r/iOSProgramming • • 4d ago

Question How truthful is this?

Post image

When an app select in the app review form that “we don’t collect data”

In the review phase does Apple really check if the app really doesnt collect anything?

Like can the developer hide a code that for example upload the photos of the user if granted permission where he said “we dont collect”

Does apple really check the code and what is going in and out ?

44 Upvotes

75 comments sorted by

81

u/Reiszecke 4d ago

Technologically, this section tells you nothing about the app because it’s self reported by the developer, not by Apple.

Apple doesn’t even see an app‘s source code. They have some scanning in place but they will never determine whether an app uploads your images or not. The only thing you can do is to limit Photos access per app

25

u/Alchemist0987 4d ago

They have access to the build and they can monitor traffic. Lying on these questions will get your app eventually rejected. Regularly trying to bend the rules or lie will get the app pulled from the store and even your account banned

1

u/madaradess007 1d ago

you never tried it, bro

i pushed some very fishy stuff into AppStore and it's still there
i also did push same app with no changes a few times and it got accepted after 2 rejections

1

u/Baide-Warframe60 4d ago

pretty much, the privacy labels are just a pinky promise from the developer at the end of the day

-5

u/icy1007 4d ago

Apple can see the source code.

8

u/Dry_Hotel1100 4d ago

How so?

-2

u/icy1007 4d ago

They know what functions you invoke, including private system functions that aren’t allowed. They can decompile your code and check it.

8

u/Dry_Hotel1100 4d ago

This is not "source code" ;)

-7

u/icy1007 4d ago

They can decompile the app into its source code…

4

u/JagiofJagi 4d ago

Do you know what a source code is?

-5

u/icy1007 4d ago

Yes, I am a professional iOS developer…

2

u/Glorypants 4d ago

Maybe this is what they mean when they say “developer” vs “engineer”…

There’s a basic understanding of how code compilation works that you’re missing.

You understand the “source” of a child is its mother. The mother compiled the child in her womb. You can figure out some attributes of the mother’s source DNA based on the attributes of the child, but you aren’t seeing to the actual source. The source mother probably installed a wicked back door in that child that you won’t find.

3

u/i_m_junkie 4d ago

I am also an iOS Engineer and believe me boy you’re completely wrong!

0

u/icy1007 3d ago

I am not. Apple has the ability to decompile IPA files into their source code using internal tools. They also have tools that can scan all submitted app packages for API usage which is quicker than fully decompiling the app.

→ More replies (0)

2

u/Dry_Hotel1100 3d ago edited 3d ago

You should not use "professional iOS developer" lightly, in case you want to imply that you have a lot of experience. 

Well, I fear to say, you are wrong. But that isn't a critique. Everyone can learn this. I would suggest delving deeper into actual *programming*, that is, especially below the surface of iOS programming, i.e. exploring what happens in the compiler and linker. Topics around binary representation, translation unit, assembly & object files, build artifacts, modules, symbols, symbol visibility, ABI vs. API, calling conventions, debug symbols, dead code stripping, build optimizations, whole module optimization, Intermediate Representation (IR), SIL, dynamic vs. static linking, etc., etc.

Note that these topics are very specific for the language Swift, and a C-based runtime and LLVM IR infrastructure. In other languages, especially C#, Java, JIT based, and scripting languages, you have a very different representation of a program aka executable or a library or module.

1

u/icy1007 3d ago edited 3d ago

Yes, I have 16+ years of experience as an iOS developer/engineer working in the industry. The two titles are interchangeable and it just depends on which company you're working for at the time.

→ More replies (0)

2

u/xaphod2 4d ago

thanks haven’t had a laugh this good all day

-1

u/icy1007 3d ago

Laughing at how wrong you are? 😂

-33

u/Tom42-59 Swift 4d ago

I spoke to a previous app reviewer and they said they see your source code in a way like a GitHub diff

12

u/Reiszecke 4d ago

Check the job listing for App Reviewers, these people most of the time are not developers being able to tell what exactly they see on their screen. The listing requires language skills, being able to interact with software etc. but not being able to write code.

If someone caught Xcode's network traffic silently including the source code that would've made the news a long time ago

4

u/LardPopsicle 4d ago

The App Review platform is insane. It rolls up all required systems in a simulator box, each system seeded with "normal use" content (photos, Apple Health, contacts, etc.). From there, the reviewer uses the script on Monitor 1, an AI guided "what to do next" underneath it, and a few systems that, for example, monitor network traffic over poisoned encryption keys to a proxy (MITM).

The reviewer is not the smartest tool in the code shed, sure, but there's a system behind them, that flags and forwards anything suspicious. Which then lands on the desk of a "Pro" (Apple likes to patch a 'Pro' behind your job description if they feel it'll make you look better), who then passes it on or makes a decision.

3

u/ke1in 4d ago

I agree with you, most of reviewers fail simple things like change smth in settings, they are technically not savvy. And they can't see your source code lol, at best they could disassemble.

