Get App Privacy, age rating and compliance right with Codex
Your privacy manifests already say what the app and its SDKs collect. Codex reads them, MetaRun turns them into the exact App Privacy answers App Store Connect asks for, and the age rating questionnaire and export compliance go through previews.
Setup checked October 2026 against Codex MCP docs, non-interactive mode
Connect Codex once
01 · Add the server
Codex sees that MetaRun offers sign-in and starts it straight away, in your browser. Pick read-only or read and change.
codex mcp add metarun --url https://metarun.dev/api/mcp02 · Sign in again later
If the sign-in expires or you disconnected it in MetaRun's settings. --no-browser prints the link instead, for SSH sessions.
codex mcp login metarun03 · Or edit ~/.codex/config.toml
The Codex CLI, the IDE extension and Codex in the ChatGPT desktop app read the same file, so one entry covers all three.
[mcp_servers.metarun]
url = "https://metarun.dev/api/mcp"Prefer a personal access token (scripts, CI)?
Add the server with a token
Mint a personal access token in MetaRun under Settings, MCP. It's shown once and can be revoked any time. Codex reads it from the environment variable you name.
export METARUN_TOKEN="mr_pat_..."
codex mcp add metarun --url https://metarun.dev/api/mcp --bearer-token-env-var METARUN_TOKENOr in config.toml
[mcp_servers.metarun]
url = "https://metarun.dev/api/mcp"
bearer_token_env_var = "METARUN_TOKEN"What Codex handles here
App Privacy is the questionnaire behind your App Store privacy label: 35 data types, six purposes, linked or not, tracking or not, for your code and every SDK you ship. Getting it wrong is a common rejection, and Apple's API can't read or write it.
A coding agent has the input App Privacy needs: your PrivacyInfo.xcprivacy and the ones inside each Swift package or pod. MetaRun maps them one to one onto App Store Connect's answers and flags what App Review rejects. The age rating and export compliance do have an API, and go through previews.
Before you start
- Your app's PrivacyInfo.xcprivacy and each SDK's.
- Access to App Store Connect in a browser, to enter the App Privacy answers.
- The age rating questionnaire's facts: user content, web access, purchases.
How it runs
- 01
Collect the manifests
Codex finds your app's PrivacyInfo.xcprivacy and each SDK's: Swift packages under DerivedData's SourcePackages checkouts, CocoaPods under Pods.
- 02
Build the answers
MetaRun merges them strictest-wins and returns every data type to tick, whether it's linked to the user or used for tracking, its purposes, and how the label will read.
- 03
Fix what review would reject
Findings name the problems App Review flags: unknown keys, a data type with no purpose, tracking declared with nothing marked for tracking, missing tracking domains.
- 04
Enter and publish
Because App Privacy has no API, you enter the answers in App Store Connect; MetaRun returns the steps and a link to the right page. Age rating and compliance apply through previews.
An example session in Codex
Find every PrivacyInfo.xcprivacy in this repo and in DerivedData's SourcePackages, build our App Privacy answers, and list anything App Review would reject.
- apple_build_privacy_answersAnswers built from four manifests, with one finding: an SDK declares tracking without a tracking domain.
- apple_get_age_rating_declarationThree age rating questions were never answered.
- apple_preview_set_age_ratingPreview: your answers plus the three unanswered questions, listed so you can see them.
- Codex asks before running apple_apply_set_age_rating. You read the preview above and approve.
- apple_apply_set_age_ratingApplied. Apple derives the rating from the answers.
Illustrative: your apps, versions and numbers will differ. The tool names and their order are real.
The MetaRun tools Codex calls
| Tool | What it does |
|---|---|
| apple_build_privacy_answersread | Turns PrivacyInfo.xcprivacy files into App Privacy answers, with findings App Review rejects. |
| apple_get_age_rating_declarationread | The age rating questionnaire as answered now. |
| apple_preview_set_age_ratingpreview + apply | Answer or change the questionnaire, and overrides. |
| apple_list_encryption_declarationsread | Existing export compliance declarations. |
| apple_preview_declare_build_encryptionpreview + apply | Answer export compliance for a build. |
| apple_preview_set_content_rightspreview + apply | Declare whether the app uses third-party content. |
| apple_list_accessibility_declarationsread | Accessibility Nutrition Labels per device family. |
| apple_preview_set_accessibility_declarationpreview + apply | Declare which accessibility features the app supports. |
Each preview has an apply twin (the same name with apply instead of preview) that only runs with the confirm token from a fresh preview, and refuses if App Store Connect changed in between. MetaRun tools save to your MetaRun workspace only (studio projects, tracked keywords), never to Apple.
