The Short Answer
Guideline 5.1.2 is Apple's Data Use and Sharing rule, and it sits right under 5.1.1 (Data Collection and Storage) in the App Review Guidelines. Where 5.1.1 is about what you collect, 5.1.2 is about what you do with it afterward: using it for something other than what the user agreed to, sharing it with a third party without saying so, or tracking someone across other companies' apps and websites without running Apple's App Tracking Transparency prompt first. App Review cites 5.1.2 when the app's behavior and the app's privacy disclosures don't match, or when tracking is happening with no ATT prompt in sight.
The Two Things 5.1.2 Actually Checks
Almost every real-world 5.1.2 rejection for an indie app falls into one of two buckets, and they call for different fixes.
- Tracking without permission. Your app correlates data about a person or device with data from other companies' apps or websites, most commonly through an ad SDK's advertising identifier, and does this without first showing Apple's App Tracking Transparency prompt and getting a 'granted' response.
- Sharing or repurposing without disclosure. Your app sends user data to a third party, including a third-party AI provider, or uses data collected for one purpose for something else, without your privacy policy and in-app disclosures saying that plainly first.
First-party analytics that never leaves your own backend and is never linked to an ad identifier is not tracking under Apple's definition. The moment that same data is shared with, or correlated with, a different company's data for advertising purposes, it crosses into ATT territory.
The 5.1.2 Check
App Store Launch Club members run four questions before submitting to catch a 5.1.2 issue before Apple does.
- Does your app link to an ad network, attribution SDK, or analytics tool that shares data across apps for advertising? If yes, you need the App Tracking Transparency prompt before that SDK starts sending anything.
- Does the app request tracking permission before any tracking-adjacent SDK initializes, not after? Initializing an ad SDK before the prompt fires is the same as never showing the prompt, from Apple's point of view.
- Does the app send any user data, messages, images, or profile fields to a third-party AI API? If yes, does your privacy policy name that provider and explain what gets sent?
- Does anything in your data flow repurpose data collected for one feature to power a different one, such as using support-ticket text to train a recommendation feature, without telling the user?
A yes to the first or third question with no matching disclosure is the real gap. Read your own privacy policy against what your app's network calls actually do, the same way a reviewer checking Guideline 5.1.2 will.
Adding App Tracking Transparency to an Expo App
Expo ships an official package for this, so the fix is config plus one call, not a custom native module.
- Install the package: npx expo install expo-tracking-transparency.
- Add the config plugin in app.json under expo.plugins, with a userTrackingPermission string that says plainly what tracking is for, for example "This identifier will be used to deliver personalized ads to you." That string becomes NSUserTrackingUsageDescription in Info.plist. If you omit it, Expo falls back to a generic default string, which is legal but reads as less deliberate to a reviewer.
- Call requestTrackingPermissionsAsync from expo-tracking-transparency before any ad SDK, attribution SDK, or cross-app analytics tool initializes, not after. The status it returns is 'granted', 'denied', 'restricted', or 'undetermined'.
- Gate the tracking-adjacent SDK's init call on that granted status. If the user denies or the status is anything other than granted, the SDK should still work for non-personalized ads or simply not track, not silently track anyway.
- Rebuild with EAS after adding the plugin, since the Info.plist key is compiled into the binary and only takes effect in a new build.
Disclosing Third-Party AI Under 5.1.2
This is the part of 5.1.2 that catches builders who never touched an ad network. If your Expo app sends anything a user typed, uploaded, or generated to an outside AI API, whether that is a chat feature, an image generator, or a background enrichment call, Apple's current guideline requires you to clearly disclose where that personal data will be shared with third parties, including with third-party AI, and get explicit permission before doing so.
- Name the AI provider in your privacy policy the same way you would name an analytics vendor: what data reaches it, and for what purpose.
- Get the disclosure in front of the user before the first call that sends their data out, not buried three menus deep in a settings screen they may never open.
- If the AI call only processes data momentarily and does not retain it, say that explicitly. If it does retain data for model improvement, say that too. Vague language here reads to App Review the same way a missing disclosure does.
- Keep this in sync with your App Privacy details in App Store Connect, since a privacy policy that names a data use your nutrition label does not declare is its own inconsistency for a reviewer to catch.
The full walkthrough of the App Store Connect side of this, including how the nutrition-label questions map to what you actually collect, is in [App Privacy details questionnaire guide](/blog/app-privacy-details-app-store-connect).
The Guideline It Travels With: 5.1.1
5.1.1 and 5.1.2 sit back to back in the same Privacy section of the guidelines, and reviewers reading your privacy policy for one naturally check it against the other. An app with a clean account-deletion flow but a privacy policy that doesn't mention an ad SDK it ships with is a strong candidate for a 5.1.2 rejection even after clearing 5.1.1. The account-deletion side of this section is covered in [Guideline 5.1.1: how to add account deletion to your Expo app](/blog/app-store-rejection-guideline-5-1-1).
How to Answer a 5.1.2 Rejection in Resolution Center
If the rejection already landed, treat it like any other Resolution Center message: identify the specific data flow being flagged, fix that flow, then reply once.
- Identify whether the citation is about tracking without an ATT prompt or about an undisclosed data share, since the fix and the reply are different for each.
- If it's tracking, confirm the ATT prompt now fires before the SDK in question initializes, and state that in your reply.
- If it's disclosure, update the privacy policy and App Privacy details first, then state in your reply exactly what changed and where the disclosure now lives.
- Submit a new build. A reply describing a fix that has not shipped in a new build does not resolve the rejection.
The general pattern for answering any Resolution Center message is covered in [Guideline 2.1 Information Needed](/blog/guideline-2-1-information-needed-rejection).
Short, practical drops on app ideas, validating fast, store listings, and passing app review. No spam, unsubscribe anytime.
Frequently asked questions
What is a Guideline 5.1.2 rejection?
Guideline 5.1.2 is Apple's Data Use and Sharing rule. App Review cites it when an app tracks a user across other companies' apps or websites without the App Tracking Transparency prompt, or when it shares or repurposes personal data, including sending it to a third-party AI provider, without disclosing that in the privacy policy first.
Do I need App Tracking Transparency if I only use first-party analytics?
Not necessarily. Apple's tracking definition is about correlating data with a different company's data for advertising, most commonly via an advertising identifier. Analytics that stays on your own backend and is never linked to an ad network for cross-app targeting is not tracking under that definition, but any ad SDK or attribution tool that does cross-app correlation needs the ATT prompt first.
Does sending data to an AI API require a 5.1.2 disclosure?
Yes. Apple's current guideline text specifically requires you to clearly disclose where personal data will be shared with third parties, including with third-party AI, and to get explicit permission before doing so. Name the AI provider and what data reaches it in your privacy policy before the first call that sends user data out.
How do I add App Tracking Transparency to an Expo app?
Install expo-tracking-transparency, add its config plugin to app.json with a userTrackingPermission string, call requestTrackingPermissionsAsync before any tracking-adjacent SDK initializes, and gate that SDK's start on a granted status. Rebuild with EAS, since the Info.plist key is compiled into the binary.
Does the ATT prompt work the same on Android?
No. requestTrackingPermissionsAsync always resolves to granted on Android and web, because App Tracking Transparency is an iOS-only framework tied to Apple's advertising identifier rules. Test the real prompt on iOS.
How is Guideline 5.1.2 different from 5.1.1?
5.1.1 covers what data you collect and store, including requiring account deletion for apps with account creation. 5.1.2 covers what you do with data after collecting it: using it for a new purpose, sharing it with a third party, or tracking someone across other apps and sites without the required permission.
Last reviewed by David on September 1, 2026