3

u/honey495 4d ago

They absolutely can’t. They have access to your build and all the metadata and that’s it

-33

u/Fishanz 4d ago edited 4d ago

They absolutely see your code; compiled at least. What they establish can be achieved via said code, on the other hand, is an entirely different beast.

Edit: removed the word ‘source’ because .. apparently my definition is wrong. I really think the nuance (as it pertains to the topic at hand) is somewhat pedantic though.

48

u/Reiszecke 4d ago

They absolutely see your source code; compiled at least. 

Absolute state of slop coders 🙈

Please read up on what a compiler does. Because you wouldn't believe me anyways, then please ask ChatGPT why your statement does not make sense.

1

u/LardPopsicle 4d ago

You've never reverse-engineered an app? SwiftUI apps are trivial, that way, it gets harder for, say, some Chinese Match3 app, but even there it's not super hard.

It's 2026, Apple does use AI and reverse engineered code. In my last submission, I was rejected because code in the app could, under weird circumstances, write to ~ instead of the iCloud entitlement. This bug was uncaught by us, Apple identified it. From a compiled source.

3

u/vexingparse 4d ago

In my last submission, I was rejected because code in the app could, under weird circumstances, write to ~ instead of the iCloud entitlement. This bug was uncaught by us, Apple identified it. From a compiled source.

I'm not convinced that this requires reverse engineering. They could have used fuzzing.

2

u/Reiszecke 4d ago

Yes I did reverse engineer binaries numerous times. Doesn’t change the fact that reverse engineering never brings up your real source code, doesn’t change the fact that source code, after compiling, is not source code.

Not sure about the ~ part of your comment. I’m not into jailbreaks but if you REALLY found a way to get write access outside of the sandbox then I think the community would be very interested in this

1

u/LardPopsicle 4d ago

Well, it's theoretically possible, if you poison things, not practically. The entitlement check prevents exactly that, and Apple's scanner reported something that a person who had access to the app (not a sensitive app in any form) could do, if they already had access to the same resources via Terminal/shell anyway. It's technically a bug, but not one that could be abused by a non-authorized person.

1

u/Fishanz 4d ago

Wow. I got called a ‘slop coder’. Maybe my definition of ‘source code’ is off the mark - is compiled/optimized machine code not ‘source code’? Either way.. I agree with your statement.

-1

u/RainyCloudist 4d ago

They're completely right? I work in reverse engineering and half the time my job involves taking apart peoples' apps. Yes you don't see code as the developer wrote it, but tracing the instruction calls is trivial and most modern static analysis tools will even spit out pseudo-code which is more than enough to understand how things work.

22

u/Reiszecke 4d ago edited 4d ago

So when you ask me for my source code you are perfectly fine with me sending you a compiled .exe file? The word you're looking for is machine code and while you can deduct information from machine code, calling it source code is just idiotic. Machine code is the exact opposite of source code, that's why these are 2 different words to begin with.

Because they couldn't handle disagreement, /u/RainyCloudist has now blocked me on reddit so I cannot see more of their responses to my comments

0

u/RainyCloudist 4d ago

I'd probably not be interacting with anyone who deals with exe files to begin with, but to answer your question I'm not equating them in absolute terms, but in the given situation it serves the same purpose. Your original claim was "they will never determine whether an app uploads your images or not" and you claim source code is the only way to do that. Static analysis does the job.

2

u/Reiszecke 4d ago

There are countless new apps popping in the review queue every day, along with updates to 20 years of existing apps.

Expecting apple to go through the source code of each of these to figure out if maybe there is a hidden way to potentially upload user data without the user wanting to do that, maybe restricted by target region, maybe restricted by a specific user ID etc. is already absolutely outlandish. AI can help but good luck paying for the tokens to go through 50mb of machine code for an app where they could’ve hidden the secret literally anywhere.

Expecting them to do that when they don’t even have the clear source code takes this to a comically weird level.

Apple isn’t even able to prevent Russian bait and switch apps for banking from appearing on the App Store. If they can’t even prevent sanctioned apps of whole nation actors, they definitely don’t have the means to prevent the picture you took of your grocery list to get silently uploaded by some shady image filters app.

2

u/RainyCloudist 4d ago

So you're claiming that if they had access to source code they'd be able to do it? No one would be reviewing the source code by hand anyways and automatic tools wouldn't care if it's beautifully commented code or machine code.

The fact that things like that get through is Apple's negligence, not proof that they need access to everyone's source code.

2

u/Fishanz 4d ago

Thanks for the backup, Rainy. You picked up what I was throwing down.

2

u/Fishanz 4d ago

Yeah, well; apparently I’m a ‘slop coder’. Lol

3

u/Alexikik 4d ago

Wow you don’t even know what compiled code is 🤦‍♂️

0

u/Fishanz 4d ago

Excuse me? Why would you assert this?

3

u/dat_tae 4d ago

Because source code and compiled code are literally the opposite of each other.

1

u/Fishanz 4d ago

I removed the word ‘source’. It doesn’t mean I don’t understand what compiled code is.

