Privacy manifest says tracking but lists no tracking domains
Check PB-11 · App Store Review Guideline 5.1.1 · Probable rejection · verified 2026-09-16
Why App Review rejects under Guideline 5.1.1
5.1.1 covers everything about what data the app touches and whether the user was told. In practice three sub-cases account for most rejections: a permission string that is missing, unclear, or declared for an API the app never calls; a missing PrivacyInfo.xcprivacy for the app or for an SDK on Apple's required list; and account creation without an in-app deletion path (5.1.1(v)). All three can be checked against the binary before submitting — the manifest is a file, the strings are keys, the APIs are symbols.
How to fix it
If you declare that you track, you must also list the domains you send data to (NSPrivacyTrackingDomains). Get the domain list from your SDK vendor's documentation.
How RejectProof detects it
The scan reads your .ipa in the browser (or locally with npx rejectproof): Info.plist, entitlements, the privacy manifest, embedded frameworks and the executable itself. Check PB-11 reports the exact evidence it found — the key, the symbol, the file or the URL — so you can confirm it in your own project before changing anything. Nothing is uploaded; only a small redacted summary is sent to build the report, and you see it first.