Key takeaways
- A 5.6 flag on a Google AI Studio app usually means the reviewer could not see or use something – a failed Gemini call, a blocked Google sign-in or a feature that appeared after a redeploy.
- Shared AI Studio apps bill Gemini calls to the creator's limits, and rate limits apply per project – review traffic can hit a 429 error and make AI features look switched off.
- Every prompt sent to Gemini shares user content with a third party: Guideline 5.1.2(i) requires clear disclosure and explicit permission before the first request.
- Treat Deploy as a release: no new features while a build is in review, AI credits through In-App Purchase and listing claims the model actually delivers.
- WebViewGold, made by our team, puts native modules around your AI Studio web app – Sign in with Apple, push, an offline screen, StoreKit – but quotas, consent and claims stay your job.
Our recommended solution
Rebuild your wrapper with WebViewGold – a real app, not just a website in a frame
WebViewGold turns your website into native iOS and Android apps with push notifications, a native offline screen, deep links, a QR scanner and more – the building blocks App Store reviewers look for. Built by our own team, and we submit WebViewGold apps all the time.
What the rejection typically looks like
Guideline 5.6 - Developer Code of Conduct
We've identified a pattern of unusual behavior with the app that is commonly associated with fraudulent activity. Specifically, the app contains features that appear to have been intentionally hidden during the review process.
Paraphrased example – the exact wording in your message may differ.
Google AI Studio app rejected under Guideline 5.6: what Apple is telling you
A Google AI Studio app rejected under Guideline 5.6 has usually not hidden anything on purpose. App Review ran into behavior it couldn't verify – an AI feature that returned nothing, a sign-in it couldn't finish, a paywall that differed from the listing – and judged the pattern. Fix the cause, make every AI feature testable and reply with specifics.
Developers who received 5.6 rejections in 2026 report wording about "a pattern of unusual behavior" that is "commonly associated with fraudulent activity" and "features that appear to have been intentionally hidden during the review process" – usually without naming a screen. Apple rejected more than 22,000 submissions for hidden or undocumented features in 2025 and says machine learning helps it "flag potentially problematic changes in app updates" (Apple Newsroom, May 20, 2026).
No guideline forbids apps made with AI tools: our overview of 5.6 rejections for AI-built apps explains the background, and the WebView 5.6 article covers the general diagnosis. This article is about what only Google AI Studio brings to the table: server-side Gemini calls, Firebase sign-in, quick redeploys to Cloud Run and model output that never looks the same twice.
Seven Google AI Studio defaults that look like concealment in review
Build mode generates a React front end and a Node.js server that calls Gemini with your key, provisions Firestore and Firebase Authentication with "Sign in with Google" and deploys to Cloud Run (Google AI Studio docs). For a web prototype, these are sensible defaults. In an iOS app under review, each one can create a moment where the reviewer sees less than your users do:
| AI Studio default | What the reviewer runs into | Why it reads as 5.6 |
|---|---|---|
| Gemini calls of a shared app count toward the creator's usage limits | The generate button spins and fails, or returns an empty card | The headline feature seems to be switched off for review |
| Firebase Authentication with "Sign in with Google" | Google refuses the login inside the WebView with a disallowed_useragent error | Everything behind the login stays out of sight |
| Every redeploy pushes a new Cloud Run revision | The reviewer tests one version while users already get another | The app changed after review without a new build |
| Stripe keys stored as server-side secrets | A web checkout for AI credits – or no paywall at all because it is switched off in the app | Digital sales outside In-App Purchase, or a paywall reviewers never saw |
| Remixing a project from the App Gallery | Screens and flows that match other submissions | Apple analyzes app similarity; lookalikes add to the pattern |
| Model output that varies | Weaker results than the screenshots and description promise | 5.6 forbids charging for "features or content that are not delivered" |
| Cloud Run scales to zero | A blank or slow first screen after a quiet period | Mostly a 2.1 issue, but it adds to the impression of withheld content |
Rejected or stuck? Talk to an App Specialist – for free.