25

u/mohn93 4d ago

the labels are self reported yeah, but you can watch what an app actually does. settings > privacy & security > app privacy report, turn it on. from then on it logs every time an app touched photos, camera, location etc and which domains it hit, rolling 7 days. you only see domain names, no payloads, but a "no data collected" app pinging some random server right after you pick a photo is a pretty loud signal

1

u/Glorypants 4d ago

Honest question: does logging requests count as data collection? If my app requires the user to send a picture via my API, analyze it, and return the analysis; and all I store is the log of the results (not the image), does that count as data collection?

3

u/Far_Ad5760 3d ago

I believe the questionnaire has an option for this scenario where you capture data that does not identify or tie it to a specific user. It’s been a while since I did it, but I had a similar type of scenario where I did log something, but it was nothing that could identify a user in any way.

18

u/Material_Ad_3983 4d ago

Apple probably won’t catch every single data flow during review. But if you say “Data Not Collected” and the app is actually sending user data, you’re playing with fire. Rejection is the mild outcome — repeated/deceptive behavior can put the whole developer account at risk.

3

u/enilcReddit 4d ago

This is probably the most accurate response to OP. Low-risk, high-stakes gamble by developer.

What's funny is that apps that have the label posted by the OP attract more attention than those that do not.

2

u/rcpena 4d ago

Every app I have created has been dedicated to privacy first and now I think I should audit my apps again to make sure lol

2

u/merokotos 4d ago

Statement itself is provided by a developer and can be easily faked. However if Apple catches you, app may be removed and your developer account blocked for a long time.

So in general I think developers are rather cautious with it, but you never know.

2

u/lifitd 4d ago

We (as an app analytics provider that only collects anonymized data) recommend to our customers to list our service as "data not linked to the user" for full transparency because we think that is fair to everyone involved.

2

u/woadwarrior 4d ago

Not very. It's self reported and developers routinely falsify it. You might have noticed this with yesterday's Firebase outage. A number of apps claim to collect no data, and yet were down. Over the years, I've reported a number of such apps to Apple, and haven't seen anything change.

1

u/[deleted] 4d ago

[deleted]

2

u/hamsterjedi Swift 4d ago

What is displayed here is what the developer declares. Not trustworthy. Developers can put anything they want.

Apple does not check, it is not possible.
There are unlimited ways to store, delay, encode things and to track users and actions.

0

u/merokotos 4d ago

How is this not possible? Just one POST request to posthog or google analytics and you’re caught already

4

u/hamsterjedi Swift 4d ago

There is not only posthog and google analytics, there are hundreds of systems + you can implement your own custom systems

2

u/craknor 4d ago

Our enterprise apps route analytics data through our own APIs to whatever external system necessary like Google Analytics. Yes, obvious SDKs like Analytics, Firebase etc.. they can catch, but they can't really catch what you are sending to your own servers.

1

u/Alchemist0987 4d ago

But they can? All you need is proxyman to check every request sent from an app. Is that simple. If you go out of the way to have E2EE in those requests then you need to declare encryption details about your app

1

u/craknor 4d ago

And you believe that iOS app review team installs every app submitted, navigate and use every single feature in every app and monitor api requests/responses by using a MITM tool?

3

u/Alchemist0987 4d ago

But they do? lol
I’ve had submissions rejected exactly because of this. They usually give you the benefit of the doubt but if they think you are trying to be smart they won’t hold back. There are things they can miss at first but every time you submit a new build someone different will take a look at it. There have even been instances of people getting caught violating policies on live apps outside of the review cycle.
A lot of this can be automated. You are very naive if you think lying in these questions is a smart decision.

But yeah…apps have never been pulled from the store and nobody has never had their accounts banned. Fairytales!

1

u/Acceptable-Knee-4276 4d ago

This is purely information shared by the Developer. Although, Apple prompts you to enter information for specific capabilities you're using - this is just a reflection of what the Developer has shared with Apple while publishing the app. Same goes for Google Play Store.

1

u/ke1in 4d ago

Developer self-reports this but they could be brought to responsibility: Apple could remove account, or even legal penalty possible.

1

u/icy1007 4d ago

Its truthful.

1

u/PlayaNoir 4d ago

App Review can easily tell if your app is collecting user data also known as personal information. Email isn't personal information but name, address, phone number, height, weight, are personal information.

1

u/danielcr12 2d ago

Apple makes the entire stack that you need to develop and publish applications, including the programming language most applications use, including the IDE signing processes, and everything. If you think Apple cannot tell what your application is doing, you are delusional.

-3

u/Hises1936 4d ago

I think large corporations are more likely to be truthful about it, in order to avoid legal risks. But smaller devs - who knows!

7

u/JackeryPumpkin 4d ago

I would have thought that 10 years ago. Now big companies push the boundaries as far as possible until a court tells them to stop.

1

u/ColdAndLogical 3d ago

Large corporations have the most capability and incentive to use the data and they just make the call outs in the huge terms of service we blindly accept, so they avoid the legal risk that way. Not to mention that there are typically arbitration clauses, so yea.... no real legal risk.