Apple removes a requirement that apps with third-party log-ins must offer Sign in with Apple, but requires an equivalent option with certain privacy features
There's another small but notable change coming to the App Store. Apple has revised its App Store guidelines to remove the requirement …
Context & Ripple Effects
Apple originally made its privacy-oriented login service mandatory for iOS apps that used third-party sign-ins, after introducing Sign in with Apple as an email-masking option. The new guideline reverses the product-specific mandate while preserving a privacy baseline for alternatives.
The change fits a broader App Store policy pattern in which Apple has paired platform access rules with user-control requirements, including the in-app account-deletion requirement for apps that support account creation.
First-order effects
- Apps using third-party login services no longer have to add Sign in with Apple specifically; they must instead provide an additional sign-in option with the required privacy protections.
- Apple retains a privacy standard for login flows but gives developers more latitude over which compliant identity option they implement.
Second-order effects
- Third-party identity providers and app developers can compete around privacy-preserving login features rather than treating Apple’s service as a mandatory companion integration.
- Developers updating authentication flows must assess whether their alternative option meets Apple’s specified privacy criteria, shifting compliance work from adding one named service to validating feature equivalence.
Third-order effects
- If Apple applies this approach more broadly, App Store policy could increasingly specify user outcomes—such as privacy and account control—rather than require Apple-branded implementations.
- That would preserve Apple’s role as rule-setter while leaving more room for competing services, though the practical openness depends on how narrowly Apple defines equivalent protections.
The trend: App Store governance is moving from prescriptive use of Apple services toward outcome-based requirements that still enforce Apple-defined privacy standards.