Book a free consultation call: we look at your rejection or setup, explain the fastest way forward and tell you honestly whether you need us. Prefer to hand it off? Book our AI-powered + human-powered service and we take care of it.
Gemini quotas: how review traffic can switch your AI features off
This trigger is unique to apps built on the Gemini API. Rate limits count requests per minute, tokens per minute and requests per day; they "are applied per project, not per API key", daily quotas reset at midnight Pacific time, and specified limits "are not guaranteed" (Gemini API docs). Past the limit, requests fail with 429 RESOURCE_EXHAUSTED.
AI Studio's documentation adds: "When you share your app, API calls count toward your usage limits." Depending on how you set up your keys, Build mode sessions, TestFlight testers, web visitors and the reviewer may all draw on one project. If the quota runs out before the reviewer opens the app, generated code may fail silently – an endless spinner, an empty card, a vanished button – and that looks like a feature kept from review.
- Run production on a paid tier. Linking an active billing account moves the project from the Free tier to Tier 1 – and changes how Google treats your users' prompts (see step 4 of the fix).
- Keep experiments elsewhere. A separate project for prompting means a long Build mode session can't drain the live app's quota. Check AI Studio's rate limit view before you submit and during review.
- Fail out loud. On a 429 or a timeout, show a plain message with a retry button. Never hide the AI entry point because a call failed.
- Don't stage a performance. Canned answers for the reviewer are what 5.6 punishes. Guideline 2.1 allows a built-in demo mode only "with prior approval by Apple", and it must exhibit the app's full features.
If users pay per request, put the credit back automatically when Gemini fails. Otherwise the app has charged for something it didn't deliver – a practice the customer-trust paragraph of 5.6 names explicitly.
Where to look: AI Studio, Cloud Run, Firebase and App Store Connect
In Google AI Studio
- The rate limits of your production project around the review date.
- Generated front-end code that hides components when a request fails, when nobody is signed in or when the user agent shows your app's marker. Build mode wrote this code for you, so read it at least once.
- Your GitHub sync history: every commit pushed between submission and rejection is a suspect.
In Google Cloud and Firebase
- The Cloud Run revision that served traffic during review, logs with 429 responses or server errors, and a minimum instances setting of zero.
- The sign-in providers enabled in Firebase Authentication – Google alone gives the reviewer no working way in – and a demo account that signs in with a password and owns realistic Firestore data.
In App Store Connect
- AI claims in the description, subtitle and screenshots compared with what an ordinary prompt produces.
- Notes for Review with steps and a sample prompt per AI feature, and App Privacy answers that cover what goes to Gemini.
How to fix a 5.6 rejection of an AI Studio app, step by step
- Stabilize the AI backend: paid tier, a separate production project, visible errors with retry and credits returned on failure.
- Let the reviewer in. Enable email and password sign-in in Firebase Authentication and create a demo account with realistic data. Google login can't stay in the WebView: Google's OAuth policy says a developer "must not direct a Google OAuth 2.0 authorization request to an embedded user-agent under the developer's control", and a changed user agent doesn't make it compliant. The clean fix is native Google sign-in – the Google Sign-In SDK or
ASWebAuthenticationSession, handed to Firebase Authentication – which is custom code in your Xcode project. The simpler fix: offer email and Sign in with Apple in the app and keep Google for the web. Sending the login to Safari satisfies Google, but Apple says linking out to the default browser to sign in "provides a poor user experience and isn't appropriate" under Guideline 4. If Google stays for primary accounts, 4.8 requires an equivalent option such as Sign in with Apple – see Guideline 4.8 for WebView apps. - Ask before the first prompt. Guideline 5.1.2(i) requires you to "clearly disclose where personal data will be shared with third parties, including with third-party AI, and obtain explicit permission before doing so". One screen that names Google's Gemini API, lists what is sent (text, photos, voice) and why, links your privacy policy and records the choice does the job – details in our Guideline 5.1.2 guide.
- Match the disclosure to your Gemini tier. Under the Gemini API terms, content sent through unpaid services, Google AI Studio included, is used to improve Google products and may be read by human reviewers; Google advises against submitting personal information there. Apps offered in the EEA, Switzerland or the UK may only use paid services. Real users belong on a paid tier.
