App rejected: privacy policy URL missing or not working
Guideline 5.1.1 covers data collection and storage, and the most common way to fall foul of it is the simplest: the URL you entered does not load for
What the rejection means
Guideline 5.1.1 covers data collection and storage, and the most common way to fall foul of it is the simplest: the URL you entered does not load for the reviewer.
The usual causes
- The link 404s, or the page moved.
- The page sits behind a login or a cookie wall the reviewer cannot pass.
- The domain expired between one submission and the next.
- The URL points at a homepage rather than at the policy.
What to change
Put the policy somewhere that will still exist in a year, open the URL in a private window before you submit, and check it again on every update.
Before you resubmit
- Open every URL you entered in a private window.
- Read the reviewer's message again and answer the specific point, not the general topic.
- Reply in Resolution Center saying what you changed and where to see it.
Keeping it true after launch
A legal page stops being true the moment the product moves past it, usually by adding a payment provider, an analytics SDK or a sign-in. No store re-checks your pages against your build, so the drift is yours to notice.
- Re-read it whenever you add a dependency that sees user data.
- Re-check what loads on the page after any change: the cookie notice and the policy have to agree.
- Keep the URL stable. Changing where a policy lives breaks every listing that points at it.
Common questions
How long does a resubmission take?
Usually the same as a first review. Answering the exact point raised, with a link, is what shortens it.
Can I argue a rejection?
You can, and sometimes you should. It works when the reviewer has misread something and you can show it in one sentence with a link. It rarely works as a general objection.
