Where do you see that? I see "The developer does not collect any data from this app."
That said, Apple doesn't really handle the case of permissions changing with an app update very well, so launching your app purely device-local then updating to add something server-side a year later would probably let you get around that.
This app seems to not have the key that'd indicate it's capable of sending anything to a server: https://github.com/afterxleep/Bouncer/blob/master/Bouncer/In... (though, you know, that assumes that the build on the App Store is directly from the source we can see...)
Isn't App Store review supposed to at least catch things like that?