- Sell AI credits through In-App Purchase. Generations and premium models are digital, so Guideline 3.1.1 applies, and credits bought this way "may not expire". Keep Stripe for physical goods and services, and show the reviewer the same paywall users get – see 3.1.1 for WebView apps.
- Rewrite the claims. Guideline 2.3.1(a) names "promoting content or services that it does not actually offer" as grounds for removal, so cut generated buzzwords like "accurate" or "expert-level" and describe what an ordinary prompt produces. Keep Gemini's name and logo out of your app name and icon: Guideline 4.1 bars other developers' brands there without approval.
- Moderate shared output. If users publish generations or meet in multiplayer sessions, Guideline 1.2 requires filtering, reporting, blocking and published contact information – see the user-generated content guide.
- Ship a new build and describe every AI feature in the Notes for Review: where it is, a sample prompt and the kind of result to expect.
The fastest fix for most WebView rejections
WebViewGold: native features for your web app
Instead of building native features from scratch, start from WebViewGold. You get ready-made Xcode and Android Studio projects for your website, with native modules you switch on in the configuration:
- Push notificationsOneSignal or Firebase, for real, personal events
- Native offline screenNo browser error pages when the connection drops
- Native splash screenApp-like start instead of a loading web page
- Deep linksLinks open the right screen inside the app
- QR & barcode scannerDevice features the website alone can't offer
- In-app purchasesNative purchase flows where the store requires them
No tool guarantees an approval: Apple still judges what your app offers. Use the native features in your main user journey – our App Specialists review your WebViewGold app before it goes to the App Store.
Deploy is a release: change control after approval
Build mode makes changes cheap – describe them, or point at an element in annotation mode, and the next deploy ships them. That speed is what makes an approved AI Studio app drift away from the reviewed one. Decide per change:
| Change | Deploy only? | Why |
|---|---|---|
| Copy, styling, bug fixes, clearer error messages | Yes | Same app, same features |
| Tuned system instructions or a newer Gemini model behind an existing feature | Usually – rerun the sample prompts from your review notes first | The output must still match your listing |
| A new AI capability such as image generation, voice input or camera analysis | No – new build | Microphone and camera access need purpose strings in the binary, plus new consent and App Privacy answers |
| Credit packs, subscriptions or a new paywall | No – new build | In-App Purchase needs native code and products Apple reviews |
| Multiplayer or public sharing of generations | No – new build | Brings user-generated content rules and new review notes |
| Unpublishing the app or switching its subdomain | Never while the iOS app is live | Google releases an unpublished app's subdomain for anyone to claim |
Tag the commit you submitted in the GitHub repository AI Studio syncs with, so you can always show what the reviewer saw, and pause feature deploys while a build is in review.
Wrapping the AI Studio app so the reviewer meets a native app
Most Google AI Studio apps reach the App Store as their deployed web app inside a native iOS shell. WebViewGold, the website-to-app solution built by our own team, is a ready-made Xcode project: you enter your Cloud Run URL in Config.swift and switch on native modules. Several of them answer the triggers in this article:
- Sign-in: Sign in with Apple pages (
appleid.apple.com) are detected and handled automatically. Because you own the Xcode project, native Google sign-in can be added there as custom code. WebViewGold'sgooglelogin://prefix can hand a Google login URL to the external browser, which satisfies Google – but given Apple's stance on browser sign-in, treat it as a fallback. - Cold starts and dead zones: a native offline fallback screen instead of a blank view.
- AI credits: StoreKit In-App Purchases and subscriptions (Extended license).
- Vision features: the VisionKit document scanner and the QR and barcode scanner feed clean input to your prompts.
- Long-running generations: push notifications via OneSignal, Firebase or Pushwoosh announce finished results.
- Ratings: Apple's native rating dialog replaces any generated "rate us" modal – 5.6.1 disallows custom review prompts.
- Layout: a custom user agent lets your React code recognize the app and drop web-only elements – for presentation only, never to switch features.
