App Store Submission Reference

SkillDev tools

App Store submission reference — complete metadata field specs, App Review guideline index, privacy manifest schema, age rating system, export compliance, EU DSA requirements, IAP review pipeline, and WWDC25 submission changes

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the App Store Submission Reference skill

What this skill tells your AI

The instructions your AI receives, as published by comeonoliver/skillshub in skills/CharlesWiltgen/Axiom/axiom-app-store-ref/SKILL.md and read by ahel’s review.

Overview

Complete reference for every App Store submission requirement:

  • Part 1 — Required metadata fields (descriptions, screenshots, keywords, App Review info)
  • Part 2 — Privacy requirements (manifest schema, nutrition labels, ATT, Required Reason APIs)
  • Part 3 — App Review Guidelines quick reference (all sections 1-5)
  • Part 4 — Age rating system (5-tier, capabilities, regional variations)
  • Part 5 — Export compliance (encryption decision tree)
  • Part 6 — Account and authentication requirements (deletion, SIWA)
  • Part 7 — Monetization and IAP submission pipeline
  • Part 8 — EU-specific compliance (DSA trader status)
  • Part 9 — Build upload and processing
  • Part 10 — WWDC25 changes (draft submissions, accessibility labels, tags)

When to Use This Skill

Use when
  • Looking up specific metadata field requirements or character limits
  • Checking App Review guideline numbers for a specific topic
  • Verifying privacy manifest schema fields or Required Reason API categories
  • Understanding age rating tiers and new capability declarations
  • Checking EU compliance requirements for DSA trader status
  • Understanding IAP submission pipeline and review flow
  • Preparing builds for upload (SDK requirements, encryption, signing)
Do NOT use when
  • Deciding if your app is ready to submit (use app-store-submission)
  • Troubleshooting a rejection (use app-store-diag)
  • Implementing in-app purchases (use storekit-ref)
  • Writing privacy manifest code (use privacy-ux)
  • Auditing accessibility compliance (use accessibility-diag)

Related Skills

  • app-store-submission — Discipline skill with pre-flight checklist and workflow
  • app-store-diag — Rejection troubleshooting and appeal guidance
  • privacy-ux — Privacy manifest implementation, ATT UX, permission requests
  • storekit-ref — StoreKit 2 API reference for IAP implementation
  • accessibility-diag — Accessibility compliance scanning and VoiceOver testing

Key Terminology

TermDefinition
App Store ConnectWeb portal and API for managing app metadata, builds, pricing, TestFlight, and analytics
App ReviewApple's human review process that evaluates every app update against the App Review Guidelines
Privacy ManifestPrivacyInfo.xcprivacy file declaring data collection, tracking domains, and Required Reason API usage
Required Reason APISystem APIs (file timestamps, disk space, user defaults, etc.) that require declared usage reasons
Privacy Nutrition LabelApp Store privacy cards showing what data your app collects and how it uses it
DSA Trader StatusEU Digital Services Act classification determining if you are a "trader" selling to EU consumers
Build StringUnique identifier for each uploaded build (e.g., "1.2.3.4"), separate from version number
Bundle IDReverse-domain identifier (e.g., "com.company.app") uniquely identifying your app across Apple's ecosystem

Part 1: Required Metadata Fields

App Information

FieldRequiredLocalizableMax LengthNotes
App NameYesYes30 charsMust be unique on the App Store
SubtitleNoYes30 charsAppears below app name in search results
DescriptionYesYes4000 charsPlain text, no HTML or rich formatting
Promotional TextNoYes170 charsEditable without new submission
KeywordsYesYes100 bytesComma-separated, each keyword >2 chars
What's NewYes*Yes4000 chars*Required for all versions except first
CopyrightYesNoFormat: "YYYY Company Name"
Support URLYesYesMust link to actual contact information
Marketing URLNoYesOptional promotional page
Privacy Policy URLYesYesHTTPS, publicly accessible

Visual Assets

AssetRequiredLocalizableSpecification
App IconYesNo1024x1024 PNG, no alpha, no rounded corners
ScreenshotsYesYesPer device size, 2-10 per locale per device
App PreviewNoYesUp to 3 videos per device size per locale
Screenshot Requirements

Screenshots must be provided for each device size you support:

DeviceRequired Size (portrait)Required Size (landscape)
iPhone 6.9"1320 x 28682868 x 1320
iPhone 6.7"1290 x 27962796 x 1290
iPhone 6.5"1284 x 27782778 x 1284
iPhone 5.5"1242 x 22082208 x 1242
iPad Pro 13"2048 x 27322732 x 2048
iPad Pro 12.9"2048 x 27322732 x 2048

Screenshots must show the app in actual use. Not permitted: title art alone, login screens, splash screens, or screens from other platforms.

