My app got rejected because I do not use App Tracking Transparency to request the user's permission before collecting data used to track.
They also attached a screenshot which shows the problem occurs during login. The app uses Google Sign-In login process, which is managed by Google and connects to a Firebase backend.
Should I appeal or implement ATT even thought it is a third-party library?