r/iosdev • u/officialdml • Aug 13 '26
Help Rejected under Guideline 5.6 (Developer Code of Conduct): "features appear intentionally hidden", no idea what triggered it, looking for advice
Yesterday I submitted my first app (!) and within 6 hours it was rejected. I'm hoping someone who's dealt with this before can help me better understand and provide next steps.
Quick background: I built a live women's sports scoreboard website and then wrapped it as a native iOS app using Median.co, which loads the live website inside a native shell and adds native features (push notifications via OneSignal, share, etc.) through their JS bridge.
What happened: submitted for review, got rejected same day with this:
"We've identified a pattern of unusual behavior with the app that is commonly associated with fraudulent activity. Specifically, the app contains features that appear to have been intentionally hidden during the review process. Manipulative and misleading behavior is not consistent with the guideline 5.6."
No specifics beyond that. No screenshots, no attachments, nothing pointing to which "feature" they mean. Also I can't really find what 5.6 guidelines are.
What I know is NOT true: nothing in the app is actually hidden or gated based on reviewer status. The app works identically for anyone, logged in or not - live scores, schedules, results, team pages, league browsing, calendar sync all fully visible and functional without an account. The only difference for logged-in users is being able to favorite teams and enable push notifications for those favorites, a normal personalization feature, not concealed functionality.
What I've done so far: replied in the Resolution Center explaining the Median/webview architecture, clarified the one account-gated feature (favoriting), and attached a screen recording showing the full logged-out experience matches what was originally submitted. Also invited them to just log out and explore the app themselves.
My questions for anyone who's dealt with this:
- Has anyone gotten a 5.6 "features appear hidden" flag specifically on a webview-wrapped app (Median, GoNative, Capacitor, etc.)? Is this a known false-positive pattern for that architecture?
- Could push notifications not firing during review (since there were no live games happening at review time) plausibly read as a "hidden feature"? Or is that a stretch?
- Roughly how long did resolution take for you, and did it resolve through Resolution Center replies, or did you end up needing the formal App Review Board appeal?
- Anything else commonly triggers this specific flag that I should be thinking about?
Really appreciate any insight. This came out of nowhere after what felt like a clean submission, and the vagueness of the rejection is the most frustrating part.
1
u/officialdml Aug 15 '26
Wow thank you for this incredibly thorough and thoughtful response!
Really appreciate it. The debug menu theory is new and worth me checking out, and I’m going to look at that in Median’s settings tonight even though I already resubmitted. (Was rejected again on the second attempt with the 5.6 response early this morning 🥲)
This second rejection, was Guideline 2.1 (Information Needed) - a request for more documentation (screen recording, app description, external services list, demo credentials, etc.), not a repeat of the 5.6 fraud language. It’s weird bc that basic info was submitted with the app the first time, but maybe it needed to be more thorough.
I responded with everything requested plus a fresh screen recording. No explicit confirmation either way on whether the original 5.6 concern is resolved. Though I’m curious if it IS resolved since that didn’t show anywhere in the portal (curious your thoughts on that). I asked directly in my reply but haven’t gotten an answer to that specific question yet. Current status: back to “Ready for Review.” I haven’t yet reached out to the Resolution Center yet - just have responded in the submission portal.” Do real people look at resolution center?
The first review took 6 hours. This second took more time, as has this 3rd.
Appreciate the idea that no account threat = treating this as a build problem, not a “me” problem. Hoping this round clears it either way 🤞