For developers · Checked 30 September 2026

The iOS privacy manifest: what to declare and how

Short answer: a privacy manifest is a file named PrivacyInfo.xcprivacy in your app or SDK bundle. If your code uses one of Apple’s required reason APIs, you must list the API category and an approved reason in it: since May 1, 2024, App Store Connect does not accept apps that use these APIs without declaring why. Third-party SDKs must carry their own manifest; your app’s manifest cannot cover them.

The five required reason API categories

From TN3183 «Adding required reason API entries to your privacy manifest», read 30 September 2026. Approved reason codes for each category are listed in Apple’s NSPrivacyAccessedAPITypeReasons documentation.

Category value for NSPrivacyAccessedAPITypeWhat it covers
NSPrivacyAccessedAPICategoryFileTimestampAPIs that read file creation or modification times
NSPrivacyAccessedAPICategorySystemBootTimeAPIs that read system boot time or uptime
NSPrivacyAccessedAPICategoryDiskSpaceAPIs that read available or total disk space
NSPrivacyAccessedAPICategoryActiveKeyboardsAPIs that read the list of active keyboards
NSPrivacyAccessedAPICategoryUserDefaultsUserDefaults APIs

Why Apple asks for reasons

Some APIs an app needs for normal work can also be misused to fingerprint a device or a person. Apple does not allow fingerprinting, whether or not the user has given permission to track. So for these «required reason» APIs you declare why you use them, you may use them and the data derived from them only for the declared reasons, and those reasons have to match what the app visibly does. None of them may be used for tracking.

What goes in PrivacyInfo.xcprivacy

Add the NSPrivacyAccessedAPITypes key, an array. For every category of required reason API your code uses, add one dictionary with exactly two keys: NSPrivacyAccessedAPIType, a string set to the category value from the table above, and NSPrivacyAccessedAPITypeReasons, an array of the approved reason codes that match your use. In Xcode, choose Editor > Raw Keys and Values to see the raw key names while you edit, and make sure the reason you pick belongs to the category in the same dictionary. The same file also holds your tracking declaration, tracking domains and collected data types.

Third-party SDKs

Every executable or dynamic library that calls a required reason API needs a privacy manifest in its own bundle. An SDK cannot rely on the app’s manifest, or on another SDK’s, to report its use. Since May 1, 2024, when you add an SDK from Apple’s list of commonly used third-party SDKs, the submission needs that SDK’s privacy manifest, its declared reasons and, if you add it as a binary dependency, a valid signature. In practice: update SDKs to versions that ship a manifest before you upload.

If App Store Connect rejects the upload

Apple sends an email after an upload that uses a required reason API without a declared reason, and since May 1, 2024 such uploads are not accepted. Read which category the email names, search your code and your SDKs for the API, then either add the category with the matching reason to the manifest of the bundle that calls it, or update the SDK that calls it. Rebuild and upload again; the manifest is read from the build, so the fix is always a new build.

Where Censuus fits

Getting through review is the floor; being found is the rest. Censuus ranks apps by the visits they draw, and adding your app is free on the List my app form. Placement comes from traffic and sponsorship: apps climb on the visits they draw, and a sponsor can pay to rise higher.

Frequently asked questions

Is a privacy manifest required for every iOS app?

It is required when your app or an SDK in it uses a required reason API. Since May 1, 2024, App Store Connect does not accept apps that use those APIs without describing the reason in a privacy manifest.

What are the required reason API categories?

File timestamp, system boot time, disk space, active keyboards and UserDefaults, declared with the NSPrivacyAccessedAPICategory values of the same names.

Can my app’s privacy manifest cover a third-party SDK?

No. Apple says an SDK cannot rely on the app’s manifest or on other SDKs’ manifests to report its own use; each bundle that calls a required reason API needs its own manifest.

Does the privacy manifest apply to watchOS and visionOS apps?

Yes. Apple asks for required reason declarations for apps and SDKs on iOS, iPadOS, tvOS, visionOS and watchOS.

Guides for app developers

Put your app in the ranking

Censuus ranks apps by the visits they draw and by sponsorship, no bots. Listing is free; sponsorship raises placement.