Halide rejected from App Store because it doesn't explain why it takes photos
9to5mac.com
9to5mac.com
Edit to add: This was for an update, over half a decade after release, not the initial release, and nothing had changed in how it functioned in this regard in that time.
Edit 2: Typo + clarification
I don't even think this would apply in the pathological case where a bug in the app causes the personal data to be leaked. You didn't leak it, the user did.
EDIT: meant to reply lower.
I know that's the opposite of what they led with, I'm not trying to be cheeky. It's just shorter if you invert the premise and avoid technicalities.
In general, on HN, I see people struggling to wrap their mind around that everyone who takes in data has to take it seriously, at least, that's how the app stores view it.
It doesnt mattet if you good faith assume he user of your app is smart wnough to keep the app and that endpoint secure, you are providing a meansnto exfiltrate your app data
The data protection policy would explicitly state such a exposure.
"No ezposure" is a state.
Any app that allows a user to put in a endpoint that transfers the user data should have a data policy, since a malactor could convince the user to change thta endpoint, leading to a breach.
I think that it seems benign only in theory.
For example, allowing the user to access the data is a feature, not a bug, and if you allow the user access to the data, then a blackhat can persuade the user to access and forward the data. This isn't a matter of HTTP or no HTTP, the user's data access is tightly bound to user's risk of social engineering.
Being benign doesn't make the policy self-evident. Google's rule is that you have to state your policy, you're not allowed to argue that users should understand any policy as being self-evident. IMO that's good of Google, because the cost for nice apps like this is so minor: Having to write a one- or two-sentence policy.
If everything stays on the device, sure, ignore data privacy.
But since you shuttle it through a hostile environment, it's important to identify how that data privacy is ensured.
Suppose there's an app, Niceapp, that keeps all data on device, and you want to attack it and exfiltrate its data. ① You install it, find out that it stores the data in /sdcard/Pictures/Niceapp, or some other world-readable directory. ② You write your own app with file system and network access permissions. You can find many suitable apps on github that you can rename and prettify. ③ You social-engineer users to install your app, which is then free to read the Niceapp data and exfiltrate them.
The attack works because the unstated policy leaves users (and possibly also the Niceapp developers) open to make inaccurate assumptions.
Edit: no, the more I think about it the more this interpretation is completely nuts. It implies that every single software vendor needs to secure consent from every single end user of software they ship through any client.
e.g. if SAP provide CRM software to Contoso, and Jim is a customer of Contoso, even though all the data is processed on Contoso premises, SAP still need to be in communication with Jim?
Contrary to a popular opinion, GDPR is fairly logical and close to common sense.
It gets murkier with "joint data processing" (a cursed cop-out for scenarios like Facebook acting both as a data processor for a website's ad tracking and as a data controller for its own ad tracking at the same time), but the scenario you described is not that.
Why do these companies get to say what you do with your camera, how you order food, or who you date? Their App Store dictatorship lets them control all of this.
The DOJ needs to mandate web installs for both platforms. Sandboxing, permissions dialogues, behavioural heuristics, and signature detection are all we need to keep us safe. The App Store concept is just a grift to earn Apple and Google margin on all transactions.
Apple might lose its monopoly, at least if other legislations follow the EU.
You can't one click install a web app, nor is it the expected user behavior.
The "might be harmful" and buried system dialogues mean that 0.001% of users will ever do this. It's completely unviable.
In a sense this might be worse behavior. Google gets to skirt regulatory scrutiny, yet functionally enables zero companies and users to leverage this path.
Think of Amazon or chinese huawei devices, even samsung ships it's own app store. Google's App Store is not that dominant.
Can you share some examples of when this happened to you?
(personally I'm in the middle on this: some quality control is valuable, and probably essential for anything with access to user data or payment services. But the store is also anti-competitive.)
Why do they have to know or control me or my audience?
I admit that I don't know about Apple's ecosystem, but if you don't want Google to know about your Islamic LGBT app, you don't have to tell them. Android users can download your app off your personally-owned .com and install it to their phone no problem.
All of my apps don't get 'upgraded' with new microtransactions, no SEO spam, and the apps do the job.
