What the rejection typically looks like
Guideline 5.1.1(v) - Data Collection and Storage
Issue Description
The app supports account creation but does not include an option to initiate account deletion. Apps that support account creation must also offer account deletion to give users more control of the data they've shared while using an app.
Next Steps
Update the app to support account deletion. Only offering to temporarily deactivate or disable an account is insufficient. If the app already supports account deletion, reply to App Review in App Store Connect and identify where to locate this feature.
Paraphrased example – the exact wording in your message may differ.
What Guideline 5.1.1(v) actually requires
Guideline 5.1.1(v) sits under 5.1 Privacy > 5.1.1 Data Collection and Storage > (v) Account Sign-In. The key sentence: "If your app supports account creation, you must also offer account deletion within the app" (App Store Review Guidelines, 5.1.1(v)). The requirement applies to new apps and updates submitted since June 30, 2022.
Apple's support page Offering account deletion in your app spells out what is expected:
- Easy to find, typically in the app's account settings.
- Real deletion of the entire account record and associated personal data. You may offer deactivation as an extra option, but offering only deactivation is insufficient.
- A direct link if people must finish on your website: straight to the page where they complete the deletion.
- Transparency: if deletion takes time, say how long and confirm when it is done. If you sell in-app purchases, explain how billing and cancellations are handled.
Cases developers often overlook
- Automatically created "guest" accounts need a deletion option for the account and its data too.
- Sign-up that links out to the browser still counts. Apple's FAQ says such apps must still offer deletion in the app, and adds that sending people to the default browser to register is a poor experience under Guideline 4.
- Region doesn't matter. A GDPR or CCPA process offered only in some countries is not enough. All users must be able to delete their accounts, although you can open your existing flow to everyone if it meets 5.1.1(v).
- User-generated content such as photos, videos, posts and reviews should be deleted with the account. If local laws require you to keep some data, tell users what you keep.
Common reasons apps get rejected under 5.1.1(v)
- No deletion option at all. Sign-up and logout exist, but deletion was planned "for later". Typical for a first MVP submission.
- Deactivate instead of delete. The button says "Deactivate" or "Pause", or it removes the profile but keeps the login and personal data on the server.
- "Contact support to delete your account." A mailto link, contact form or phone number. Apple says apps outside highly regulated industries should not require a phone call, an email or other support flows.
- The link goes to the wrong page. Your homepage, a help article with instructions or the privacy policy instead of the deletion page itself.
- Hard to find. Several levels deep, labeled vaguely, or only reachable through your Privacy Policy or Terms of Service. Apple's Human Interface Guidelines specifically say not to bury it there.
- Unnecessary hurdles. Identity checks and a confirmation step are allowed, but Apple says apps that make deletion unnecessarily difficult will not pass review. A mandatory exit survey or a chain of "Are you sure?" screens invites that verdict.
- Broken in the review build. A feature flag is off in production or the endpoint fails for the demo account. Reviewers may test the flow, so it has to work in the build you submit.
If your rejection also mentions forced logins or unnecessary personal data, see our Guideline 5.1.1 Data Collection and Storage guide.
Rejected or stuck? Talk to an App Specialist – for free.
Book a free consultation call: we look at your rejection or setup, explain the fastest way forward and tell you honestly whether you need us. Prefer to hand it off? Book our AI-powered + human-powered service and we take care of it.
How to fix a 5.1.1(v) rejection step by step
- Map what "the account" includes. User table, uploaded files, push tokens, CRM and newsletter tools, analytics with user IDs, payment provider records, third-party SDK backends. Decide for each whether you delete, anonymize or retain it for a legal reason.
- Add a visible entry point. The usual pattern is Profile or Settings > Account > Delete Account, styled as a destructive action (
Button(role: .destructive)in SwiftUI), visible on iPhone and iPad layouts. - Build one clear confirmation screen. State what will be deleted, what you must keep by law (for example tax-relevant invoices), how long it takes and what happens to subscriptions. Identity checks are allowed, such as a password, Face ID, a code sent to the email or phone already on the account, or a fresh Sign in with Apple prompt.
- Implement the backend deletion. An authenticated endpoint such as
DELETE /v1/medeletes or irreversibly anonymizes the account and its content and queues clean-up jobs for third-party systems. If your process is manual, record the request immediately and show the timeline. - Revoke Sign in with Apple tokens and handle subscriptions (both covered below).
