Your app works, and you are ready to put it in the stores. Before submitting, you still need to test the release build, prepare the listing, and complete each store's account and privacy requirements.
This checklist groups that work into eight phases. Start the account setup early, then work through the build, listing, testing, and submission steps.
If you built with an AI coding tool, the same release checks still apply. Our guide to Apple's review requirements explains the rules that can affect these apps.
Phase 1: Before You Touch the App Stores
Test more than the successful demo. Check what happens when a payment fails, a connection drops, or a user signs in to the wrong account. Convex's production-readiness guide discusses this transition from prototype to release.
Review security and access
Review sign-in, permissions, credentials, dependencies, and the main user tasks. Use the checklist below to organize the work, and get help with areas you cannot confidently assess.
- Protect secrets: keep privileged credentials on the server. Client environment variables may still be bundled into the app. If a secret was exposed, rotate it and review repository history and access.
- Enable Row Level Security (RLS) where your database uses it, and test that users can access only the records they are allowed to see. An audit of apps built with Lovable found 170+ out of 1,645 had completely exposed databases.[3]
- Enforce auth server-side. AI-generated code often checks permissions only on the frontend. Any user with browser dev tools can bypass that. Every API endpoint must verify authentication and authorization independently.
- Add real error handling. Replace generic try/catch blocks with specific error recovery. Log errors to a monitoring service (Sentry, LogRocket) so you know when things break in production.
- Run a security scanner. Tools like Snyk, SonarQube, or the free CISO Vibe Coding Checklist can help find issues; review their findings and test the controls.
Test on Real Devices
Use real devices alongside the simulator. Check that controls are easy to tap, smaller screens stay readable, and the app responds well on older hardware.
Choose devices that represent the audience you plan to support: a small phone, a larger phone, and a tablet if your app supports tablets.
Set Up Version Control & CI
Put the project in version control so you can review and undo changes. Set up automated builds and relevant tests to catch problems before the next release.
Phase 2: Developer Accounts
Create an account for each store you plan to use. Leave time for enrollment, identity checks, and any testing requirements before choosing a launch date.
Apple Developer Program
- Cost: $99 USD/year (recurring).[4]
- What you get: Access to App Store Connect, TestFlight, code signing certificates, provisioning profiles.
- Enrollment: Allow time for account and identity checks.
- Tip: Fee waivers are available for eligible nonprofits and educational institutions.
Google Play Console
- Cost: $25 USD one-time (no annual renewal).[5]
- What you get: Access to Play Console, internal/closed/open testing tracks, store listing management.
- Account security: Complete the identity and account-security checks shown during registration.
Phase 3: Write the store listing
Apple App Store Metadata
| Field | Limit | Tips |
|---|---|---|
| App Name | 30 characters | Use a clear name and a relevant task term where it fits. Apple requires unique names — check availability first. |
| Subtitle | 30 characters | Use a secondary keyword. Don't repeat the app name. |
| Keywords | 100 bytes | Comma-separated, no spaces after commas. Use the space for relevant terms. No duplicates of words in your name/subtitle. |
| Description | 4,000 characters | Not indexed for search on iOS, but critical for conversion. Lead with benefits, not features. |
| Promotional Text | 170 characters | Can be updated without a new app version. Use for time-sensitive messaging. |
Google Play Store Metadata
| Field | Limit | Tips |
|---|---|---|
| App Title | 30 characters | Include your primary keyword. Keep the title readable. |
| Short Description | 80 characters | Shown on the store listing. Make it compelling. This is your elevator pitch. |
| Full Description | 4,000 characters | Google indexes this for search. Use relevant terms naturally. Structure with line breaks. |
Write the listing from the features in your release build. Metadata generation can help you draft the fields; review the wording and check that each field fits.
Phase 4: Screenshots. Your App's First Impression
Use screenshots to show the app's main task and what someone can accomplish with it. Make the first image understandable at the small size people see in search results.
Check the required screenshot sizes
The accepted sizes depend on the store and supported devices. Use Apple's screenshot specifications and Google Play's preview-asset requirements to choose the exports for your app.
Use real app captures with short, readable captions. Device frames are optional. You can arrange the images in the AppDrift screenshot editor; check Free and Pro labels when choosing a template. For examples of how to order the screens, see screenshots that sell.
Phase 5: Privacy & Compliance
Complete the privacy disclosures for both your app and the services it uses.
Apple Requirements
- Privacy policy URL: must be linked in App Store Connect AND accessible from within the app.[6]
- App Privacy Details (“nutrition labels”): disclose all data types collected, how they're used, and whether they're linked to identity.
- App Tracking Transparency: if you track users across apps, you must request permission via the ATT framework.
Google Play Requirements
- Privacy policy: must be linked in Play Console and match what the Data Safety Form declares.[7]
- Data Safety Form: a separate form detailing data collection, usage, and processing. Must be filled out before your app can go live.
- External services: Review what data each AI or other third-party service receives. Complete the disclosures and consent flows that apply to that use.
