Repeated App Review Rejections: Custom-Built VPN App Flagged Under Guideline 4.3(a), Now Guideline 5.6

Hi everyone,

I’m looking for advice from developers who may have experienced a similar App Review situation.

Our app, ASK VPN (Apple ID: 679*****), has been rejected multiple times, and I’m struggling to understand exactly what Apple is detecting.

Initially, the app was rejected under Guideline 4.3(a) - Design - Spam.

Apple first stated that the app shared a similar binary, metadata, and/or concept with apps previously submitted by a terminated Apple Developer Program account.

After we asked for clarification, Apple later stated that the app shared a similar binary, metadata, and/or concept with apps submitted by other developers, with only minor differences.

To clarify an important point: we did not purchase this VPN source code from another developer, and we did not use a commercial VPN template, cloned project, or repackaged source code.

ASK VPN was developed specifically for this project.

I defined the product strategy, required functionality, user flow, and design direction myself, and used Codex AI as a development assistant to help implement the application.

The codebase was created for ASK VPN rather than acquired from another developer or reused from an existing App Store application.

Because of that, the earlier Guideline 4.3(a) rejection mentioning similarity to apps associated with other developers, including a terminated developer account, is particularly confusing to us.

After the earlier rejection, we carefully reviewed and updated the application and added or improved product-specific functionality, including:

  • Native iOS VPN implementation using Network Extension / Packet Tunnel
  • ASK VPN account and profile integration
  • Account status and expiry information
  • First-use onboarding
  • Terms and Conditions acceptance
  • Privacy and VPN disclosure screens
  • English and Myanmar localization
  • In-app support and guided help
  • Support diagnostic / Profile ID functionality
  • Secure handling and redaction of sensitive VPN configuration data
  • Updated app-specific UI and functionality

We explained these changes to App Review and repeatedly asked which specific part was considered similar — source code, VPN implementation, framework, metadata, screenshots, assets, certificates, signing history, bundle identifier, backend behavior, or app functionality — but we did not receive a specific technical explanation.

Now, on our latest submission, the rejection has changed to:

Guideline 5.6 - Developer Code of Conduct

Apple states:

“The app contains features that appear to have been intentionally hidden during the review process.”

This is especially confusing and concerning because we are not intentionally hiding any features from App Review.

Another thing I have noticed is that the app enters “In Review” and then gets rejected very quickly, sometimes almost immediately.

This has happened repeatedly.

Because the rejection happens so quickly, I am wondering whether an automated or internal detection system may be flagging something related to the binary, code structure, Network Extension, account association, signing history, backend behavior, configuration, or another technical characteristic.

At this point, we are willing to provide Apple with the complete source code of the application for technical review.

We are also willing to provide:

  • Complete iOS source code
  • Network Extension / Packet Tunnel implementation
  • Backend and API implementation
  • Server-side configuration relevant to app behavior
  • Feature flags and remote configuration
  • Environment-specific configuration
  • Authentication and account logic
  • Source-control history
  • Design and implementation records
  • Complete feature documentation
  • Test accounts and credentials
  • Any other technical information Apple may require

We would also be willing to provide access to a private source-code repository if Apple has an approved secure method for doing so.

We are not looking for a way around App Review.

We genuinely want to understand the exact issue, correct it properly, and fully comply with the App Store Review Guidelines.

I would really appreciate advice from anyone who has experienced something similar.

In particular:

  • What can cause Apple to associate a newly developed app with apps from a terminated Developer Program account?
  • Can common Network Extension / Packet Tunnel implementation patterns trigger similarity detection?
  • Can AI-assisted code, standard iOS architecture, common libraries, or generated implementation patterns contribute to binary or source-code similarity?
  • What can cause Apple to believe functionality is intentionally hidden during review?
  • Could API responses, server-side behavior, feature flags, account states, device region, IP address, or review-environment differences cause this?
  • Could signing history, certificates, bundle history, provisioning, or backend infrastructure create an association with another developer?
  • Is there a way to request a deeper technical investigation or provide Apple with the complete source code?
  • What is the best escalation path when repeated App Review replies do not identify the specific feature, code path, or behavior causing the rejection?
  • Has anyone experienced a similar progression from Guideline 4.3(a) → Guideline 5.6?

I’m honestly very discouraged after going through repeated rejections without being able to identify the root cause, but I want to resolve this correctly rather than keep making speculative changes and resubmitting.

Any technical guidance or experience from developers who have dealt with a similar case would be greatly appreciated.

Thank you.

There is little information with which other people can assist you. There is no software description. There is no list of keywords.

Another thing I have noticed is that the app enters “In Review” and then gets rejected very quickly, sometimes almost immediately.

If you click on the Submit button or the Add for Review button without addressing the very issues that the reviewers have raised, that can happen. And you may get your account terminated if you keep doing it.

You have listed a lot of questions. I'm certain that nobody bothers to spend minutes answering them. I don't even bother to read them.

Repeated App Review Rejections: Custom-Built VPN App Flagged Under Guideline 4.3(a), Now Guideline 5.6
 
 
Q