- Clean up the device. Sign the user out, clear Keychain items and local data, return to onboarding, and notify the user once deletion is complete.
- If part of the flow is on the web, open the exact deletion page, ideally already signed in via a short-lived token. The HIG asks for a consistent experience, so the web flow shouldn't be longer or more complicated than an in-app one.
- Test the build you submit end to end against production. Add the exact path to the Notes under App Review Information in App Store Connect. If the reviewer deletes the demo account, it is gone, so list a spare account and re-create the sign-in account before every resubmission.
Sign in with Apple: revoking tokens with the REST API
Apple says apps that support Sign in with Apple should use the Sign in with Apple REST API to revoke user tokens when an account is deleted. Deleting your user row alone leaves the authorization in place.
- At sign-in, send the
authorizationCodefromASAuthorizationAppleIDCredentialto your server and exchange it athttps://appleid.apple.com/auth/token. Apple's docs say the code is single-use and valid for five minutes. Store the returnedrefresh_tokenon the server. - At deletion, call
POST https://appleid.apple.com/auth/revokeasapplication/x-www-form-urlencodedwithclient_id,client_secret,tokenandtoken_type_hint=refresh_token. - Check the response. HTTP 200 means the token was revoked or was already invalid. Log and retry errors instead of silently skipping revocation.
The client_secret is a JWT signed with your Sign in with Apple private key, and its expiry can be at most six months (15777000 seconds) ahead. Generate it on demand or rotate it, because an expired secret makes revocation fail. The client_id must match the identifier used at sign-in: usually the App ID (bundle ID) for native sign-in and the Services ID for web sign-in. Apple's TN3107 lists an unknown client_id and an invalid or expired client_secret as causes of invalid_client. Reference: Revoke tokens documentation.
If you never stored refresh tokens
Ask the user to sign in with Apple again inside the deletion flow, exchange the fresh authorizationCode on your server and revoke immediately. Firebase Authentication offers Auth.auth().revokeToken(withAuthorizationCode:), called before user.delete(). Widely used Flutter and React Native Sign in with Apple packages also return the authorization code, so the same approach works there.
Whether you must offer Sign in with Apple at all is a separate rule, covered in our Guideline 4.8 Login Services guide.
Subscriptions, legal retention and regulated industries
Active auto-renewable subscriptions
Deleting an account does not cancel a subscription billed by Apple. Apple asks you to tell users that billing continues through Apple and to ask them to cancel before they continue:
- Check the status with StoreKit 2 (
Transaction.currentEntitlements), App Store Server Notifications or the subscription status endpoint of the App Store Server API. - If a subscription is active, show the notice plus a Manage subscription button that calls
AppStore.showManageSubscriptions(in:)(iOS 15 and later) or openshttps://apps.apple.com/account/subscriptions. Refund requests can go throughbeginRefundRequest(iOS 15 and later). - You may offer to schedule deletion for when the subscription expires, but only alongside an option to delete immediately.
- Subscriptions billed through your own web checkout are not managed by Apple. Cancel those on your side as part of the deletion.
The HIG also notes that you must support account deletion even if the user didn't buy the subscription in your app. Cancellation and restore flows also matter for Guideline 3.1.2 Subscriptions.
Highly regulated industries
Apps in the fields named in Guideline 5.1.1(ix) may use additional customer service flows, such as a verification call, to confirm and facilitate deletion. The current list is banking and financial services, healthcare, gambling, legal cannabis use, air travel and crypto exchanges. Users must still be able to start the process in the app. If you rely on this exception, say so in your reply to App Review and provide supporting information. All other apps need self-service deletion without calls, emails or tickets.
B2B and MDM-deployed apps
Apple's guidance doesn't specifically address apps where only an employer or administrator creates accounts, so treat this as a gray zone. Apple's rejection message invites you to reply with information or documentation if the app can't offer deletion "for some other reason". Explain who creates accounts and how deletion works. If App Review still insists, an in-app deletion request routed to the organization's admin is a pragmatic solution.