What Apple enforces, and how MetaRun handles it
App Privacy has no API
There's no App Store Connect API endpoint for App Privacy at all. MetaRun builds the answers and the label; publishing them is done in App Store Connect.
Unanswered isn't the same as No
Apple stores an unanswered age rating question as empty, not No. An override sent on an empty questionnaire comes back as a server error, so MetaRun stages every unanswered question alongside your edits and lists them for you to see.
Korea's override needs the right category
Apple only accepts a Korea age rating override for apps in the Games or Entertainment category. The preview warns before the attempt instead of letting Apple refuse it.
Compliance declarations are permanent
An export compliance declaration can't be withdrawn once assigned to a build. Setting ITSAppUsesNonExemptEncryption in Info.plist avoids the question for future builds.
What to ask Codex
- Ask Codex: Find every PrivacyInfo.xcprivacy in this repo and in DerivedData's SourcePackages, build our App Privacy answers, and list anything App Review would reject.
- Ask Codex: Our analytics SDK isn't declaring a tracking domain. Check its manifest and tell me what the label will say.
- Ask Codex: Walk me through the age rating questionnaire for com.example.app and stage the answers.
Run it from a script with Codex
codex exec runs one request without an interactive session and with its approval policy set to never. MetaRun's reads and previews still run, because they're marked read-only; anything that would ask is refused.
Read-only check, safe to schedule
codex exec "Build the App Privacy answers from the PrivacyInfo.xcprivacy files in this repository and list every finding App Review would reject. Read only."Applies are refused in codex exec by design. Don't set MetaRun's approval mode to approve just to make them pass; keep App Store changes in an interactive session.
How Codex asks before a change
Codex decides per tool from the hints MetaRun sends with each one. In its default mode it runs tools marked read-only, which covers MetaRun's reads and previews, and asks before the rest, which covers every apply. You can change that per server with default_tools_approval_mode, or per tool with tools.<name>.approval_mode in config.toml; keep the apply tools on prompt.
Frequently asked questions
Can Codex fill in App Privacy for me?
It can do all the thinking: Codex reads the manifests and MetaRun produces the exact answers and the label. The last step, entering them in App Store Connect, is manual because Apple offers no API for App Privacy.
Which manifests should it read?
Your app's own PrivacyInfo.xcprivacy and every SDK's: Swift packages under DerivedData/<project>/SourcePackages/checkouts, CocoaPods under Pods. App Privacy covers everything the app links.
Can it set the age rating?
Yes. The questionnaire has an API, so Codex reads it, stages your answers through a preview, and applies on your approval.
What about export compliance?
Per build, via apple_preview_declare_build_encryption. It's permanent for that build, so the preview says so before you approve.
How do I connect Codex to App Store Connect?
Run codex mcp add metarun --url https://metarun.dev/api/mcp; Codex detects MetaRun's sign-in and opens it in your browser. After that, ask for "app privacy and compliance" in plain words and Codex picks the MetaRun tools.
Does Codex see my App Store Connect key?
No. Your App Store Connect API key stays envelope-encrypted on MetaRun's servers and is decrypted per request. Codex holds a MetaRun token that you can revoke in Settings at any time.
More with Codex
Codex
Submit for review
Attach the build, clear export compliance, run the readiness sweep, submit.
OpenCodex
TestFlight
Hand builds to tester groups, write What to Test, and read crash feedback.
OpenCodex
Subscriptions and IAPs
Create subscription groups, subscriptions and in-app purchases with copy and prices.
OpenCodex
Localize your listing
Name, subtitle, keywords and description in every App Store language, limits checked.
OpenApp Privacy and compliance with another agent
In depth: App Store Connect MCP server
Agent access
14-day free trial with agent access. No credit card. Your Apple key stays encrypted on MetaRun.