Store playbook
What the stores actually require.
Current as of 2026. Use this as the source of truth while you talk an app into shape. Each project also gets a live checklist you can tick off.
The honest split
Slipway designs the product, screens, store copy, privacy language, and submission sequence. Apple and Google review a signed binary. A developer — you, a contractor, or a wrap of a web app with Capacitor / Flutter / React Native — still has to produce an .ipa and an .aab. That is not a limitation of this studio; it is how the stores work.
Side by side
| Gate | Apple | |
|---|---|---|
| Developer account | $99 / year | $25 one-time + identity check |
| App name | 30 characters | 30 characters |
| Short pitch | Subtitle 30 · promo 170 | Short description 80 |
| Description | 4,000 | 4,000 |
| Icon | 1024×1024 PNG, no alpha | 512×512 PNG with alpha |
| Hero graphic | None (screenshots do the work) | Feature graphic 1024×500, required |
| Screenshots | Min 3 at 6.9" (1320×2868) | Min 2 phone shots |
| Privacy | Policy URL + nutrition labels + manifest | Policy URL + Data safety form |
| Target platform | Current iOS SDK | API 36 from 31 Aug 2026 |
| First-time extra | TestFlight pass recommended | Often 12 testers × 14 days closed test |
Apple, in order
1. Product spec is complete
Name, audience, screens, MVP features, and monetization are written down.
2. Store listings are drafted
Apple and Google copy fits character limits and matches the product you actually plan to ship.
3. Core screens are designed
Every primary user flow has a named screen with a clear action.
4. Enroll in the Apple Developer Program
Company or individual enrollment, currently $99 USD per year. Identity verification required. Use a D-U-N-S number for an organization.
5. Create the app record in App Store Connect
New app, bundle ID, SKU, primary language, and user access.
6. Publish a privacy policy URL
Public HTTPS page that returns HTML (not a PDF, not a logged-in Google Doc). Link it in both store consoles and inside the app.
7. Complete App Privacy nutrition labels
Declare data types, purposes, and tracking for your code and every third-party SDK.
8. Ship a PrivacyInfo.xcprivacy manifest
Required in the app binary and for third-party SDKs since May 2024.
9. In-app account deletion (if you have accounts)
Users who can create an account must be able to delete it from inside the app, not only by emailing support.
10. Offer Sign in with Apple (if you offer other logins)
If the app has third-party or social login, Sign in with Apple is required and must be equivalent.
11. App Store icon 1024 × 1024
PNG, no transparency, no rounded corners (Apple applies the mask), no alpha.
12. iPhone 6.9" screenshots (min 3)
Master size 1320 × 2868 (or 1290 × 2796 / 1260 × 2736). Apple scales down to smaller iPhone shelves. Actual app UI, no mock marketing frames, no unshipped features.
13. iPad 13" screenshots if you ship iPad
2064 × 2752 (or 2048 × 2732), minimum 3.
14. Name, subtitle, keywords, description
Name 30, subtitle 30, keywords 100 characters (comma-separated, no spaces after commas is best practice), description 4000, promotional text 170.
15. Age rating questionnaire
Complete every question, including the 2026 social-media capability items. Wrong answers delay review.
16. Use StoreKit for digital goods
Subscriptions, unlocks, and in-app currency must go through Apple IAP. Physical goods and real-world services may use other processors.
17. Support URL and review notes
A working support page (Guideline 1.5 on Apple). If the app has accounts, include a demo login in review notes.
18. Export compliance / encryption
Most HTTPS-only apps qualify for the exemption. Answer the questionnaire honestly.
19. Produce store binaries
iOS: signed .ipa via Xcode or a cloud build (EAS, Codemagic). Android: Play-signed AAB, not an APK, targeting the current API level. Capacitor / Flutter / React Native / native are all valid if they meet store policy.
20. TestFlight internal pass
Install the build on a real iPhone. Confirm privacy policy link, account deletion, and purchase flows before App Review.
Google, in order
1. Product spec is complete
Name, audience, screens, MVP features, and monetization are written down.
2. Store listings are drafted
Apple and Google copy fits character limits and matches the product you actually plan to ship.
3. Core screens are designed
Every primary user flow has a named screen with a clear action.
4. Create a Google Play Console account
One-time $25 USD registration. Complete identity verification. Organization accounts need a D-U-N-S number.
5. Create the app in Play Console
Default language, app or game, free or paid, and a package name you will not change.
6. Run closed testing if Play requires it
New personal Play accounts typically must run a closed test with at least 12 opted-in testers for 14 days before production. Confirm the current Play Console gate for your account type.
7. Publish a privacy policy URL
Public HTTPS page that returns HTML (not a PDF, not a logged-in Google Doc). Link it in both store consoles and inside the app.
8. Complete the Data safety form
Required on closed, open, and production tracks — even if you collect nothing.
9. Play icon 512 × 512
32-bit PNG with alpha, max 1 MB. Full square; Play applies a 30% radius mask. No badge text.
10. Feature graphic 1024 × 500
JPEG or 24-bit PNG, no alpha. Keep the focal point centered — the edges crop on some surfaces.
11. Phone screenshots (min 2, max 8)
JPEG or 24-bit PNG, each side 320–3840 px, aspect between 1:2 and 2:1. Show the real app.
12. Title, short description, full description
Title 30, short description 80, full description 4000. No misleading ranking or price claims.
13. IARC content rating
Fill the questionnaire in Play Console. Do this before production rollout.
14. Support URL and review notes
A working support page (Guideline 1.5 on Apple). If the app has accounts, include a demo login in review notes.
15. Target API 36 (Android 16) for new uploads
As of 31 August 2026, new apps and updates must target API 36. Wear / Auto have separate floors.
16. Produce store binaries
iOS: signed .ipa via Xcode or a cloud build (EAS, Codemagic). Android: Play-signed AAB, not an APK, targeting the current API level. Capacitor / Flutter / React Native / native are all valid if they meet store policy.
Rejection patterns that eat first-timers
- Screenshots of mockups or features that are not in the binary.
- Digital subscriptions billed outside StoreKit (Apple) or Play Billing.
- Accounts with no in-app deletion, or a “email us” deletion flow.
- Privacy policy on a Google Doc that requires a login.
- New Play personal accounts skipping the 12-tester closed test.
- Broken support URL, or no demo login in review notes.