> They use it to apply many security and privacy policies!
Have you read the guidelines? Many words requiring you to use and not discourage users from using Apple's in-app purchasing system (which they get a large cut of), prohibiting you from trying to compete with the App Store or similar, prohibiting app-alternatives they don't control (like remote desktop into a cloud server), requiring "Sign in with Apple" if you use another third party sign in service and that sort of thing.
There is a privacy section, but the dirty secret is that they have very little power to enforce it against premeditated abuses. Companies add a feature to their app that gives them a pretext for uploading your data to their servers, and then there is no way for the user or Apple to verify what happens to it from there or determine actual compliance with the privacy policy.
So the policies with a compliance enforcement mechanism are the ones that benefit Apple and the ones that are supposed to benefit users in practice don't have one.
> Difficult to figure out how to actually do this, especially so without a crazy UX.
Actually not so hard in that specific case. They could run the app and not sign in with a Facebook account, and if it tries to contact Facebook servers anyway, reject it.
> They should figure out the default apps thing. Though I don't know what you'd need for SMS, there's not much system integration there besides Siri (which I think supports plugins) and maybe sms: links?
They prohibit it on purpose. Signal isn't allowed to send and receive SMS on iOS:
https://support.signal.org/hc/en-us/articles/360007321171-Ca...
> Apple does not allow other apps to replace the default SMS/messaging app.
The "Firefox" on iOS isn't even actually Firefox, it's required to use Apple's browser engine.