Violation on Guideline 5.1.2 - Legal - Privacy - Data Use and Sharing

Our app has a feature that sends notifications to the user's friends. This app has been declined several times and we are still seeking a solution to publish this app with the sending notification feature.

Guideline 5.1.2 - Legal - Privacy - Data Use and Sharing

The app appears to spam, phish, or send otherwise unsolicited messages to users or a user’s contacts. Specifically, the app allows the sending of mass text or notification.

Spamming users or a user’s contacts in this manner is not appropriate. The app should not mine, trace, harvest, or otherwise maliciously exploit users’ data or other user information to promote your service.

Next Steps

To resolve this issue, please remove this feature from the app.

Our app specification:

  1. A user can send the notifications to at most 10 friends at the same time
  2. There is an hour limitation to send notifications as an anti-spam measure. There is also a day limitation.
  3. UserA can search UserB by its userId, add UserB as an friend and sends the notification without UserB permittion.
  4. User can block a friend as an anti-spam measure.

What else should we do as an anti-spam measure, or are we missing some important facts?

Best Regards,

Additional info: 5. A user cannot know a friend's info other than the user ID, username, and icon.

If you disagree with the outcome of our review, you may consider submitting an appeal to the App Review Board.When filing your appeal, make sure to:

  • Provide specific reasons why you believe your app complies with the App Store Review Guidelines.
  • Submit only one appeal per rejection.
  • Respond to any requests for additional information before submitting an appeal.

The App Review Board will contact you directly as soon as they've completed their investigation.

You cannot send notifications or emails to the user's contacts unless those contacts are created and managed on your server. Accessing or using a user's private iPhone contact list is a privacy breach. The contact list is owned by the user and should remain private and secure. Ensure that any interactions with contacts are conducted in accordance with these privacy guidelines.

If an iOS app tried to send email or notification to one of my contacts in my iPhone I would be extremely ****** off.

If those contacts are managed on the server, send the notifications through the server rather than the app to maintain privacy and security.

Violation on Guideline 5.1.2 - Legal - Privacy - Data Use and Sharing
 
 
Q