Guideline 4.8 - Design - Login Services
What the guideline says. Apps that use a third-party or social login (Google, Facebook, Log in with X and others) to set up or authenticate the user's primary account must also offer an equivalent login that:
- limits data collection to the user's name and email address;
- lets users keep their email address private;
- does not collect interactions with your app for advertising without consent.
Sign in with Apple meets all three, which is why it is the usual fix.
When it does not apply. Your app only uses your company's own accounts; it is an education, enterprise or business app that requires an existing account of that kind; it uses a government or industry-backed ID; or it is a client for a specific third-party service where users sign in to that service to reach their content. Using Google only to connect a service (for example Drive backups) is not the primary account.
How to add it.
npx expo install expo-apple-authentication # Expo
npm install @invertase/react-native-apple-authentication # bare React Native
Enable the Sign in with Apple capability for the app ID, show Apple's button next to the other providers on iOS, and link the Apple identity to the same account on your backend.
How common it is. In our scan, 11 apps use Google or Facebook login on iOS with nothing equivalent. npx nativekeel flags it and lists the exceptions so you can decide.
npx nativekeel