What Keel scores in the Kids Category, and what it does not
Apple publishes 125 numbered guidelines. Keel scores duties from 10 of them. The other 115 are out, and this page is every one of them by number, so you can disagree with a specific line instead of with a total.
The rule
A guideline is scored here only where its duty is triggered by a child, a minor, an underage user, or by the Kids Category. Everything else is out, however much it matters to an app that happens to serve children.
One stated extension, used once. A guideline that is not child-triggered is in scope only where a child-triggered duty incorporates it by reference and would otherwise be unscoreable. That is Guideline 5.1.1(i) alone: Guideline 5.1.4(b) requires a privacy policy of Kids Category apps and of any app handling a minor’s data, and 5.1.1(i) is the only place Apple states what such a policy must contain.
Out of scope is not the same as inapplicable. This is not a claim that the excluded guidelines do not apply. Every one of Apple’s 125 guidelines binds the developer, and breaking one gets an app rejected whether or not Keel scores it. Keel scores the duties a children’s-privacy program is accountable for, and names the ones it left out.
Scored only in part
These guidelines are in scope for the duty named and no further. The unscored remainder of each is written out, because "partially scored" is otherwise a hedge rather than a claim.
-
1.2.1Triggered by something other than serving a childScored: Only (a), the age-restriction duty on creator content.Not scored: The creator-content moderation rules and the monetization rules the guideline points at. Both are general and are triggered by hosting creator content rather than by a child.
-
1.4.3Triggered by something other than serving a childScored: Only the sentence rejecting apps that encourage MINORS to consume tobacco, vape products, illegal drugs or alcohol.Not scored: The general prohibition on encouraging consumption, and the separate rule on facilitating the sale of controlled substances or tobacco. Neither is triggered by a child.
-
2.3.8Binds every app regardless of audienceScored: Only the “For Kids” and “For Children” metadata reservation.Not scored: The rule holding metadata imagery to a 4+ age rating whatever the app’s own rating, and the app-name to icon consistency rule. Both bind every app.
-
2.5.13Binds every app regardless of audienceScored: Only the alternate authentication method for users under 13.Not scored: The duty to use LocalAuthentication rather than ARKit or other facial recognition technology where possible, which binds every app regardless of user age.
-
2.5.18Binds every app regardless of audienceScored: Only the prohibition on targeted or behavioral advertising based on data from kids.Not scored: Confining display ads to the main app binary, matching ads to the app’s age rating, interstitial-ad conduct, close and skip buttons, and the route for users to report inappropriate ads. All bind every app.
-
5.1.1Binds every app regardless of audienceScored: Only (i), and only through the incorporation extension above, because Guideline 5.1.4(b) cannot otherwise be evidenced.Not scored: (ii) through (x). These are Apple’s general privacy duties and bind every app whatever its audience. Note (x) names kids and is still out: it cross-references limits scored here at 1.3 and 5.1.4 rather than creating a new duty.
-
5.1.3Binds every app regardless of audienceScored: Only (iii)’s minors branch: parent or guardian consent where a participant in health-related human subject research is a minor.Not scored: (i), (ii), (iv), and the adult-consent duty in (iii). Also the limits on using health and fitness data for advertising or data mining, the prohibition on writing false data into HealthKit or storing personal health information in iCloud, and the independent ethics review board requirement. All bind every health research app regardless of participant age.
The near misses
Each of these mentions children somewhere and is still out. They are the calls most worth checking first, which is why they are named rather than absorbed into the count above.
-
1.1.4Triggered by something other than serving a childHuman trafficking and exploitationNot child-specific on its face. The duty is owed whoever the victim is.
-
1.2Triggered by something other than serving a childUser-generated content, bullying and abusive usersGeneral, and triggered by hosting user-generated content rather than by a child.
-
1.5Binds every app regardless of audienceDeveloper contact informationApple says it is “particularly important for apps that may be used in the classroom”. Classroom use is emphasis, not a trigger; the duty is identical for every app.
-
2.3.6Binds every app regardless of audienceAnswer the age-rating questions honestlyThe closest call in the document. Excluded because its trigger is submitting ANY app, not serving a child: every developer owes it identically. The Kids-Category-triggered age duty is a different one and IS scored, at 1.3/age-band.
-
2.5.2Triggered by something other than serving a childEducational apps downloading executable codeTriggered by downloading code in a teaching app. Students are not necessarily minors.
-
3.1.3Triggered by something other than serving a childPayment-method eligibility, including classroom and family salesNames “students”, “classroom management tools” and “family sales”, so it reads as child-adjacent. Eligibility for the alternative payment methods turns on the business model an app operates, not on whether a child uses it, and an app serving no children can meet every condition in it.
-
4.1Triggered by something other than serving a childCopycatsMatched a token scan on “minor changes” — the adjective, not a person. There is no child duty in Copycats at all.
-
4.7.1Points at a duty scored elsewhere hereMini apps and games must follow the privacy guidelinesTriggered by offering mini apps or games, with “personal data from kids” only as a parenthetical example. The duty it points at is Guideline 5.1, so scoring it would double-count.
-
4.10Triggered by something other than serving a childMonetizing built-in capabilitiesMatched only because Section 5’s preamble (“exploitation of children”) follows it in the page text. A preamble is not a numbered duty.
-
5.1.2Binds every app regardless of audienceData use and sharing, including ClassKitGeneral privacy duties with no child trigger. Excluding this while scoring all of 5.1.1 would have been incoherent, which is what forced 5.1.1 down to (i) alone.
-
5.4Permits rather than requiresVPN appsParental-control providers “may also use” NEVPNManager. A permission conditioned on being a parental-control app, not a duty owed to a child.
-
5.5Permits rather than requiresMobile device managementParental-control companies are one of the limited categories allowed to offer MDM. Eligibility, not a child-triggered duty.
Out entirely, by number
Apple's five guideline sections, and every guideline in each that places no child-triggered duty on a developer.
1. Safety 17
1.11.1.11.1.21.1.31.1.41.1.51.1.61.1.71.21.41.4.11.4.21.4.41.4.51.51.61.7
2. Performance 38
2.12.22.32.3.12.3.22.3.32.3.42.3.52.3.62.3.72.3.92.3.102.3.112.3.122.3.132.42.4.12.4.22.4.32.4.42.4.52.52.5.12.5.22.5.32.5.42.5.52.5.62.5.72.5.82.5.92.5.102.5.112.5.122.5.142.5.152.5.162.5.17
3. Business 9
3.13.1.13.1.23.1.33.1.43.1.53.23.2.13.2.2
4. Design 30
4.14.24.2.14.2.24.2.34.2.44.2.54.2.64.2.74.34.44.4.14.4.24.4.34.54.5.14.5.24.5.34.5.44.5.54.5.64.64.74.7.14.7.24.7.34.7.44.84.94.10
5. Legal 21
5.15.1.25.1.55.25.2.15.2.25.2.35.2.45.2.55.35.3.15.3.25.3.35.3.45.45.55.65.6.15.6.25.6.35.6.4
Where the inventory came from
Think one of these belongs in scope? That is the point of publishing it, so tell us which line. The full framework is at Apple App Store Kids Category.