Even after all these years the reality distortion field is strong as ever. Meanwhile if Google had done this people would already be outside their HQ with pitchforks and calling for the government to break up their evil monopoly.
I don’t agree with the gp comment’s sentiment though, plenty of people here and elsewhere go hard to bat for google, although admittedly lately that’s increasingly difficult to do with a straight face.
Nobody is simping for anything. Taken at face value, folks just have an opinion that is different than your and they are expressing it on a site designed explicitly to express such things. And that is just fine.
Who knows maybe they have a point that you never considered. Why else would you visit the comments here? Just to get a pat on the back that every person on the planet thinks exactly like you do?
It can be banking, it can be ad business, or any other morally questionable endeavors, its the same story. Don't blame them per se, they don't know better and life would look suddenly pretty bleak with cold hard look in the mirror. Maybe the only clear failure IMHO is to not have something much more important defining who you are to yourself, your self-worth to say. Because then this becomes rather unimportant aspect of your existence and the need for elaborate invention of new convenient truths is much lower.
This was/is very difficult for me. I am about a decade into my career and 15 years into when I first started seriously messing around with tech - in those days, ~2010, tech was seen as the future to the planet and that message very much was pitched all around silicon valley and trickled into my coursework. The massive disillusionment I felt right out of school was a really hard hit and caused a bit of depression. I wasn't changing the world, I wasn't even doing anything remotely useful for a company that also wasn't doing anything remotely useful and I think that's been the case for most of my career, outside of the occasional instances where I do consulting (which I find rewarding actually).
But such is life, outside of tech as well. I take pride now in my work, not whatever I think I am contributing to society. If my work is doing something ultimately pointless or supporting something that is morally or ethically gray, I take pride in ignoring that (because I have no control over it) and doing it as best as I can and that has helped a lot. Some may judge me harshly for that, but I don't care, it is really one of the only sane ways to cope - rather than conjuring insane justifications for why things are the way they are (which suck).
I had a teacher call me poor for having an Android. I made 4x more money than her in a year, and decided to let her know that.
I also let her know that a phone I can get for $30/mo isnt much of a status symbol. Unemployed teens are able to afford it somehow.
Instead, they can make app developers fulfill whatever criteria they want. It’s their platform after all.
It’s like going to the DMV, the type of people who work at those human facing administrative jobs often don’t care about doing their job well, they just blindly check boxes and exploit their small of amount of power to avoid any personal responsibility.
You guys are overthinking this
I don’t know anything about this particular case but there is a gray area when it comes to what an owner of a platform should/shouldn’t be allowed to do. I hope the EU cracks down hard on both Apple and Google. Both of these platforms have become essential to modern life in many ways and as such a case can be made for strict government oversight of them.
Once you realize how dirty Apple's marketing is, its quite off-putting. I have a similar aversion to Samsung, Nintendo, Disney.
Maybe Google does mind control, but I didn't catch them. Apple, Samsung, Nintendo, Disney, these companies have no qualms making you feel pain to get a sale.
Just a minor nitpick/correction here but there are multiple ongoing anti-trust suits that Google is getting killed on that very likely will lead to the breakup of some of its company's products, so that may be where the comment you are replying to is coming from.
A cherry picked measure of some rando who thinks Apple is taking money off the table that would be ours if not for Apple; free the market from this Kraken!
More banal free market retail capitalism demands from the IT crowd who would be Tim Cook themselves.
When someone here defines novel mathematical axioms, humanity will have reason to be impressed. Iterating inside the same old knowledge bubble and skill set is uninspiring; the demand to create an economic brand and build a flock of sycophants is sad old roleplay
My laptop computer has that ability built in, and it isn't really "mad"
If Apple allowed me to load software from third parties directly, like I do on my computer, I wouldn't care what the App store policies were, much like I don't care what the MacOS app store policies are.
I’m coming fresh off weeks of app rejections that turned out to be I included the word “review” in the description of my app on the Google Play Store, and best I can tell was an automated rejection based on keyword matching and entirely unhelpful to explanatory text, so let us not pretend Google is running a tighter ship here.
