As this is outside the app, I understand it is authorised. If we are interpreting 5.1.1(x) literally as written, it would be authorised but you won't have the email address to recover the password with. so the question is how do we define a core functionality and prove it requires ID ? And whether 5.1.1.(v) supersedes 5.1.1.(x) Yes that's is probably the key question - does 5.1.1(x) only covers non core functionalities? And is password recovery a core functionality? Have not contacted support yet. I thought Apple Developer Forums would be the correct place to ask these questions first. But I can see that it's kinda quiet here :D So I'll shoot them a message I guess.
Topic:
Privacy & Security
SubTopic:
General
Tags: