App Submission Materials Checklist
Compare Apple and Google account, signing, privacy, and deletion requirements, then map submission materials to client, delivery-team, and platform responsibilities.
For a commercial app, the client should register and retain the Apple and Google developer accounts. Before engineering begins, confirm the legal entity, revenue model, data practices, and launch markets. Before submission, assemble store assets, privacy declarations, reviewer access, and sector qualifications as one consistent evidence set.
Wavesteam handles implementation and submission support within scope. The client remains responsible for entity authenticity, operating qualifications, business rules, and approval of final legal text. Apple and Google make the review decision; no developer can guarantee approval.
Key platform differences
| Item | Apple App Store | Google Play |
|---|---|---|
| Commercial account | Organization membership, normally renewed annually | Organization developer account with a one-time registration fee |
| App identity | Unique Bundle ID and Apple signing configuration | Unique package name, Play App Signing, and Android App Bundle |
| Privacy disclosure | App Privacy plus a privacy-policy URL | Data safety plus a privacy-policy URL |
| Reviewer access | App Review Information, test account, contact, and review notes | App access instructions and persistent access to restricted functions |
| Account deletion | An app that creates accounts should let users initiate deletion in the app | An app that creates accounts generally needs in-app and web deletion paths |
| Digital purchases | In-App Purchase rules may apply | Google Play Billing rules may apply |
Fees, verification, testing, and disclosure requirements vary by account type, region, and policy date. Check the current console before budgeting or scheduling.
Client preparation
- own the organization developer accounts, payment methods, and internal account holder;
- provide consistent legal name, address, phone, authorized representative, website, domain email, support contact, and any required D-U-N-S record;
- approve app names, positioning, target users, brand assets, marketing copy, copyright statement, regions, devices, and release method;
- explain actual collection, use, retention, sharing, deletion, and user-rights rules, then arrange legal review of policies;
- confirm whether purchases are digital, physical, subscription, marketplace, or offline services;
- supply valid industry licenses and governance facts for medical, financial, children, news, gambling, UGC, or other sensitive areas;
- provide a durable reviewer identity and authorized test data;
- join business acceptance and respond to platform questions about operating facts.
Wavesteam preparation
- check account type and consistency of entity fields;
- create and manage the Bundle ID or package name, signing, versions, and production builds under client authorization;
- inventory SDKs, permissions, and technical data flows for privacy declarations;
- implement policy and account-deletion entry points;
- organize store metadata, screenshots, icons, and feature graphics within scope;
- configure reviewer access, explain non-obvious functions, and test the full review path;
- test functionality, compatibility, weak networks, permissions, push, purchases, crashes, upgrade, and deletion;
- submit, diagnose technical rejections, revise approved scope, and support release;
- hand over accounts, builds, records, and ongoing policy obligations.
Submission readiness gate
The package is ready only when a client business owner has completed the main flow on a real device; product behavior, privacy text, SDK inventory, and store declarations agree; reviewer access and backend data will remain available; screenshots and copy match the current build; and required qualifications have been checked for every target market.
Do not display unreleased functions, use temporary credentials that expire during review, borrow a mismatched license, or answer privacy forms from assumptions. A policy URL alone does not prove that runtime behavior is compliant.
Official verification
- Apple Developer membership comparison
- Apple App Review Guidelines
- Google Play Console account setup
- Google Play account deletion requirements
Review these sources and the actual console fields for every release. Platform policy can change after this guide is published.
Platform policies change over time. Follow the latest requirements shown in Apple Developer, App Store Connect, and Google Play Console.