Store playbook

What the stores actually require.

Current as of 2026. Use this as the source of truth while you talk an app into shape. Each project also gets a live checklist you can tick off.

The honest split

Slipway designs the product, screens, store copy, privacy language, and submission sequence. Apple and Google review a signed binary. A developer — you, a contractor, or a wrap of a web app with Capacitor / Flutter / React Native — still has to produce an .ipa and an .aab. That is not a limitation of this studio; it is how the stores work.

Side by side

GateAppleGoogle
Developer account$99 / year$25 one-time + identity check
App name30 characters30 characters
Short pitchSubtitle 30 · promo 170Short description 80
Description4,0004,000
Icon1024×1024 PNG, no alpha512×512 PNG with alpha
Hero graphicNone (screenshots do the work)Feature graphic 1024×500, required
ScreenshotsMin 3 at 6.9" (1320×2868)Min 2 phone shots
PrivacyPolicy URL + nutrition labels + manifestPolicy URL + Data safety form
Target platformCurrent iOS SDKAPI 36 from 31 Aug 2026
First-time extraTestFlight pass recommendedOften 12 testers × 14 days closed test

Apple, in order

  1. 1. Product spec is complete

    Name, audience, screens, MVP features, and monetization are written down.

  2. 2. Store listings are drafted

    Apple and Google copy fits character limits and matches the product you actually plan to ship.

  3. 3. Core screens are designed

    Every primary user flow has a named screen with a clear action.

  4. 4. Enroll in the Apple Developer Program

    Company or individual enrollment, currently $99 USD per year. Identity verification required. Use a D-U-N-S number for an organization.

  5. 5. Create the app record in App Store Connect

    New app, bundle ID, SKU, primary language, and user access.

  6. 6. Publish a privacy policy URL

    Public HTTPS page that returns HTML (not a PDF, not a logged-in Google Doc). Link it in both store consoles and inside the app.

  7. 7. Complete App Privacy nutrition labels

    Declare data types, purposes, and tracking for your code and every third-party SDK.

  8. 8. Ship a PrivacyInfo.xcprivacy manifest

    Required in the app binary and for third-party SDKs since May 2024.

  9. 9. In-app account deletion (if you have accounts)

    Users who can create an account must be able to delete it from inside the app, not only by emailing support.

  10. 10. Offer Sign in with Apple (if you offer other logins)

    If the app has third-party or social login, Sign in with Apple is required and must be equivalent.

  11. 11. App Store icon 1024 × 1024

    PNG, no transparency, no rounded corners (Apple applies the mask), no alpha.

  12. 12. iPhone 6.9" screenshots (min 3)

    Master size 1320 × 2868 (or 1290 × 2796 / 1260 × 2736). Apple scales down to smaller iPhone shelves. Actual app UI, no mock marketing frames, no unshipped features.

  13. 13. iPad 13" screenshots if you ship iPad

    2064 × 2752 (or 2048 × 2732), minimum 3.

  14. 14. Name, subtitle, keywords, description

    Name 30, subtitle 30, keywords 100 characters (comma-separated, no spaces after commas is best practice), description 4000, promotional text 170.

  15. 15. Age rating questionnaire

    Complete every question, including the 2026 social-media capability items. Wrong answers delay review.

  16. 16. Use StoreKit for digital goods

    Subscriptions, unlocks, and in-app currency must go through Apple IAP. Physical goods and real-world services may use other processors.

  17. 17. Support URL and review notes

    A working support page (Guideline 1.5 on Apple). If the app has accounts, include a demo login in review notes.

  18. 18. Export compliance / encryption

    Most HTTPS-only apps qualify for the exemption. Answer the questionnaire honestly.

  19. 19. Produce store binaries

    iOS: signed .ipa via Xcode or a cloud build (EAS, Codemagic). Android: Play-signed AAB, not an APK, targeting the current API level. Capacitor / Flutter / React Native / native are all valid if they meet store policy.

  20. 20. TestFlight internal pass

    Install the build on a real iPhone. Confirm privacy policy link, account deletion, and purchase flows before App Review.

Google, in order

  1. 1. Product spec is complete

    Name, audience, screens, MVP features, and monetization are written down.

  2. 2. Store listings are drafted

    Apple and Google copy fits character limits and matches the product you actually plan to ship.

  3. 3. Core screens are designed

    Every primary user flow has a named screen with a clear action.

  4. 4. Create a Google Play Console account

    One-time $25 USD registration. Complete identity verification. Organization accounts need a D-U-N-S number.

  5. 5. Create the app in Play Console

    Default language, app or game, free or paid, and a package name you will not change.

  6. 6. Run closed testing if Play requires it

    New personal Play accounts typically must run a closed test with at least 12 opted-in testers for 14 days before production. Confirm the current Play Console gate for your account type.

  7. 7. Publish a privacy policy URL

    Public HTTPS page that returns HTML (not a PDF, not a logged-in Google Doc). Link it in both store consoles and inside the app.

  8. 8. Complete the Data safety form

    Required on closed, open, and production tracks — even if you collect nothing.

  9. 9. Play icon 512 × 512

    32-bit PNG with alpha, max 1 MB. Full square; Play applies a 30% radius mask. No badge text.

  10. 10. Feature graphic 1024 × 500

    JPEG or 24-bit PNG, no alpha. Keep the focal point centered — the edges crop on some surfaces.

  11. 11. Phone screenshots (min 2, max 8)

    JPEG or 24-bit PNG, each side 320–3840 px, aspect between 1:2 and 2:1. Show the real app.

  12. 12. Title, short description, full description

    Title 30, short description 80, full description 4000. No misleading ranking or price claims.

  13. 13. IARC content rating

    Fill the questionnaire in Play Console. Do this before production rollout.

  14. 14. Support URL and review notes

    A working support page (Guideline 1.5 on Apple). If the app has accounts, include a demo login in review notes.

  15. 15. Target API 36 (Android 16) for new uploads

    As of 31 August 2026, new apps and updates must target API 36. Wear / Auto have separate floors.

  16. 16. Produce store binaries

    iOS: signed .ipa via Xcode or a cloud build (EAS, Codemagic). Android: Play-signed AAB, not an APK, targeting the current API level. Capacitor / Flutter / React Native / native are all valid if they meet store policy.

Rejection patterns that eat first-timers

  • Screenshots of mockups or features that are not in the binary.
  • Digital subscriptions billed outside StoreKit (Apple) or Play Billing.
  • Accounts with no in-app deletion, or a “email us” deletion flow.
  • Privacy policy on a Google Doc that requires a login.
  • New Play personal accounts skipping the 12-tester closed test.
  • Broken support URL, or no demo login in review notes.