Which accounts and qualifications should a client prepare before an app release?
Choose the release channels, operating entity, actual functions, and data handling before building the evidence list. There is no universal submission pack for every app, mini-program, and store. Wavesteam separates evidence only the client's legal entity can provide from technical material the delivery team can produce, then checks each platform's current console requirements.
The client controls developer accounts, administrators, MFA, genuine entity evidence, contacts, and sector qualifications. Wavesteam can produce builds, screenshots, release notes, test accounts, SDK registers, and reviewer instructions. Privacy policies, user terms, and platform data declarations need both sides: engineering identifies actual code behavior; the client confirms purpose, retention, recipients, and lawful operation.
When planning milestones, resources, and acceptance, also compare How long does a custom app usually take to reach its first release? and Can Wavesteam help register Apple, Google Play, and WeChat developer accounts?; the linked guidance adds context that should be considered in the same decision.
| Material | Examples | Primary owner | Verify before submission |
|---|---|---|---|
| Account and entity | Developer account, legal entity, administrator, payment | Client | Consistent names, ownership, successful verification, revocable roles |
| Product and review | Package, version, icon, screenshots, listing, rating, test path | Wavesteam drafts; client approves | Matches the submitted build; reviewer can reach restricted functions |
| Data and privacy | Policy, permission purpose, data types, SDKs, account deletion | Shared | Statements match code and URLs remain available |
| Sector and business | Category, payment, content, health, education evidence | Client and specialist | Triggered by real function and region; filing is not confused with licence |
Apple's App Privacy guidance requires accurate disclosure of the developer's and third-party code's data collection and purpose, plus a privacy-policy URL. Google Play's review preparation and Data safety guidance likewise covers policy, advertising, restricted access, audience, sensitive permissions, ratings, and SDK behavior. Copying another app's policy cannot describe the submitted build.
For internet information services offered in mainland China, verify operator and network filing under MIIT's mobile-app filing notice and filing system. App filing, website ICP filing, a value-added telecom licence, and public-security internet filing are different. Whether a commercial or sector licence applies depends on service, charging, entity, and region and needs the client's professional confirmation.
For WeChat, choose the category that matches actual code, pages, payments, and operation under the current service-category qualifications. Domestic Android stores may have separate copyright, filing, privacy, and sector portals, so use the target console rather than assuming one approval transfers.
Wavesteam maintains a version-specific evidence table with platform, owner, deadline, console status, and file link. Before submission, scan the actual build for permissions and SDKs, reconcile it with policy and declarations, and test registration, login, purchase, and account deletion using a non-admin account. Provide executable review instructions for login, hardware, or region-limited functions.
Acceptance means required fields are complete, claims match the package, review access works, the client can independently manage the developer account, and the submitted version and response are retained. The platform still decides approval and timing; complete evidence reduces avoidable rejection but does not guarantee acceptance.