Purpose string does not say why the permission is needed
Check PB-53 · App Store Review Guideline 5.1.1 · Probable rejection · verified 2026-09-16
Why App Review rejects under Guideline 5.1.1
5.1.1 covers everything about what data the app touches and whether the user was told. In practice three sub-cases account for most rejections: a permission string that is missing, unclear, or declared for an API the app never calls; a missing PrivacyInfo.xcprivacy for the app or for an SDK on Apple's required list; and account creation without an in-app deletion path (5.1.1(v)). All three can be checked against the binary before submitting — the manifest is a file, the strings are keys, the APIs are symbols.
How to fix it
Apple rejects purpose strings that only name the resource — "Allow MyApp to access your camera" (the Expo default) is the most common 5.1.1 rejection text. Each NS*UsageDescription must state what the user gets: "Camera is used to scan receipts so you do not type totals by hand." Expo: expo.ios.infoPlist.<key> or the plugin's permission option. Swift: Info.plist. One sentence with a concrete reason per key.
How RejectProof detects it
The scan reads your .ipa in the browser (or locally with npx rejectproof): Info.plist, entitlements, the privacy manifest, embedded frameworks and the executable itself. Check PB-53 reports the exact evidence it found — the key, the symbol, the file or the URL — so you can confirm it in your own project before changing anything. Nothing is uploaded; only a small redacted summary is sent to build the report, and you see it first.