Apple 5.1.2(i) · EU AI Act
What your privacy policy has to say about AI features
If your app sends personal data to an AI provider — an LLM API, a recommendation model, anything with a vendor behind it — two separate rules apply, and most privacy policies were written before either existed.
Apple 5.1.2(i): name the provider and ask first
Apple's guideline requires disclosing any third-party AI service you send user data to, saying what data goes and that it will not be used to train the vendor's models, and getting consent before the first call — not buried in a settings screen, an actual prompt.
The EU AI Act adds a transparency duty
Article 50 requires telling people when they are interacting with an AI system, and when a text, image or video was AI-generated. It sits beside Apple's rule rather than replacing it: one is a store requirement, the other is a law that applies regardless of platform.
What actually goes in the policy
The provider's name, what categories of data reach it, whether it trains on your traffic (most enterprise API tiers say no — check yours), and how a user can decline. Lanpage's Privacy Policy template writes this section once you tell the wizard your app uses AI features.
The mistake that fails review
A generic line like "we may use AI to improve our services" names nothing and asks for nothing. A reviewer checking this asks which provider, what data, and where the consent prompt is — not whether AI exists somewhere in the stack.
What the section has to name
- The AI provider or providers you send data to.
- What categories of personal data reach them.
- Whether your data trains their models — most API tiers opt you out by default, but say so.
- A consent prompt before the first call, not just a policy sentence.
Questions
- My app only runs AI on-device, nothing leaves the phone. Do I need this?
- No. The requirement is about data sent to a third-party AI service. On-device inference with no vendor in the loop is not what either rule targets.
- Does this apply if I built a chatbot with an LLM API?
- Yes. That is exactly the case both rules describe: user input or personal data leaving your app for a provider's servers.
- Is "we use AI responsibly" enough?
- No — that names no provider and asks for nothing. Both rules want specifics: which vendor, what data, and a real consent step.
Answer this from the wizard, not a blank editor
Say your app uses AI features and Lanpage writes this section with the provider you name and the consent flow already in the template.
Free. No card.
We help you publish and maintain your legal and support pages. We are not a law firm and we do not guarantee regulatory compliance.