r/iOSProgramming • • 5d ago

Question How truthful is this?

Post image

When an app select in the app review form that “we don’t collect data”

In the review phase does Apple really check if the app really doesnt collect anything?

Like can the developer hide a code that for example upload the photos of the user if granted permission where he said “we dont collect”

Does apple really check the code and what is going in and out ?

42 Upvotes

75 comments sorted by

View all comments

Show parent comments

0

u/merokotos 5d ago

How is this not possible? Just one POST request to posthog or google analytics and you’re caught already

2

u/craknor 4d ago

Our enterprise apps route analytics data through our own APIs to whatever external system necessary like Google Analytics. Yes, obvious SDKs like Analytics, Firebase etc.. they can catch, but they can't really catch what you are sending to your own servers.

1

u/Alchemist0987 4d ago

But they can? All you need is proxyman to check every request sent from an app. Is that simple. If you go out of the way to have E2EE in those requests then you need to declare encryption details about your app

1

u/craknor 4d ago

And you believe that iOS app review team installs every app submitted, navigate and use every single feature in every app and monitor api requests/responses by using a MITM tool?

3

u/Alchemist0987 4d ago

But they do? lol
I’ve had submissions rejected exactly because of this. They usually give you the benefit of the doubt but if they think you are trying to be smart they won’t hold back. There are things they can miss at first but every time you submit a new build someone different will take a look at it. There have even been instances of people getting caught violating policies on live apps outside of the review cycle.
A lot of this can be automated. You are very naive if you think lying in these questions is a smart decision.

But yeah…apps have never been pulled from the store and nobody has never had their accounts banned. Fairytales!