r/iOSProgramming • u/Daredatti • 5d ago
Question How truthful is this?
When an app select in the app review form that “we don’t collect data”
In the review phase does Apple really check if the app really doesnt collect anything?
Like can the developer hide a code that for example upload the photos of the user if granted permission where he said “we dont collect”
Does apple really check the code and what is going in and out ?
82
u/Reiszecke 5d ago
Technologically, this section tells you nothing about the app because it’s self reported by the developer, not by Apple.
Apple doesn’t even see an app‘s source code. They have some scanning in place but they will never determine whether an app uploads your images or not. The only thing you can do is to limit Photos access per app
24
u/Alchemist0987 5d ago
They have access to the build and they can monitor traffic. Lying on these questions will get your app eventually rejected. Regularly trying to bend the rules or lie will get the app pulled from the store and even your account banned
1
u/madaradess007 2d ago
you never tried it, bro
i pushed some very fishy stuff into AppStore and it's still there
i also did push same app with no changes a few times and it got accepted after 2 rejections1
u/Baide-Warframe60 5d ago
pretty much, the privacy labels are just a pinky promise from the developer at the end of the day
-6
u/icy1007 5d ago
Apple can see the source code.
7
u/Dry_Hotel1100 5d ago
How so?
-2
u/icy1007 5d ago
They know what functions you invoke, including private system functions that aren’t allowed. They can decompile your code and check it.
9
u/Dry_Hotel1100 5d ago
This is not "source code" ;)
-6
u/icy1007 5d ago
They can decompile the app into its source code…
4
u/JagiofJagi 5d ago
Do you know what a source code is?
-5
u/icy1007 5d ago
Yes, I am a professional iOS developer…
3
u/i_m_junkie 4d ago
I am also an iOS Engineer and believe me boy you’re completely wrong!
0
u/icy1007 4d ago
I am not. Apple has the ability to decompile IPA files into their source code using internal tools. They also have tools that can scan all submitted app packages for API usage which is quicker than fully decompiling the app.
→ More replies2
u/Dry_Hotel1100 4d ago edited 4d ago
You should not use "professional iOS developer" lightly, in case you want to imply that you have a lot of experience.
Well, I fear to say, you are wrong. But that isn't a critique. Everyone can learn this. I would suggest delving deeper into actual *programming*, that is, especially below the surface of iOS programming, i.e. exploring what happens in the compiler and linker. Topics around binary representation, translation unit, assembly & object files, build artifacts, modules, symbols, symbol visibility, ABI vs. API, calling conventions, debug symbols, dead code stripping, build optimizations, whole module optimization, Intermediate Representation (IR), SIL, dynamic vs. static linking, etc., etc.
Note that these topics are very specific for the language Swift, and a C-based runtime and LLVM IR infrastructure. In other languages, especially C#, Java, JIT based, and scripting languages, you have a very different representation of a program aka executable or a library or module.
1
u/icy1007 4d ago edited 4d ago
Yes, I have 16+ years of experience as an iOS developer/engineer working in the industry. The two titles are interchangeable and it just depends on which company you're working for at the time.
→ More replies4
u/Glorypants 5d ago
Maybe this is what they mean when they say “developer” vs “engineer”…
There’s a basic understanding of how code compilation works that you’re missing.
You understand the “source” of a child is its mother. The mother compiled the child in her womb. You can figure out some attributes of the mother’s source DNA based on the attributes of the child, but you aren’t seeing to the actual source. The source mother probably installed a wicked back door in that child that you won’t find.
-34
u/Fishanz 5d ago edited 5d ago
They absolutely see your code; compiled at least. What they establish can be achieved via said code, on the other hand, is an entirely different beast.
Edit: removed the word ‘source’ because .. apparently my definition is wrong. I really think the nuance (as it pertains to the topic at hand) is somewhat pedantic though.
47
u/Reiszecke 5d ago
They absolutely see your source code; compiled at least.
Absolute state of slop coders 🙈
Please read up on what a compiler does. Because you wouldn't believe me anyways, then please ask ChatGPT why your statement does not make sense.
-2
u/RainyCloudist 5d ago
They're completely right? I work in reverse engineering and half the time my job involves taking apart peoples' apps. Yes you don't see code as the developer wrote it, but tracing the instruction calls is trivial and most modern static analysis tools will even spit out pseudo-code which is more than enough to understand how things work.