Nope, not seeing anyone defending Apple on this (at least in the top hundred or so comments at time of writing). Even if you can find one, the posts ITT remarking on how common ridiculous Apple defenses are likely outnumber the actual comments defensive of Apple. Y’all may want to adjust your priors.
The intended functionality of the App, no matter how obvious it may seem, needs to be documented to users IMO. Yes it's a camera app - yes it takes pictures. However, users should understand WHEN and under what conditions the app takes pictures.
Saying "this app takes photos" is really not enough. Does it take photos while I sleep?
That might sound ridiculous but remember the plethora of apps that take location data when they don't explicitly need it at that moment.
Hey everyone. Apple followed up with us to confirm this was a reviewer goof. Normally, they don't sweat that description when it's obvious it's a camera app. They're stricter on apps that don't really need camera access. This was human error, there's no need for us to change the description, so we're all good.
So I had to add a completely useless feature where a user could partition their database by marking some items as "favorites" and have a separate "favorite" view.
This was then approved, with the assertion that "it's now the magical kind of experience users expect from the App Store."
I'm pretty invested in an Apple ecosystem for some very specific software, but that was nearly enough to make me ragequit (unfortunately, the specific software is not something I could develop/imitate under Linux without a huge financial investment).
1. What is your definition of 'professional tools'?
2. What does Apple need to do to make Macs 'real' professional tools?
I think this is a cultural divide for young developers, because older developers wouldn't think twice about my comment, but clearly it's an unpopular opinion.
In carpentry, your hammer doesn't tell you what you can and cannot fasten.
No commercial, professional engineering tools require features for consumers, like favoriting items, for them to be distributed.
If that's lost on you, then I have no idea what you think a professional tool is, but there's no world I operate in where you and I share the same idea of it.
*Not Safe For Widescreen
The article states that the alert had to be changed from:
"The camera will be used to take photographs"
to
"The camera will be used to take photographs for the app that you just downloaded to take photographs for."
"Spotify, why would you like to play audio? Please notify the users that you are using the speakers to play the audio for the app they just downloaded to play audio."
If they make using third party apps a little more scary, a little more dense, consistently, people will slowly gravitate to Apple's first party apps. You can see a similar pattern for MacOS where more and more restrictions are added to opening apps downloaded from outside the App Store.
Developing for the App Store is about as much fun as filling out tax forms and talking to an IRS agent.
Whereas with app store reviews, it's a black box with no option other than trial and error to figure out what to do.
That is a terrible reason to request camera access. It is just restating the access request and it should be rejected. Why will photographs be taken? Because it is a camera/photography application and will only take photographs on explicit user request.
But as you just downloaded a camera app that you want to use to take pictures, that description is actually already beyond what could reasonably be expected.
E.g “The camera will be used to continuously take photographs and upload them to our AI platform for training, analysis, and aesthetic optimization.”
In my job capacity, I give status updates about many unrelated projects.
If I am not explaining full context in a seemingly simple update or question, I will get my hand slapped. And if I tell my boss to “read” it’s going to go worse.
I would have removed the risk of removal by simply prefacing the app is a professional camera app and taking photos is the primary user function.
And not just a lesson for here but also in life: One-liners are fun to say, but people generally don’t like being on the receiving end of them.
This is an example of such an unparalleled curation service. The app makers are just lucky enough to be popular (and even promoted by another arm of Apple) or they'd still be out of the app store.
Imagine the ridiculous level of explanatory humdrum apps would need to conjure if they were to explain themselves to uninterested people pressed for time like that reviewer you described?
Oh come off it. It's used to take photographs because it's a photography application. How much handholding do we need?
Isn’t that a philosophical question? Do we now need to get philosophical to go through App Store reviews?
"This is an alternate camera app. To take photographs, it needs access to the camera hardware."
Photography is literally the only thing camera is good for and it's used for that purpose 100% of the time.
They can just write that the reason is that Halide is a photo app and be back on the store with no need for hand wringing.
I just wish Apple was as good as this at vetting all apps. There is always some junk on the store.
Is photometry photography now? Is the barcode reader at my supermarket performing photography? The encoder on my scroll wheel? My solar roof?
