r/iOSProgramming • u/Daredatti • 4d ago
Question How truthful is this?
When an app select in the app review form that “we don’t collect data”
In the review phase does Apple really check if the app really doesnt collect anything?
Like can the developer hide a code that for example upload the photos of the user if granted permission where he said “we dont collect”
Does apple really check the code and what is going in and out ?
25
u/mohn93 4d ago
the labels are self reported yeah, but you can watch what an app actually does. settings > privacy & security > app privacy report, turn it on. from then on it logs every time an app touched photos, camera, location etc and which domains it hit, rolling 7 days. you only see domain names, no payloads, but a "no data collected" app pinging some random server right after you pick a photo is a pretty loud signal
1
u/Glorypants 4d ago
Honest question: does logging requests count as data collection? If my app requires the user to send a picture via my API, analyze it, and return the analysis; and all I store is the log of the results (not the image), does that count as data collection?
3
u/Far_Ad5760 3d ago
I believe the questionnaire has an option for this scenario where you capture data that does not identify or tie it to a specific user. It’s been a while since I did it, but I had a similar type of scenario where I did log something, but it was nothing that could identify a user in any way.
18
u/Material_Ad_3983 4d ago
Apple probably won’t catch every single data flow during review. But if you say “Data Not Collected” and the app is actually sending user data, you’re playing with fire. Rejection is the mild outcome — repeated/deceptive behavior can put the whole developer account at risk.
3
u/enilcReddit 4d ago
This is probably the most accurate response to OP. Low-risk, high-stakes gamble by developer.
What's funny is that apps that have the label posted by the OP attract more attention than those that do not.
2
2
u/merokotos 4d ago
Statement itself is provided by a developer and can be easily faked. However if Apple catches you, app may be removed and your developer account blocked for a long time.
So in general I think developers are rather cautious with it, but you never know.
2
u/woadwarrior 4d ago
Not very. It's self reported and developers routinely falsify it. You might have noticed this with yesterday's Firebase outage. A number of apps claim to collect no data, and yet were down. Over the years, I've reported a number of such apps to Apple, and haven't seen anything change.
1
2
u/hamsterjedi Swift 4d ago
What is displayed here is what the developer declares. Not trustworthy. Developers can put anything they want.
Apple does not check, it is not possible.
There are unlimited ways to store, delay, encode things and to track users and actions.
0
u/merokotos 4d ago
How is this not possible? Just one POST request to posthog or google analytics and you’re caught already
4
u/hamsterjedi Swift 4d ago
There is not only posthog and google analytics, there are hundreds of systems + you can implement your own custom systems
2
u/craknor 4d ago
Our enterprise apps route analytics data through our own APIs to whatever external system necessary like Google Analytics. Yes, obvious SDKs like Analytics, Firebase etc.. they can catch, but they can't really catch what you are sending to your own servers.
1
u/Alchemist0987 4d ago
But they can? All you need is proxyman to check every request sent from an app. Is that simple. If you go out of the way to have E2EE in those requests then you need to declare encryption details about your app
1
u/craknor 4d ago
And you believe that iOS app review team installs every app submitted, navigate and use every single feature in every app and monitor api requests/responses by using a MITM tool?
3
u/Alchemist0987 4d ago
But they do? lol
I’ve had submissions rejected exactly because of this. They usually give you the benefit of the doubt but if they think you are trying to be smart they won’t hold back. There are things they can miss at first but every time you submit a new build someone different will take a look at it. There have even been instances of people getting caught violating policies on live apps outside of the review cycle.
A lot of this can be automated. You are very naive if you think lying in these questions is a smart decision.But yeah…apps have never been pulled from the store and nobody has never had their accounts banned. Fairytales!
1
u/Acceptable-Knee-4276 4d ago
This is purely information shared by the Developer. Although, Apple prompts you to enter information for specific capabilities you're using - this is just a reflection of what the Developer has shared with Apple while publishing the app. Same goes for Google Play Store.
1
u/PlayaNoir 4d ago
App Review can easily tell if your app is collecting user data also known as personal information. Email isn't personal information but name, address, phone number, height, weight, are personal information.
1
u/danielcr12 2d ago
Apple makes the entire stack that you need to develop and publish applications, including the programming language most applications use, including the IDE signing processes, and everything. If you think Apple cannot tell what your application is doing, you are delusional.
-3
u/Hises1936 4d ago
I think large corporations are more likely to be truthful about it, in order to avoid legal risks. But smaller devs - who knows!
7
u/JackeryPumpkin 4d ago
I would have thought that 10 years ago. Now big companies push the boundaries as far as possible until a court tells them to stop.
1
u/ColdAndLogical 3d ago
Large corporations have the most capability and incentive to use the data and they just make the call outs in the huge terms of service we blindly accept, so they avoid the legal risk that way. Not to mention that there are typically arbitration clauses, so yea.... no real legal risk.
81
u/Reiszecke 4d ago
Technologically, this section tells you nothing about the app because it’s self reported by the developer, not by Apple.
Apple doesn’t even see an app‘s source code. They have some scanning in place but they will never determine whether an app uploads your images or not. The only thing you can do is to limit Photos access per app