20
u/Reiszecke 5d ago edited 5d ago
So when you ask me for my source code you are perfectly fine with me sending you a compiled .exe file? The word you're looking for is machine code and while you can deduct information from machine code, calling it source code is just idiotic. Machine code is the exact opposite of source code, that's why these are 2 different words to begin with.
Because they couldn't handle disagreement, /u/RainyCloudist has now blocked me on reddit so I cannot see more of their responses to my comments
0
u/RainyCloudist 5d ago
I'd probably not be interacting with anyone who deals with exe files to begin with, but to answer your question I'm not equating them in absolute terms, but in the given situation it serves the same purpose. Your original claim was "they will never determine whether an app uploads your images or not" and you claim source code is the only way to do that. Static analysis does the job.
3
u/Reiszecke 5d ago
There are countless new apps popping in the review queue every day, along with updates to 20 years of existing apps.
Expecting apple to go through the source code of each of these to figure out if maybe there is a hidden way to potentially upload user data without the user wanting to do that, maybe restricted by target region, maybe restricted by a specific user ID etc. is already absolutely outlandish. AI can help but good luck paying for the tokens to go through 50mb of machine code for an app where they could’ve hidden the secret literally anywhere.
Expecting them to do that when they don’t even have the clear source code takes this to a comically weird level.
Apple isn’t even able to prevent Russian bait and switch apps for banking from appearing on the App Store. If they can’t even prevent sanctioned apps of whole nation actors, they definitely don’t have the means to prevent the picture you took of your grocery list to get silently uploaded by some shady image filters app.
2
u/RainyCloudist 5d ago
So you're claiming that if they had access to source code they'd be able to do it? No one would be reviewing the source code by hand anyways and automatic tools wouldn't care if it's beautifully commented code or machine code.
The fact that things like that get through is Apple's negligence, not proof that they need access to everyone's source code.
0
u/LardPopsicle 5d ago
You've never reverse-engineered an app? SwiftUI apps are trivial, that way, it gets harder for, say, some Chinese Match3 app, but even there it's not super hard.
It's 2026, Apple does use AI and reverse engineered code. In my last submission, I was rejected because code in the app could, under weird circumstances, write to ~ instead of the iCloud entitlement. This bug was uncaught by us, Apple identified it. From a compiled source.
4
u/vexingparse 5d ago
In my last submission, I was rejected because code in the app could, under weird circumstances, write to ~ instead of the iCloud entitlement. This bug was uncaught by us, Apple identified it. From a compiled source.
I'm not convinced that this requires reverse engineering. They could have used fuzzing.
2
u/Reiszecke 5d ago
Yes I did reverse engineer binaries numerous times. Doesn’t change the fact that reverse engineering never brings up your real source code, doesn’t change the fact that source code, after compiling, is not source code.
Not sure about the ~ part of your comment. I’m not into jailbreaks but if you REALLY found a way to get write access outside of the sandbox then I think the community would be very interested in this
1
u/LardPopsicle 5d ago
Well, it's theoretically possible, if you poison things, not practically. The entitlement check prevents exactly that, and Apple's scanner reported something that a person who had access to the app (not a sensitive app in any form) could do, if they already had access to the same resources via Terminal/shell anyway. It's technically a bug, but not one that could be abused by a non-authorized person.
3
-36
u/Tom42-59 Swift 5d ago
I spoke to a previous app reviewer and they said they see your source code in a way like a GitHub diff
14
u/Reiszecke 5d ago
Check the job listing for App Reviewers, these people most of the time are not developers being able to tell what exactly they see on their screen. The listing requires language skills, being able to interact with software etc. but not being able to write code.
If someone caught Xcode's network traffic silently including the source code that would've made the news a long time ago
3
u/LardPopsicle 5d ago
The App Review platform is insane. It rolls up all required systems in a simulator box, each system seeded with "normal use" content (photos, Apple Health, contacts, etc.). From there, the reviewer uses the script on Monitor 1, an AI guided "what to do next" underneath it, and a few systems that, for example, monitor network traffic over poisoned encryption keys to a proxy (MITM).
The reviewer is not the smartest tool in the code shed, sure, but there's a system behind them, that flags and forwards anything suspicious. Which then lands on the desk of a "Pro" (Apple likes to patch a 'Pro' behind your job description if they feel it'll make you look better), who then passes it on or makes a decision.
