Skip to content

Guide / Privacy manifest

The privacy manifest of a feedback package in SwiftUI

A privacy manifest is a small property list file named PrivacyInfo.xcprivacy in which an app or a package states what data it collects. Apple expects third-party SDKs to include one. This guide shows what the Nitpick Swift package declares, how that connects to your own App Privacy answers and what you still have to do yourself.

What a manifest holds

The file has four main keys:

Xcode merges the manifests of all frameworks and packages in your app into one privacy report, so you see the combined picture in one place.

What the Nitpick package declares

The package carries its own manifest and lists it as a resource in Package.swift, so it travels with the package into your app. It says that there is no tracking, that there are no tracking domains, and that four data types are collected, none linked to identity, none used for tracking, all for App Functionality. It uses one required reason API, UserDefaults, to keep the last app settings, declared with reason CA92.1.

<key>NSPrivacyTracking</key>
<false/>
<key>NSPrivacyTrackingDomains</key>
<array/>
<key>NSPrivacyCollectedDataTypes</key>
<array>
  <dict>
    <key>NSPrivacyCollectedDataType</key>
    <string>NSPrivacyCollectedDataTypeOtherUserContent</string>
    <key>NSPrivacyCollectedDataTypeLinked</key>
    <false/>
    <key>NSPrivacyCollectedDataTypeTracking</key>
    <false/>
    <key>NSPrivacyCollectedDataTypePurposes</key>
    <array>
      <string>NSPrivacyCollectedDataTypePurposeAppFunctionality</string>
    </array>
  </dict>
  <!-- the same entry for CustomerSupport, ProductInteraction and OtherDiagnosticData -->
</array>
<key>NSPrivacyAccessedAPITypes</key>
<array>
  <dict>
    <key>NSPrivacyAccessedAPIType</key>
    <string>NSPrivacyAccessedAPICategoryUserDefaults</string>
    <key>NSPrivacyAccessedAPITypeReasons</key>
    <array>
      <string>CA92.1</string>
    </array>
  </dict>
</array>

The four types match the answers in App Privacy answers for a feedback component: the comment and the screenshot, the report as a message to the maker, the tap position, and the device and app details.

What the manifest does not do

It does not fill in App Store Connect for you. The App Privacy answers are still yours to give, and Apple holds you responsible for the data that the code of third parties in your app collects. The manifest makes the report and your answers easier to check against each other.

What to check in your own app

  1. Add the package, build and archive the app, then open the privacy report that Xcode generates and look for the four data types and the UserDefaults reason.
  2. Compare it with your App Privacy answers in App Store Connect.
  3. If your own code uses required reason APIs, declare them in your app's own manifest. The Nitpick package declares its own UserDefaults reason; declare the APIs that your own code uses in your app's manifest.
  4. Put the paragraph from Privacy and store forms in your privacy policy.

The panel itself adds the visible side: a preview of what is sent, a Send button and the line "Your feedback goes to the maker of this app." under it.

Keep reading

Add the package by following in-app feedback for SwiftUI. On Android the equivalent form is Google Play Data safety. If your agent installs the package, see Codex with SwiftUI. The install page is Install for SwiftUI.

$9 a month per account. Unlimited apps.

Get started

Related

Sources