November.

by•

Apple's App Review Guidelines say you must disclose where personal data goes to third-party AI and get explicit permission first. A privacy policy paragraph doesn't do that.

Most of us read Apple's November 2025 guideline update, saw "AI" in it, and filed it under things for the big players. I did too, until I reread it as someone who sends people's journal entries to a language model.

Guideline 5.1.2(i) now says: "You must clearly disclose where personal data will be shared with third parties, including with third-party AI, and obtain explicit permission before doing so." Apple announced the revision on 13 November 2025. I could not find a grace period in the coverage I read, and the guidelines call themselves a living document, so I would assume it is enforced now.

Three things about the wording are easy to miss.

First, it says explicit permission, not a line in your privacy policy. A consent the user has to actively give, in the flow, before the first request leaves the device, is the safe reading. A footer link is not.

Second, "third-party AI" is about where the data goes, not what your app is. If you call a hosted model API from your backend, the data is being shared with a third party, even if the user never sees the model's name. Whether your provider is contractually a processor is a legal question I cannot answer for you, and I am not a lawyer. But the review team reads your app, not your vendor agreement.

Third, the consent has to be specific. "We use AI to improve your experience" tells the user nothing. What helps is saying what is sent (the text of an entry, not just metadata), who receives it, and what happens afterwards.

What I am doing, and what I would do in any small app that touches anything personal: list every place user content leaves your servers for a model, write down the provider next to each one, and put a plain-language consent screen before the first call, with a way to say no that still leaves the app usable. Then add the same line to your release checklist as the age-rating answer, so the next person who wires in a new model has to revisit it.

For an app like ours the stakes are lopsided. People write things in a journal they would not say out loud. A rejected build is annoying. Quietly sending that text somewhere the user did not understand is the version that costs trust, and Apple's rule happens to force the honest design.

Primary source is Apple's App Review Guidelines, section 5.1.2. Read it directly rather than trusting my summary, because it has been rewritten more than once this year.

How are you handling consent for model calls in your app: one upfront screen, or per feature?

16 views

Add a comment

Replies

Be the first to comment