
Catch App Store rejections early

Catch App Store rejections early
RejectProof is a web-based tool that analyzes iOS application builds (in .ipa or .app format) to identify potential reasons for rejection by Apple’s App Store review team. The scan runs entirely within the user’s browser using a Web Worker, meaning the binary file never leaves the local machine. Only a small JSON summary of the scan results is transmitted to the server, and only after the user has reviewed and explicitly clicked a send button. No account creation or file upload endpoint is involved, and no data is retained after the scan completes. The tool provides two tiers of analysis. A free check answers ten questions about the build and generates a metadata report. For a one-time payment of nine dollars, a full 32-point binary scan is unlocked. This scan returns a guideline-by-guideline rejection report, typically produced in under a minute. Each flagged item includes the relevant Apple guideline number, the specific evidence (such as the file name and string location), and a plain-English fix tailored to common development environments like Xcode, Expo, Rork, Bolt, or a0. The scan examines keyword counters for approximately 40 terms (for example, ATTrackingManager and SKPaymentQueue), embedded framework folder names under Frameworks/ to detect ad or analytics SDKs that lack a privacy manifest, and the contents of the Info.plist and PrivacyInfo.xcprivacy files. Values for Apple’s allowed keys (such as bundle identifier, version, and usage description texts) are retained, while all other values are replaced with “[redacted]”. The provisioning profile’s team identifier, expiry date, and Apple entitlements are read, but custom entitlements and certificate blobs are redacted and never transmitted. RejectProof is designed for developers who have built an app using Rork, a0, Bolt, or Expo combined with AI coding assistants like Claude Code or Cursor, as well as for first-time submitters who have an .ipa file but are unfamiliar with App Review requirements. It also serves indie iOS developers who know the guidelines but want a quick sanity check before each submission. The workflow involves dropping the .ipa file onto the web page, answering ten questions, and receiving a free report. After that, the user can choose to purchase the full binary scan. The tool does not store any files, passwords, or account information, and the only persistent data is the JSON summary that powers the report link.