App Preview Video Specifications
SpecificationRequirement
Duration15-30 seconds
FormatH.264, ProRes 422
AudioEnglish or localized; no offensive content
Frame rate30 or 60 fps
ResolutionMust match screenshot dimensions for the device
ContentMust show actual app footage; no device frames allowed in video
Per localeUp to 3 preview videos per device size per locale
App Icon Requirements
SpecificationRequirement
Size1024 x 1024 pixels
FormatPNG
Color spacesRGB or P3
Alpha channelNot allowed
Rounded cornersNot allowed (system applies automatically)
Layers/transparencyNot allowed
ContentMust be appropriate for 4+ rating regardless of app's actual rating

App Review Information

FieldRequiredNotes
Contact First NameYesReviewer contact
Contact Last NameYesReviewer contact
Contact EmailYesMust be monitored
Contact PhoneYesInclude country code
Notes for ReviewNoUp to 4000 bytes; explain non-obvious features
Sign-in UsernameIf login requiredMust not expire during review
Sign-in PasswordIf login requiredMust not expire during review
AttachmentNoUp to 10 files, max 512 MB total

Metadata Rules (Guideline 2.3)

  • App names must be unique, max 30 characters
  • Keywords must not include trademarked terms, popular app names, or pricing terms ("free", "sale")
  • Screenshots must show the app in use, not just marketing art
  • Icons, screenshots, and previews must be appropriate for a 4+ rating even if the app is rated higher
  • "For Kids" and "For Children" are reserved for the Kids category
  • No other mobile platform names or imagery in screenshots (no Android phones, Windows logos)
  • Metadata must accurately reflect app functionality; misleading metadata is grounds for rejection

Localization Requirements

AspectDetails
MinimumPrimary language required; all other localizations optional
Per-locale metadataApp name, subtitle, description, keywords, What's New, screenshots
Promotional TextLocalizable and editable without new submission
ScreenshotsCan differ per locale (show localized UI)
App PreviewsCan differ per locale (show localized audio/UI)
URL fieldsSupport URL and Marketing URL can differ per locale

When localizing, provide screenshots that match the localized UI. Reviewers check that screenshots accurately represent the app in each locale.

Category Selection

Primary CategorySecondary CategoryRules
RequiredOptionalChoose the category that best describes your app
Must be accurateCan complement primaryInaccurate category is grounds for rejection (2.3.7)
Games have subcategoriesGames must also select up to 2 game subcategories

Available categories: Books, Business, Developer Tools, Education, Entertainment, Finance, Food & Drink, Games, Graphics & Design, Health & Fitness, Lifestyle, Magazines & Newspapers, Medical, Music, Navigation, News, Photo & Video, Productivity, Reference, Shopping, Social Networking, Sports, Travel, Utilities, Weather.


Part 2: Privacy Requirements

Privacy Policy (Guideline 5.1.1(i))

Required in BOTH locations:

  1. App Store Connect metadata (Privacy Policy URL field)
  2. Within the app itself (accessible from settings or equivalent)

The privacy policy must identify:

  • What data is collected and by what means
  • All uses of collected data
  • Third-party sharing practices
  • Data retention and deletion policies
  • How users can revoke consent

Privacy Manifest Schema (PrivacyInfo.xcprivacy)

<!-- Top-level keys -->
NSPrivacyTracking              <!-- Boolean: Does app track users? -->
NSPrivacyTrackingDomains       <!-- Array<String>: Domains used for tracking -->
NSPrivacyCollectedDataTypes    <!-- Array<Dictionary>: Data collected -->
NSPrivacyAccessedAPITypes      <!-- Array<Dictionary>: Required Reason APIs -->
NSPrivacyCollectedDataTypes Entry

Each dictionary in the array contains:

KeyTypeDescription
NSPrivacyCollectedDataTypeStringCategory key (e.g., "NSPrivacyCollectedDataTypeName")
NSPrivacyCollectedDataTypePurposesArray<String>Purpose keys for this data type
NSPrivacyCollectedDataTypeLinkedBooleanIs this data linked to user identity?
NSPrivacyCollectedDataTypeTrackingBooleanIs this data used for tracking?
NSPrivacyAccessedAPITypes Entry