If you start from a policy template, edit it to match what your app collects and shares. Check that the policy, store disclosures, permissions, and actual app behavior agree.
Phase 6: Testing
iOS. TestFlight
- Upload your build through Xcode or Transporter.
- Internal testing: Up to 100 testers (team members). Check build processing and availability in App Store Connect.
- External testing: Up to 10,000 testers. Requires Apple's Beta App Review.
- Builds expire after 90 days.
- Tip: Get at least 5 external testers to use the app for a full day. They'll find bugs your simulator testing missed.
Android. Testing Tracks
- Internal testing: Up to 100 testers. Check availability in Play Console.
- Check Google's testing rules for new personal developer accounts. Accounts created after November 13, 2023 must meet the applicable closed-test and production-access requirements; currently the documented test requires at least 12 opted-in testers continuously for 14 days.
- Open testing: Optional public beta.
- Plan the closed test. Invite testers early and confirm they stay opted in for the full required period before applying for production access.
Phase 7: Submission
Apple App Store Submission Checklist
- Archive your app in Xcode (Product → Archive).
- Upload to App Store Connect via Xcode or Transporter.
- Fill in all metadata fields (name, subtitle, keywords, description, promotional text).
- Upload screenshots for all required device sizes.
- Set your price and availability (countries, release date).
- Complete the App Privacy Details section.
- Add demo credentials in the App Review Notes field (if login required).
- Select your build and submit for review.
Important (April 2026): Apps must be built with the iOS 26 SDK or later.[8]
Google Play Submission Checklist
- Build your Android App Bundle (.aab format, not APK).
- Upload to Play Console.
- Complete the store listing (title, descriptions, screenshots, feature graphic).
- Fill out the Data Safety Form.
- Complete the content rating questionnaire.
- Set pricing and distribution (countries, devices).
- If new personal account: complete 14-day closed testing with 12+ testers first.
- Submit for review.
Check the Google Play target API requirements for your app type and submission date before creating the final build.
Phase 8: Support the release
After release, watch for crashes, login problems, payment failures, and questions from new users. Keep time available to respond and make fixes.
Immediate Post-Launch Actions
- Monitor crash reports in App Store Connect and Play Console. Prioritize problems that block core tasks.
- Read and respond to reviews. Help users with specific problems and use recurring issues to plan fixes.
- Share your launch in communities where the app answers a relevant need and promotion is allowed.
Plan your next language
Choose another language when there is interest in the market and your product can support those users. Start by reviewing local search terms and deciding which parts of the product need translation.
Metadata translation supports listing drafts in 60+ languages. Have a fluent reviewer check the wording and research local keywords; translate the app interface separately where needed. The global launch guide covers that wider preparation.
Quick Reference: Apple vs. Google Play at a Glance
| Requirement | Apple App Store | Google Play |
|---|---|---|
| Developer Fee | $99/year | $25 one-time |
| App Name Limit | 30 characters | 30 characters |
| Description Limit | 4,000 characters | 4,000 characters |
| Keywords | 100-byte dedicated field | Extracted from description |
| Screenshot Count | 1-10 per device | 2-8 per device |
| Testing | TestFlight (10K external) | Internal / Closed / Open tracks |
| App Format | .ipa via Xcode | .aab (App Bundle) |
| Privacy | Policy + App Privacy Details | Policy + Data Safety Form |
Frequently Asked Questions
How much does it cost to publish an app to the App Store?
Apple charges $99/year for a Developer Program membership. Google Play charges a one-time $25 registration fee. There are no per-app submission fees on either platform. Fee waivers are available from Apple for eligible nonprofits and educational institutions.
How long does App Store review take in 2026?
Review time varies by app, account, and the information reviewers need. Follow the status in your store console and allow time for corrections. New Google personal accounts may also need to complete testing and apply for production access.
Can I publish an app built with Cursor or Lovable?
Yes, but check what the app does at runtime against Apple's review guidelines. Section 2.5.2 restricts downloaded code that changes features and includes a limited educational exception. Section 4.7 allows specified software experiences under additional rules. Remote content and executable code need different treatment; the right approach depends on your architecture.
What are the most common reasons for app rejection?
Check for incomplete screens, placeholder text, crashes, inaccurate privacy disclosures, and missing reviewer login details. Also review Apple's minimum-functionality and spam rules in sections 4.2 and 4.3. These are useful checks, rather than a ranked list of rejection causes.
Do I need a privacy policy for my app?
Yes. Apple requires a privacy policy in App Store Connect and within the app, along with App Privacy Details. Google Play requires a privacy policy and a separate Data Safety form. Make sure each describes your app's actual data practices.
Continue Reading
- Why Apple Is Rejecting Vibe-Coded Apps (And How to Get Approved). Understand which guidelines Apple enforces and how to stay compliant.
- How to Publish an App Built with Cursor, Lovable, or Bolt. Tool-specific workflows for each vibe coding platform.
- Complete Guide to Publishing on App Store & Google Play. The full publishing reference for both stores.



