That's because Apple requires it. They won't approve my app, unless there's a "full-fat delete" option.
If a user of the app deletes, it completely nukes their entire account, down to the last byte.
That's because Apple requires it. They won't approve my app, unless there's a "full-fat delete" option.
If a user of the app deletes, it completely nukes their entire account, down to the last byte.
I have seen apps that delete an entire thread, when a root comment is deleted; including responses by other people. I think SMF did that.
In the case of our app, we leave communication between users to other apps (like Mail and Messages), so we sidestep that problem.
Actually, the reason we deliberately push communication out to other apps, is so we’re not on the hook for it. There’s no reason for us to have the users communicating with each other, via our app. Long story, but privacy is a real big deal, with our user base. I’m super tinfoil about security.
Hence it may be reasonable to request that all data be removed.
There is public evidence that a lot of apps lie on their privacy labels and they seem to get away with it.
Most times, that’s usually a server, of some kind, but it could also be something like an iCloud data account, I guess; which would be a challenge, as the data could be in many places.
The guidelines do state that it should be a full delete. In my experience, Apple has never checked or asked to verify if a user account was fully deleted on apps I've worked on, which involve PHI. It's been a part of HIPAA compliance for our apps since the beginning (and we do actually fat delete, FWIW). It's a relatively new requirement from Apple's end, though. The deadline was actually extended from January 31st 2022 to now June 30th 2022. Enforcement or stringency on Apple's part could change around then, but I don't see Apple having the resources or willpower to do much of an increase here.
Full guidelines are here: https://developer.apple.com/news/?id=i71db0mv
Edit: This comment is in response to the suggestion that all apple apps delete all local data which after rereading the parent they were only suggesting for their app.
Are you sure about that?
I'm not an iOS developer but as a user I noticed a few years ago that deleting google apps, even all google apps, off my phone and from icloud still resulted in a freshly installed google app suggesting I log in using the account I was last using.
My best guess after doing some searching is re-identification was done using a "Keychain Access Group"[1] which does not automatically get deleted on app uninstall. Though it is stated [2][3] that this is an implementation detail and not a guaranteed behavior. If I recall correctly the only way to reset the Keychain Access Group if the app doesn't do it is to wipe the phone.
It is also possible to persist data if an app is part of an "Application Group" and one of the apps in that group is still installed on your device then data shared via that approach will not be automatically deleted unless all apps in that group are uninstalled (from what I have read).
Apple does have the "DeviceCheck"[4] framework which significantly limits the amount of bits which can persist across app reinstalls which prevents / severely limits an app's ability to reidentify users but still enable some useful use cases. However until "Keychain Access Group" persistence is removed there is not a lot motivating a developer to use this framework.
1: https://developer.apple.com/documentation/security/keychain_...
2: https://developer.apple.com/forums/thread/36442?page=2 and for some prior history see https://developer.apple.com/forums/thread/72271?page=2
3: https://stackoverflow.com/questions/60485419/ios-keychain-da...
I wrote every line of code in the server that manages users’ PID (which is held under conditions that would drive most HNers into fits). I use a modified variant of my BAOBAB server[0]. It’s pretty tightly bolted down. The security of the system is enforced on the server[1].
I also wrote every line of the native Swift frontend app. I use the keychain for some stuff, and persistent prefs[2] for other stuff. The keychain can live between installs, so I have to explicitly delete that, as well as the persistent prefs. Since it only holds login info for a deleted account, it’s not an enormous risk (unless the user is one of those folks that reuses passwords).
So, yeah. I’m sure.
[0] https://riftvalleysoftware.com/work/open-source-projects/#ba...
[1] https://riftvalleysoftware.com/BAOBAB/PDFs/Security.pdf (downloads a PDF).
[2] https://riftvalleysoftware.com/work/open-source-projects/#RV...