Each dictionary in the array contains:

KeyTypeDescription
NSPrivacyAccessedAPITypeStringAPI category identifier
NSPrivacyAccessedAPITypeReasonsArray<String>Approved reason codes for usage
Complete PrivacyInfo.xcprivacy Example
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN"
  "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
    <key>NSPrivacyTracking</key>
    <false/>
    <key>NSPrivacyTrackingDomains</key>
    <array/>
    <key>NSPrivacyCollectedDataTypes</key>
    <array>
        <dict>
            <key>NSPrivacyCollectedDataType</key>
            <string>NSPrivacyCollectedDataTypeEmailAddress</string>
            <key>NSPrivacyCollectedDataTypeLinked</key>
            <true/>
            <key>NSPrivacyCollectedDataTypeTracking</key>
            <false/>
            <key>NSPrivacyCollectedDataTypePurposes</key>
            <array>
                <string>NSPrivacyCollectedDataTypePurposeAppFunctionality</string>
            </array>
        </dict>
    </array>
    <key>NSPrivacyAccessedAPITypes</key>
    <array>
        <dict>
            <key>NSPrivacyAccessedAPIType</key>
            <string>NSPrivacyAccessedAPICategoryUserDefaults</string>
            <key>NSPrivacyAccessedAPITypeReasons</key>
            <array>
                <string>CA92.1</string>
            </array>
        </dict>
    </array>
</dict>
</plist>
API Category Identifiers
CategoryIdentifier String
File timestampNSPrivacyAccessedAPICategoryFileTimestamp
System boot timeNSPrivacyAccessedAPICategorySystemBootTime
Disk spaceNSPrivacyAccessedAPICategoryDiskSpace
Active keyboardNSPrivacyAccessedAPICategoryActiveKeyboards
User defaultsNSPrivacyAccessedAPICategoryUserDefaults
Generating Aggregate Privacy Report
Xcode > Product > Archive > Generate Privacy Report

This produces a PDF summarizing privacy manifests from your app and all embedded frameworks.

Required Reason API Categories

CategoryAPIs CoveredCommon Reasons
File timestampNSFileCreationDate, NSFileModificationDate, NSURLContentModificationDateKeyDDA9.1 (display to user), C617.1 (inside app container)
System boot timesystemUptime, mach_absolute_time35F9.1 (measure elapsed time)
Disk spaceNSFileSystemFreeSize, NSFileSystemSize, volumeAvailableCapacityKeyE174.1 (check before writing), 85F4.1 (display to user)
Active keyboardactiveInputModes54BD.1 (customize UI for keyboard)
User defaultsUserDefaults (all access requires declaration)CA92.1 (access within app group), 1C8F.1 (access within same app)

App Privacy Details (Nutrition Labels)

Data Type Categories
CategoryExamples
Contact InfoName, email address, phone number, physical address
Health & FitnessHealth data, fitness data
Financial InfoPayment info, credit info
LocationPrecise location, coarse location
Sensitive InfoRacial or ethnic data, sexual orientation, religion, biometrics
ContactsAddress book contacts
User ContentPhotos, videos, audio, gameplay content, customer support messages
Browsing HistoryWeb browsing history
Search HistoryIn-app search history
IdentifiersUser ID, device ID
PurchasesPurchase history
Usage DataProduct interaction, advertising data, app launches, taps, scrolls
DiagnosticsCrash data, performance data
SurroundingsEnvironment scanning (e.g., AR data)
BodyHands, head (e.g., hand tracking in visionOS)
Purpose Categories
PurposeDescription
Third-Party AdvertisingDisplaying third-party ads or sharing with ad networks
Developer's Advertising/MarketingYour own marketing campaigns
AnalyticsUnderstanding user behavior and measuring effectiveness
Product PersonalizationCustomizing features, content recommendations
App FunctionalityRequired for app to work (e.g., authentication, data sync)
OtherAny purpose not listed above

Tracking and Collection Definitions

"Collected" means data is transmitted off-device and accessible beyond what is needed to service the current request. On-device-only processing is NOT collection.

"Tracking" means:

  • Linking user/device data from your app with third-party data for advertising or measurement, OR
  • Sharing user/device data with a data broker

App Tracking Transparency (ATT)

Required if your app "tracks" per Apple's definition above.