Deletion patterns: what passes and what gets rejected
This is our reading of Apple's support page and the Human Interface Guidelines. App Review makes the final call on each submission.
| Pattern | Likely outcome |
|---|---|
| Settings > Account > Delete Account, one confirmation screen | Matches the pattern Apple describes |
| Button opens the deletion page on your website directly | Allowed: Apple accepts a direct link to the page where deletion is completed |
| Request recorded at once, final purge after a stated period, confirmation afterwards | Allowed if users are told the timeline and get a confirmation |
| Scheduled deletion at subscription expiry plus a "delete now" option | Allowed per Apple's FAQ |
| Only "Deactivate account" or "Log out" | Rejected: deactivation alone is insufficient |
| "Email [email protected] to delete your data" (non-regulated app) | Rejected: no support flows outside regulated industries |
| Link to a help article or the privacy policy | Not compliant: the link must lead directly to the deletion page |
| Mandatory survey before the delete button works | High risk of being judged "unnecessarily difficult" |
How to respond to App Review
- The option was missing or non-compliant: fix it, upload a new build, select it for the version and resubmit. Then reply to the App Review message in App Store Connect with the exact path. A short screen recording of the flow removes doubt.
- The reviewer missed an existing option: Apple's rejection text asks you to reply in App Store Connect and identify where the feature is, so usually no new build is needed. Include the path, a screenshot and a working demo account, then make the option more prominent in your next update.
- You believe the rule doesn't apply, for example because accounts can't be created in or through the app: explain it in your reply with supporting information. If that doesn't resolve it, you can appeal to the App Review Board via the appeal form.
Cover the four points Apple's guidance focuses on: where the option is, that it deletes rather than deactivates, how Sign in with Apple tokens are revoked and how subscribers are informed. The template below follows that structure.
How to prevent 5.1.1(v) rejections in future releases
- Automate the flow in CI. An XCUITest that signs up a throwaway account, deletes it and asserts that signing in fails catches regressions before every release.
- Monitor token revocation. Log every
auth/revokeresponse and alert on errors such asinvalid_client, which often points to an expired client secret. - Treat new login methods as a trigger. Adding Sign in with Apple, passkeys or automatic guest accounts changes what "the account" means. Re-check deletion each time.
- Keep review notes in your release checklist: path to Delete Account, working demo credentials, spare account.
- Ship the same flow on Android. Google Play has its own rule, including a web deletion link declared in Play Console. See our Google Play account deletion guide.
If you want a second pair of eyes before resubmitting, appsubmitter.io combines AI-assisted pre-submission checks with human review of flows like this, alongside CI/CD setup and submission handling. Book a free consultation call to walk through your deletion flow and review notes.
Template: how to reply to App Review
Adapt this template to your situation. Keep it factual, short and specific – and only claim what you have actually changed.
Checklist before you resubmit
- A clearly labeled Delete Account option is reachable from account or profile settings in a few taps on iPhone and iPad.
- Confirming deletes the account record and associated personal data, including user-generated content, rather than deactivating it.
- No email, phone call or support ticket is required (unless your app is in a 5.1.1(ix) regulated industry, and even then users start the process in the app).
- Any web step opens the exact deletion page, not your homepage, a help article or the privacy policy.
- The confirmation screen states what is deleted, what is retained for legal reasons and how long deletion takes, and users are notified when it is complete.
- For Sign in with Apple accounts, your server calls auth/revoke with a valid, unexpired client secret and receives HTTP 200.
- Users with an active auto-renewable subscription see the billing notice and a manage-subscriptions option first.
- Automatically created guest accounts with server-side data can be deleted too.
- The flow works end to end on the exact build you submit.
- The App Review notes contain the deletion path, a working sign-in account and a spare demo account.
Frequently asked questions
Does account deletion have to happen immediately to pass App Review?
Can I just link to my website for account deletion?
Is deactivating an account enough for Guideline 5.1.1(v)?
Can I ask users to email support to delete their account?
Do I need account deletion if users can only log in and accounts are created elsewhere?
Do I need to revoke Sign in with Apple tokens when an account is deleted?
https://appleid.apple.com/auth/revoke with the stored refresh token, or reauthenticate the user to get a fresh authorization code if you never stored one.What happens to a user's App Store subscription when they delete their account?
Official source: App Store Review Guidelines – 5.1.1(v) Account Sign-In. Store policies change regularly – always check the current version. This guide is independent advice and not affiliated with Apple or Google.