onebox

Guide 20 of 27

For your agent: .md · all guides

On this page
  1. What Apple needs
  2. Where to host the two pages
  3. What the privacy policy says
  4. What the support page says
  5. Where the values go
  6. Check it works
  7. Common errors

Privacy policy and support page, without a landing page

Runs on: your browser. No server needed.

Apple asks every app for two public web pages, even a free app with no accounts: a privacy policy and a support page. If you use box:new-landing-page, those pages come with it and you can skip this guide. If you do not want a landing page, this guide gets you the two pages for free in about half an hour.

What Apple needs

PageWhere you enter the URLNeeded when
Privacy policyApp Store Connect → your app → App PrivacyAlways
Support pageApp Store Connect → your app → the version pageAlways
Terms of use (EULA)The App Store description, or the custom EULA fieldYou sell subscriptions (revenuecat.md)

Rules that people often miss:

Where to host the two pages

Pick one. All are free.

OptionGood forWatch out
GitHub PagesYou already use GitHubFree only from a public repository. The pages are public anyway, so make a small public repo just for them
Cloudflare PagesYour domain is already on CloudflareA few more steps than GitHub Pages; gives you privacy.example.com style URLs
Notion (published page)The fastestLooks like Notion, not like your app; the URL is long

A page on your own domain looks most trustworthy to reviewers and users, but any stable public URL is accepted.

GitHub Pages in five steps

  1. Create a public repository, for example myapp-pages.
  2. Add two files: privacy.md and support.md (the checklists below).
  3. In the repository’s settings, open Pages, choose Deploy from a branch, pick main and the root folder, and save.
  4. Wait a minute. The pages are at https://<user>.github.io/myapp-pages/privacy and …/support.
  5. Open both URLs in a private browser window to prove they are public.

What the privacy policy says

Use plain words, not legal-sounding ones. Cover each point in one or two sentences:

If users are in the EU or the UK, also name the legal basis (usually “to provide the service you asked for”) and the right to see, correct and delete their data. This checklist is a starting point, not legal advice.

What the support page says

Where the values go

ValueWhere
Privacy policy URLApp Store Connect → App Privacy; also in the app’s settings screen and the paywall
Support URLApp Store Connect → your app → the version page
Terms of use URLApp Store description, or the custom EULA field; also on the paywall

Check it works

Common errors

Wrong or out of date? Fix it on GitHub.