  • Add NSUserTrackingUsageDescription to Info.plist (explains why tracking is needed)
  • Call ATTrackingManager.requestTrackingAuthorization() before tracking
  • Respect the result:
    • .authorized — User granted permission to track
    • .denied — User denied tracking; do not track
    • .notDetermined — User has not yet been asked
    • .restricted — Device-level restriction prevents tracking

Request at a contextually appropriate moment, not at first launch.

Common Purpose Strings (NS*UsageDescription)

These Info.plist keys must be present for each system permission your app requests:

PermissionInfo.plist Key
CameraNSCameraUsageDescription
MicrophoneNSMicrophoneUsageDescription
Photo Library (read)NSPhotoLibraryUsageDescription
Photo Library (write)NSPhotoLibraryAddUsageDescription
Location (when in use)NSLocationWhenInUseUsageDescription
Location (always)NSLocationAlwaysAndWhenInUseUsageDescription
ContactsNSContactsUsageDescription
Calendars (full access)NSCalendarsFullAccessUsageDescription
Reminders (full access)NSRemindersFullAccessUsageDescription
HealthNSHealthShareUsageDescription, NSHealthUpdateUsageDescription
MotionNSMotionUsageDescription
BluetoothNSBluetoothAlwaysUsageDescription
Face IDNSFaceIDUsageDescription
Local NetworkNSLocalNetworkUsageDescription
TrackingNSUserTrackingUsageDescription
Speech RecognitionNSSpeechRecognitionUsageDescription
Apple MusicNSAppleMusicUsageDescription

Missing purpose strings cause immediate rejection. Purpose string text must clearly explain why the permission is needed in the context of your app's functionality.

Third-Party SDK Privacy Manifests

Apple maintains a list of commonly used SDKs that require privacy manifests. Starting spring 2024, if your app includes these SDKs without privacy manifests, it will be flagged during submission.

Third-party SDKs should include their own PrivacyInfo.xcprivacy in their framework bundle. The aggregate privacy report combines all manifests from your app and embedded frameworks.

If a third-party SDK does not include a privacy manifest, you must declare its data collection in your app's privacy manifest.


Part 3: App Review Guidelines Quick Reference

For the complete guideline index (Sections 1-5), see references/app-review-guidelines.md.

Most Common Rejection Reasons

Based on Apple's published data, the most frequent rejection reasons:

RankGuidelineIssuePrevention
12.1App Completeness — bugs, crashes, placeholder contentThorough QA before submission
24.3Spam — duplicate apps, cookie-cutter templatesEnsure genuine unique value
32.3.3Inaccurate screenshotsScreenshots must match actual app
45.1.1Privacy — missing policy or purpose stringsComplete all privacy requirements
54.0Design — not meeting minimum quality barFollow HIG, test all flows
62.5.1Private API usageOnly use public APIs
73.1.1IAP required for digital goodsUse IAP for digital content
84.2Minimum functionality — app too simpleProvide genuine utility
95.1.1(v)Missing account deletionImplement full account deletion
102.3.7Wrong app categoryChoose accurate primary category

App Review Timeline

StageTypical Duration
Waiting for ReviewMinutes to hours
In ReviewMinutes to 24 hours
Total (90th percentile)Under 24 hours
Total (edge cases)Up to 7 days
Expedited ReviewSame day to 24 hours (if approved)

Review times increase during holidays and major iOS release periods. Plan submissions accordingly.


Part 4: Age Rating System

Five-Tier Rating System (Updated January 31, 2026)

RatingTriggers
4+No objectionable material
9+Infrequent or mild: profanity, cartoon/fantasy violence, horror/fear themes. Loot boxes present
13+Frequent or intense: profanity or crude humor. Infrequent: alcohol/tobacco/drugs references, sexual content/nudity, realistic violence
16+Unrestricted web access, frequent medical/treatment info, mature/suggestive themes
18+Frequent or intense: alcohol/tobacco/drugs use, sexual content/nudity, realistic violence. Simulated gambling with real-money elements
UnratedApp cannot be published without completing the questionnaire

Capability Declarations (New, WWDC25)

Apps must declare if they include these capabilities:

CapabilityWhen to Declare
Messaging/chatAny in-app messaging between users
User-generated contentUsers can post, share, or upload content visible to others
AdvertisingApp displays ads from any ad network
Parental controlsApp has parental restrictions or family features
Age assuranceApp verifies user age for restricted content

These declarations appear alongside the age rating on the App Store product page, giving parents and users additional transparency.