Cameras can be used for many things other than photography. Many other things than cameras can be used for photography. The two are not synonymous.
You are trying to bend definitions
> Cameras can be used for many things other than photography
Like plug a hole with it or hammer a nail?
This is photography. You are thinking about art but photography also means technical process.
People should be able to control computers they own. Simple as that.
Be careful what you wish for.
If the docs don't say why then you do not go to the second stage.
But the app was featured in the Glowtime event just weeks ago. The app has won an Apple Design Award. It has been in the App Store for, what, seven years? Of all the apps to reject, the reviewer sure made a poor choice.
If Apple is going to have strict usability requirements on the clarity of the permissions requests, that has the potential to be a good thing. But that requires establishing guidelines, and publishing them, and being clear about what in the prompt does not meet the guidelines.
“This is a camera app”, might be a better explanation.
Last month our app was rejected for not working on the iPad Air. This rejection came in at 2 am in the morning on a weekend. App was never supported for iPad. My company panicked but I realized what was happening and just sent it for review again and it was accepted after 15 hours.
But the damage was done and iOS platform missed the marketing launch. Android made it through.
It’s a mess because the review is almost always disproportionate to the changes you might have done in a update. That update was a simple content change and there was no reason to assume it would be blocked. But there is never any guarantee. Sometimes they will say you can’t say iOS 18 in your release notes. :) it’s dumb so be warned, set the right expectation to the rest of the organization.
“Halide needs access to your camera to capture photos and videos with advanced controls for pro-level photography.”
For user facing text I tend to always try a LLM version, just because the results are so middle of the road, which is exactly what I want in a case like this.
The reality of the situation is that the camera app needs camera permissions because it's a camera app. It's for taking photos, you know.
In other words, "camera app needs access to the camera."
Explain why you need it and what you’ll use it for.
“Halide needs access to the camera to capture the photos you take.”
Capture photos, that’s obvious. Will only be used when _I_ choose to take photos. That’s good to know!
Contrast with something like “App needs access to capture the photos you take as well as perform periodic background captures and image recognition to provide feedback to our advertising partners.”… Wait, what?!
Still silly, but I don’t think there’s no room for more precision and clarity here. The prompt Halide is using doesn’t actually say they’re _not_ doing the second one.
I just think that it's a silly reason to reject this app.
(And I say that as someone who used to work at Google in the Android org - and I'd make the same comment if the Play Store did it.)
The thing is. I like apps needing to display and even better request permissions for resources like the camera, files and clipboard.
But that should be the limit. What I don’t want is somebody, anybody other than my self deciding if an application actually needs those permission.
WE need an alternative to walled garden app stores. It can be fine that a curated store exist that does these things. But they need to live side by side with stores or catalogs that do less and more.
It’s an uphill battle because Apple and Google both know that it will be a loss of revenue for them. What is silly though is they could make the App Store have sub app stores curated by different entities (or not at all) and solve all this and keep revenue. But they won’t.
"The camera will be used to take photographs"
Given how that reads, I'd think listing any single specific reason a user would want to take photos with this app instead of the default camera app would have worked fine.
The age of open permissions is should be long over.
I'm sick over overreaching app permissions wasting my battery trying to collect more data on me. If you want more data, provide more value.
It's not overreaching app permission, it's been rejected because the text "The camera will be used to take photographs" wasn't considered a good enough explanation for the permission.
I get that the app store is strict. But its strict for a reason. Apple or the app store isn't out to get your app or you.
moral of the story. spend 3 extra minutes writing something out and save yourself from a headache.
why are we assuming every person that reviews apps knows what ur app does? with submissions like this the explain it like im 5 approach is necessary.
For the permission request, I'd condense your paragraph into a sentence or two.
It's not unusual to download an app, but not launch it immediately. Demanding that the user remember your App Store description is unfair. It's your baby, not theirs.
They might not launch your app for hours or days after downloading. And Apple, reasonably I think, wants developers to try harder to accommodate user's realities.
It's the App Store reviewer that considered the permission prompt to be unclear, and thus rejected the app from the platform.
