What the OpenAI API means for your app's privacy disclosures
the OpenAI API is a model API. What it involves, whether it needs the tracking prompt, what goes on the App Store labels and the Play Data safety form, and the rejection it is usually behind.
What the OpenAI API actually does
Model calls from your backend or, less wisely, from the app itself.
What its job necessarily involves
These follow from what the thing is for, so they are true whichever version you installed:
- Whatever your users type, sent to a third party the moment they press send.
- Any context you attach, which is often more than the prompt.
What to open and check in the OpenAI API
The settings below decide what the honest answer on the forms is, and they are specific to this SDK rather than to its category:
- Whether calls go from the device or from your server. From the device means your API key ships inside the binary, which is a larger problem than the disclosure.
- What context you attach to a prompt beyond what the user typed.
- The retention terms on your account, so the policy can say something true about them.
the OpenAI API does not need the tracking prompt
Nothing here reads an advertising identifier. So the OpenAI API does not on its own require App Tracking Transparency. That is a statement about this SDK, not about your app: add one ad network or one attribution tool and the prompt applies to everything.
the OpenAI API in Europe: runs on necessity
You cannot deliver the service without it, so the OpenAI API generally rests on the contract with your user rather than on consent. Say plainly in the policy that it is a processor, what it does, and where it runs.
the OpenAI API in California: probably not a sale
the OpenAI API does its job for you rather than for its own commercial purposes, which normally keeps it a service provider rather than a sale. That depends on your contract saying so, and the standard terms usually do.
the OpenAI API on the App Store privacy labels
Apple asks what your app collects, and your app collects whatever its SDKs collect. the OpenAI API is generally declared under App Functionality, alongside whatever the rest of your app does for its own reasons.
the OpenAI API on the Google Play Data safety form
The form asks two things the labels do not: whether data is shared with anyone else, and whether it is encrypted in transit. For this SDK the honest answer is usually collected but not shared, because it processes on your behalf.
Check OpenAI's own privacy manifest for the OpenAI API
Since 2024 Apple has required third-party SDKs on its list to ship a signed privacy manifest declaring what they collect and which sensitive APIs they use, and your app's combined manifest is built from them. That file is the authoritative answer for the OpenAI API, it comes from OpenAI, and it changes when they ship.
The rejection the OpenAI API is usually behind
The policy never says that user input leaves for a model provider, which is the single most common gap in apps shipped in the last two years.
What to put in the privacy policy about the OpenAI API
- OpenAI named as a processor or a recipient, not hidden behind "our partners".
- What it is for, in a sentence someone would understand without knowing what an SDK is.
- Where it runs, and what makes a transfer outside your region lawful.
- How long the data is kept, which is a question the vendor documents and most policies skip.
- That it processes on your instructions rather than for its own purposes.
Keeping it true after launch
A legal page stops being true the moment the product moves past it, usually by adding a payment provider, an analytics SDK or a sign-in. No store re-checks your pages against your build, so the drift is yours to notice.
- Re-read it whenever you add a dependency that sees user data.
- Re-check what loads on the page after any change: the cookie notice and the policy have to agree.
- Keep the URL stable. Changing where a policy lives breaks every listing that points at it.
Common questions
Do I need a privacy policy just because I use the OpenAI API?
Yes, and you needed one anyway. Both stores ask for the URL before a listing goes live, whatever the app does. The SDK changes what the policy has to say, not whether you need one.
Does the OpenAI API put me over the line into tracking?
Not by itself. The question is always about your app as a whole, so it is the other things you installed that decide the answer.
Does removing the SDK fix a rejection?
Usually yes and it is the fastest route, but only if you also correct the labels and the form. Reviewers compare what you declared against what the binary contains, and a stale declaration fails on its own.