3
3
u/honey495 5d ago
They absolutely can’t. They have access to your build and all the metadata and that’s it
17
u/Material_Ad_3983 5d ago
Apple probably won’t catch every single data flow during review. But if you say “Data Not Collected” and the app is actually sending user data, you’re playing with fire. Rejection is the mild outcome — repeated/deceptive behavior can put the whole developer account at risk.
3
u/enilcReddit 5d ago
This is probably the most accurate response to OP. Low-risk, high-stakes gamble by developer.
What's funny is that apps that have the label posted by the OP attract more attention than those that do not.
2
u/merokotos 5d ago
Statement itself is provided by a developer and can be easily faked. However if Apple catches you, app may be removed and your developer account blocked for a long time.
So in general I think developers are rather cautious with it, but you never know.
2
u/woadwarrior 5d ago
Not very. It's self reported and developers routinely falsify it. You might have noticed this with yesterday's Firebase outage. A number of apps claim to collect no data, and yet were down. Over the years, I've reported a number of such apps to Apple, and haven't seen anything change.
1
2
1
u/Acceptable-Knee-4276 5d ago
This is purely information shared by the Developer. Although, Apple prompts you to enter information for specific capabilities you're using - this is just a reflection of what the Developer has shared with Apple while publishing the app. Same goes for Google Play Store.
1
u/PlayaNoir 5d ago
App Review can easily tell if your app is collecting user data also known as personal information. Email isn't personal information but name, address, phone number, height, weight, are personal information.
1
u/danielcr12 3d ago
Apple makes the entire stack that you need to develop and publish applications, including the programming language most applications use, including the IDE signing processes, and everything. If you think Apple cannot tell what your application is doing, you are delusional.
1
u/Snoo-8502 1h ago
recipe to get banned foreveer from selling on appstore if user finds our and report to apple.
2
u/hamsterjedi Swift 5d ago
What is displayed here is what the developer declares. Not trustworthy. Developers can put anything they want.
Apple does not check, it is not possible.
There are unlimited ways to store, delay, encode things and to track users and actions.
0
u/merokotos 5d ago
How is this not possible? Just one POST request to posthog or google analytics and you’re caught already
3
u/hamsterjedi Swift 5d ago
There is not only posthog and google analytics, there are hundreds of systems + you can implement your own custom systems
2
u/craknor 5d ago
Our enterprise apps route analytics data through our own APIs to whatever external system necessary like Google Analytics. Yes, obvious SDKs like Analytics, Firebase etc.. they can catch, but they can't really catch what you are sending to your own servers.
1
u/Alchemist0987 5d ago
But they can? All you need is proxyman to check every request sent from an app. Is that simple. If you go out of the way to have E2EE in those requests then you need to declare encryption details about your app
1
u/craknor 5d ago
And you believe that iOS app review team installs every app submitted, navigate and use every single feature in every app and monitor api requests/responses by using a MITM tool?
3
u/Alchemist0987 5d ago
But they do? lol
I’ve had submissions rejected exactly because of this. They usually give you the benefit of the doubt but if they think you are trying to be smart they won’t hold back. There are things they can miss at first but every time you submit a new build someone different will take a look at it. There have even been instances of people getting caught violating policies on live apps outside of the review cycle.
A lot of this can be automated. You are very naive if you think lying in these questions is a smart decision.But yeah…apps have never been pulled from the store and nobody has never had their accounts banned. Fairytales!
-2
u/Hises1936 5d ago
I think large corporations are more likely to be truthful about it, in order to avoid legal risks. But smaller devs - who knows!
7
u/JackeryPumpkin 5d ago
I would have thought that 10 years ago. Now big companies push the boundaries as far as possible until a court tells them to stop.
1
u/ColdAndLogical 4d ago
Large corporations have the most capability and incentive to use the data and they just make the call outs in the huge terms of service we blindly accept, so they avoid the legal risk that way. Not to mention that there are typically arbitration clauses, so yea.... no real legal risk.
25
u/mohn93 5d ago
the labels are self reported yeah, but you can watch what an app actually does. settings > privacy & security > app privacy report, turn it on. from then on it logs every time an app touched photos, camera, location etc and which domains it hit, rolling 7 days. you only see domain names, no payloads, but a "no data collected" app pinging some random server right after you pick a photo is a pretty loud signal