WebViewGold is a one-time purchase, you publish in your own developer account, and the separately sold Cloud Builder builds the app in your browser if you have no Mac. In our usual setup, WebViewGold supplies the native app and appsubmitter.io handles the submission. No tool can promise an approval, though. The full setup is in our guide to converting a Google AI Studio app to iOS, and the Android guide covers Google Play.
Answering App Review – and the shortcuts that make it worse
Reply in App Store Connect once the new build is uploaded: what you found, what you changed, the demo account, sample prompts and a short screen recording. Mention that model output varies, and if the letter names no screen, ask politely which flow raised the concern. A 30-minute App Review appointment via Meet with Apple helps when you can't find the trigger; an appeal only makes sense if Apple misunderstood the app, and Apple accepts one per rejected submission.
Avoid the moves that turn a fixable rejection into an account problem:
- A second developer account, or the same build resubmitted unchanged.
- Detecting the reviewer – by IP range, user agent or account – to serve different features or canned AI answers.
- Deleting the app to resubmit it under a new name, or unpublishing the AI Studio app to start fresh.
- Promising Apple features that the next deploy will add.
appsubmitter.io takes this part off your plate: AI-powered pre-submission checks plus an App Specialist who tests the AI features the way a reviewer does, writes the review notes and answers App Review – always in your own developer account, where our specialists work as members of your team. Code changes aren't included, but we quote them upfront. Book the iOS service or start with a free consultation call.
Template: how to reply to App Review
Adapt this template to your situation. Keep it factual, short and specific – and only claim what you have actually changed.
Checklist before you resubmit
- Production Gemini calls run on a paid tier in their own project, not on the free quota you use for building.
- A 429 or failed Gemini request shows a message with a retry option, and spent credits are returned.
- The reviewer can sign in with a password-based demo account that has realistic data.
- Google login never loads inside the WebView (no modified user agent), and Sign in with Apple or another 4.8-compliant login sits next to it.
- A consent screen names Google's Gemini API, says what is sent and asks for permission before the first request.
- AI credits and subscriptions use In-App Purchase, and reviewer and users see the same paywall.
- Description, subtitle, icon and screenshots promise only what the model reliably delivers, without Gemini branding.
- No feature deploys while the build is in review; the submitted commit is tagged in GitHub.
- Notes for Review list every AI feature with its location, a sample prompt and the expected kind of result.
Frequently asked questions
Why was my Google AI Studio app rejected under Guideline 5.6?
Does Apple reject apps because they were built with Google AI Studio?
Do I have to tell users that my app sends data to Gemini?
My AI features worked in testing. Why did the reviewer see errors?
429 RESOURCE_EXHAUSTED error. Run production on a paid tier in its own project and show a retry message when a call fails.Can WebViewGold fix a 5.6 rejection of my AI Studio app?
Should I create a new developer account after a 5.6 rejection?
Recommended solution
From WebView rejection to approval: WebViewGold + appsubmitter.io
- 1 Build with WebViewGold Turn your website into native iOS and Android projects.
- 2 Add native value Push, offline screen, deep links or scanning in your main flow.
- 3 We submit it Our App Specialists submit and talk to the review team.
WebViewGold is made by our team (jocapps GmbH). It is a tool, not a guarantee – approval decisions are made by Apple and Google.
Sources and further reading
- Apple – App Store Review Guidelines, 5.6 Developer Code of Conduct
- Apple – App Store Review Guidelines, 5.1.2 Data Use and Sharing
- Google AI – Build apps in Google AI Studio (Build mode)
- Google AI – Gemini API rate limits
- Google AI – Gemini API Additional Terms of Service
- Google for Developers – OAuth 2.0 policies: use secure browsers
- Apple Developer – Offering account deletion in your app
- Apple Newsroom – App Store fraud prevention in 2025 (May 20, 2026)
Store policies and third-party products change regularly – always check the current versions. This article is independent advice and not affiliated with or endorsed by Apple, Google or any other company or product mentioned; all trademarks belong to their owners. WebViewGold and appsubmitter.io are made by our team at jocapps GmbH.