You built the Instagram or Facebook integration. It works on your own account. You submitted for review, waited, and got a rejection with a sentence that could mean anything. Then you did it again. Our own app was rejected twice before it was approved, so this is not a list from the documentation. It is the list of what was actually wrong each time we have unblocked a founder since.
1. The screencast does not show the permission being used
This is the most common reason and the easiest to miss. Reviewers need to see the login, the consent screen with the exact permission listed, and then the feature that uses the data, in one recording. A video of the finished feature with the user already logged in fails. A video that shows the login but ends before the feature does anything fails. Record it end to end on a real phone or a browser at normal speed, and narrate or subtitle what each screen is doing.
2. The reviewer could not log in
Meta reviewers test from their own environment. If your app needs an account, give them one in the submission notes, with a password that does not expire and no two-factor step. If the feature only appears after onboarding, walk them to it in the notes: which menu, which button. If your staging site is behind an allowlist or a VPN, they will never see it and the rejection will say the feature could not be reproduced.
3. You asked for more permissions than the feature needs
Each permission is reviewed on its own. Requesting instagram_manage_comments because you might add a comments feature later gets the whole submission rejected, because the screencast cannot show a feature that does not exist yet. Submit only the permissions your current build calls, and add the rest in a later review when the feature is real.
4. The privacy policy or data deletion URL is missing or generic
Both URLs must be public, must load without a login, and must actually describe what your app does with Meta data. A template that never mentions Facebook or Instagram counts as missing. The data deletion page needs to tell a user how to delete their data, or you need the deletion callback wired so Meta can trigger it. Reviewers open these links.
5. Business verification is not finished
Advanced access to most Instagram and Facebook permissions requires a verified business behind the app. If verification is pending, the review can sit or fail without saying so. Start verification before you submit, and make sure the legal name on the documents matches the business name on the app.
6. The app is in development mode or the feature is behind a flag
If the reviewer's test account is not a tester on the app, development mode blocks them. If the feature is behind a launch flag that is off in production, they see nothing. Turn the feature on for the review window, or give the test account the role it needs.
7. The use case description reads like marketing
The text field for each permission is read by a person. It should say what the user does, what data the app reads or writes, and what the user sees as a result, in that order. Our approved wording for publishing posts was three sentences. The rejected version was a paragraph about the product vision.
Before you resubmit
- Re-record the screencast: login, consent screen, feature, result. One take.
- Put working test credentials and a click path in the notes.
- Remove every permission the current build does not call.
- Open your privacy and data deletion URLs in a private window and read them as a reviewer would.
- Check business verification status and the app mode.
Each rejection costs you a review cycle, and the cycles are the part you cannot speed up. If you would rather hand this over, the Platform Approval Unblocker is a fixed-price package: we take the app through review for you, and the price is on the pricing page before you talk to anyone.
