Skip to content

Guide / Privacy manifest

The privacy manifest of an Expo app with feedback

An Expo app has a privacy manifest too, but where it comes from is different from a native Swift app. This guide explains what the Nitpick package for Expo declares, what its screenshot library declares, and where the answers about collected data go. It is information to help you, and Apple's rules change.

What ships in the Nitpick package

@nitpickhq/react-native is JavaScript and TypeScript only. It has no native code and ships no PrivacyInfo.xcprivacy file of its own. The data that it sends is therefore not described by a manifest that comes with the package. You describe it yourself in the App Privacy form in App Store Connect, with the answers from App Privacy answers for a feedback component.

What the native libraries bring

The component uses react-native-view-shot for the screenshot. That library does ship its own PrivacyInfo.xcprivacy in its iOS folder. expo-device and expo-constants also ship their own PrivacyInfo.xcprivacy. Check the privacy report of your own build to see which manifests ended up in the app.

Declaring reasons in app.json

Expo reads the privacy manifest of your app from the ios.privacyManifests field of your app config:

{
  "expo": {
    "ios": {
      "privacyManifests": {
        "NSPrivacyAccessedAPITypes": [
          {
            "NSPrivacyAccessedAPIType": "NSPrivacyAccessedAPICategoryUserDefaults",
            "NSPrivacyAccessedAPITypeReasons": ["CA92.1"]
          }
        ]
      }
    }
  }
}

That example is from Expo's own documentation. Expo also warns that Apple does not correctly parse all the manifest files of static CocoaPods dependencies, so you may have to copy the required reasons from your libraries into this field yourself. Check the privacy report of a real build to see what ended up in the app.

A short checklist

  1. Run npx expo install --fix to keep the libraries on versions that match your SDK.
  2. Build the app, archive it and read Xcode's privacy report for the manifests that are included.
  3. Add the required reasons that are missing to ios.privacyManifests.
  4. Answer App Privacy in App Store Connect for the four data types the component sends: Other User Content, Customer Support, Product Interaction and Other Diagnostic Data.
  5. Put the paragraph from Privacy and store forms in your privacy policy.

What was tested

The component was checked in Expo Go on iOS. Check the privacy report of a real build before you submit.

Keep reading

The Swift package does ship a manifest, see the privacy manifest guide for SwiftUI. For Android, read Google Play Data safety. To add the component, see in-app feedback for Expo. The install page is Install for Expo.

$9 a month per account. Unlimited apps.

Get started

Related

Sources