Hi Apple Developer Community,
I’m preparing an iOS app called Titech for App Review. The app is intended for clinic/business users and provides preliminary AI-generated cosmetic analysis and preview guidance based on user-submitted face photos. The app is not intended to provide medical advice, diagnosis, or treatment decisions, and users are told to consult qualified experts before acting on any recommendation.
We have received multiple App Review rejections and I would appreciate guidance on whether our current approach is aligned with Apple’s expectations.
Current issues raised by App Review:
Guideline 2.1 - Information Needed
Apple asked for more information about how the app uses face data, including:
What face data is collected
How it is used, stored, retained, deleted, and shared
Whether it is shared with third parties
Where this is explained in the privacy policy
Exact privacy policy text about face data
We updated the app and privacy policy to explain that:
Users voluntarily upload front, left-side, and right-side face photos
Photos may be sent to our backend and processed by OpenAI through the OpenAI API
Face ID/fingerprint data is not collected
Uploaded face photos and generated preview images are deleted after the active session ends
The app does not sell face data or share it with advertisers/data brokers
Guideline 2.1(b) - Information Needed
Apple asked about the business model and whether users access paid content. Our app does not currently include paid digital content, subscriptions, credits, or in-app purchases. Access is controlled by a registration code for clinic/business users and App Review only.
Guideline 2.3.3 - Accurate Metadata
Apple said the screenshots did not show the current version of the app in use. We replaced the screenshots with updated iPhone and iPad screenshots showing:
Clinic access
Consent and face-data disclosure
Photo capture
AI-generated analysis
Recommendations
Side effects page
Generated preview flow
My questions:
For apps using user-submitted face photos with a third-party AI API, is it enough to clearly disclose OpenAI processing in the consent screen and privacy policy, or should this also be repeated elsewhere in the app flow?
For face photos that are deleted after the active session ends, what wording does Apple generally expect around retention and deletion?
Since the app is clinic/business access only and does not sell digital content, is a registration code acceptable if we clearly explain that it is not a paid digital unlock?
Are there any additional App Review notes or privacy policy sections that developers usually include for apps involving face photos and AI-generated preliminary recommendations?
For metadata, should the screenshots avoid login/consent screens entirely, or is it acceptable to include them as long as most screenshots show core app functionality?
Any advice from developers who have passed review with apps involving user-uploaded face photos, AI analysis, or cosmetic/health-adjacent recommendations would be very helpful.
Thank you.
Topic:
App & System Services
SubTopic:
Health & Fitness
Tags:
App Review
Privacy
Photos and Imaging
StoreKit
0
0
23