Regional Variations

Age ratings map differently across regions:

Apple RatingAustraliaBrazilKoreaGermany (USK)
4+4+L (All ages)All0
9+9+A1012+6
13+13+A1215+12
16+15+A1619+16
18+R 18+A1819+18

The age rating questionnaire automatically generates the appropriate regional ratings based on your answers.

Age Rating Best Practices

  • Answer the questionnaire conservatively; under-rating leads to rejection
  • If your app accesses unrestricted web content (WebView without content filter), it will be rated 16+ minimum
  • UGC apps typically need 13+ minimum due to moderation requirements
  • Simulated gambling (even without real money) requires at least 9+
  • Realistic violence in gameplay requires at least 13+

Age Rating Questionnaire Topics

The questionnaire covers these content categories:

CategoryOptions
Cartoon or Fantasy ViolenceNone, Infrequent/Mild, Frequent/Intense
Realistic ViolenceNone, Infrequent/Mild, Frequent/Intense
Profanity or Crude HumorNone, Infrequent/Mild, Frequent/Intense
Mature/Suggestive ThemesNone, Infrequent/Mild, Frequent/Intense
Alcohol, Tobacco, or Drug Use or ReferencesNone, Infrequent/Mild, Frequent/Intense
Sexual Content and NudityNone, Infrequent/Mild, Frequent/Intense
Horror/Fear ThemesNone, Infrequent/Mild, Frequent/Intense
Simulated GamblingNone, Infrequent/Mild, Frequent/Intense
Medical/Treatment InformationNone, Infrequent/Mild, Frequent/Intense
Unrestricted Web AccessYes/No

The system automatically calculates your app's age rating across all regions based on your answers.


Part 5: Export Compliance

Encryption Decision Tree

Does your app use encryption?
├── No → Set ITSAppUsesNonExemptEncryption = NO in Info.plist → Done
├── Only HTTPS/TLS/URLSession?
│   ├── Yes → Exempt, set ITSAppUsesNonExemptEncryption = NO → Done
│   │         (May need annual self-classification report to BIS)
│   └── No (custom encryption) →
│       Set ITSAppUsesNonExemptEncryption = YES →
│       Upload compliance documentation to App Store Connect →
│       Receive encryption compliance code →
│       Set ITSEncryptionExportComplianceCode in Info.plist → Done

Info.plist Keys

<!-- Most apps: HTTPS only -->
<key>ITSAppUsesNonExemptEncryption</key>
<false/>

<!-- Apps with custom encryption -->
<key>ITSAppUsesNonExemptEncryption</key>
<true/>
<key>ITSEncryptionExportComplianceCode</key>
<string>YOUR_COMPLIANCE_CODE</string>

Exempt Encryption Uses

These are exempt from export documentation (but may still require annual self-classification):

  • HTTPS/TLS (URLSession, Network.framework, WKWebView)
  • Secure Enclave operations (biometric auth, Keychain)
  • Apple's built-in encryption frameworks (CryptoKit, Security.framework) when used per Apple documentation
  • Password hashing (bcrypt, scrypt, PBKDF2)

Non-Exempt Encryption Uses

These require compliance documentation:

  • Custom encryption algorithms
  • Open-source encryption libraries (OpenSSL, libsodium) used for non-standard purposes
  • End-to-end encrypted messaging
  • VPN implementations
  • Custom DRM systems

Part 6: Account and Authentication

Account Deletion (Required Since June 2022)

Apps that support account creation must offer account deletion. Requirements:

RequirementDetails
Full deletionMust fully delete the account, not just deactivate
Easy to findMust be accessible from app settings; not buried behind support tickets
Inform timelineTell user how long deletion takes
Confirm completionNotify user when deletion is complete
Delete shared UGCMust handle user-generated content shared with others
Revoke SIWA tokensCall Apple's revoke token endpoint for Sign in with Apple accounts
Handle subscriptionsWarn about active subscriptions; direct to subscription management
Sign in with Apple Token Revocation

Shortened here. Read the whole file on GitHub.

Signals

GitHub stars
63
Forks
22
Last commit
Jun 2026
Advanced
Catalog kind
skill
Gateway key
axiom-app-store-ref
Source
github.com/comeonoliver/skillshub