Given the enormous volume of app submissions and the large number of points each app must be reviewed on, it might be unrealistic to require that reviewers always use the full context of the app when reviewing each individual component - the person reviewing the message might not even know what the app is! And they shouldn't have to! The message should be self-explanatory. The app needs access to the camera because it is a photography app, not because it takes photos.
I applaud Apple's thoroughness on this topic. It's much better than the opposite problem, which is what plagues virtually 100% of other software platforms historically, and I'm disheartened for software as a whole that some people (especially HN users, who should be more thoughtful) can't see beyond the petty "it must be mindless Apple defenders" catch-all, or the "rejection reasons are sometimes non-specific" problem, (the latter of which I am assuming on good faith is a real problem, though I've never personally encountered it).
Sorry, you have gone too far here. If the reviewer doesn't know what the app is, they aren't reviewing the app at all. Knowing that a photography app takes photographs is the absolute bare minimum of context that is required to even begin to meaningfully review it.
For example, there's the case where you download an app today, and don't get around to trying it for hours or days or longer. Curt "duh-style" permissions requests are user-hostile.
Apple insists that developers "try harder". In almost all cases, this is the right choice for the user.
Sometimes it's hilariously wrong, of course! There are humans in the review loop, and I've been on the wrong side of some epic ridiculousness. But on the whole, they're usually more frequently right than wrong. I'll take it.
I mean hell that's the root of the problem. It doesn't matter what context you provide or how obvious you make things, you're feeding your app to a black box that gives results seemingly at random. I haven't met a developer that hasn't failed review for arbitrary reasons, including me. Either give me clear guidelines and procedures to follow - and then follow them - or don't lock me out of doing my job.
That said,
I agree, lack of consistency is frustrating. But there is a big caveat to that opinion. When I experience inconsistent rejection, it has always been due to things that are reasonable to not catch as a reviewer 100% of the time. But personally, I would rather they catch 75% of instances of a problem than give up and let them all through because the inconsistency is frustrating. Of course, I would really like them to get that number to 100%, but I acknowledge that a lot of this stuff is not easily captured at a 100% rate using a tester script, or automatic processing. The key here is of course that you agree with or understand the rule they are enforcing. This is probably where most of the disagreement actually lies, and not so much in the inconsistency. I happen to be the kind of "purist" who would rather things be stricter for developers. I want the UX to be as good as possible, and I want the APIs to continue to improve and to not burden/complicate the platform with a lot of backwards compatibility. This is the opposite of a lot of developers, and I totally understand the other side of that argument.
This is not to say that Apple review is not shitty sometimes. I just happen to think that the one or two biggest things developers complain about seem to not be as clear-cut as developers describe.
Isn't providing functionality provided by existing iOS apps still a reason for rejection?
The description should at least say "for taking photos with advanced customisation suitable for professionals"
Please submit others if you have any.
Does anyone really think giving 20-30% of ecosystem revenue to some gatekeeper makes better ecosystems?
We need new open computing laws.
If you don't want that feature, don't buy the device! Or jailbreak it. Or compile your own code and load it.
It is not the 20%-30% of revenue that makes a better ecosystem, it's the vetting process for the software that makes it better. Every vetting process has errors, just as all software has bugs. The end goals of the process and the error rate of the process, and correction procedures of the process, are what makes a better software ecosystem.
Your average user won't know or even bother to change since as you mentioned they don't want to run unwanted code. Rest of us can run anything on our devices.
For example, I'm not going to buy Sonos speakers ever. It doesn't mean they should be outlawed for their practices.
Because then your grandmother will turn on that toggle as instructed by the fraud-center in South Asia, install a keylogger watching her banking activity when she sends you that $5 for your birthday, so they can drain that inheritance you were counting on.
See the article right here on HN about Python devs applying for jobs and being prompted to self-pown.
TL;DR:
There are more people susceptible to fraudulent instructions by bad actors than there are people qualified to evaluate consequences of running unvetted code.
Examples of both 1) and 2) are plenty, so I guess I just disagree that this vetting process helps anyone but the incumbent gatekeeper-taxers.