App Store & Google Play Legal Requirements: 2026 Guide

Many teams treat app store submission as a technical step. Build the app, upload the binary, wait for approval. Then the rejection arrives, and it has nothing to do with code. The privacy policy doesn’t match what the SDKs collect. A wallet was submitted under an individual account. An exchange app went live in a country where it holds no license. The reviewer asked for a legal document nobody prepared.
Apple and Google publish their rules, and both enforce them. What the rules don’t tell you is which ones carry legal weight and which ones depend on your business model. This guide covers the listing process on both platforms as of September 2026, the legal requirements behind it, and the points where legal help changes the outcome.
Policies on both platforms change often. Every requirement below is cited to the platform’s own documentation and was checked on the retrieval date shown. Check the current text before you submit.
Table of contents
Quick Answer
-
Both platforms verify who you are before they review your app. Organizations need a D-U-N-S Number, and some app categories can only be published from an organization account.
-
Every app needs a privacy policy on both platforms, including apps that collect no data at all.
-
Crypto exchanges, real-money gambling, and financial apps are approved on licensing, not on design. The license has to exist in every place the app is offered.
-
An Apple appeal is limited to one per submission and has to give specific reasons. Google will reinstate an app if it finds an error, but its own documentation points developers to legal counsel for legal questions.
-
Legal review is easiest before submission. After a rejection or removal, the same work happens under time pressure.
Two Platforms, Two Gatekeepers
The two stores ask for similar things in different ways. The table below compares the requirements that matter most from a legal point of view.
| Apple App Store | Google Play | |
|---|---|---|
| Who can enroll | Individuals or legal entities. Organizations must provide a D-U-N-S Number. Apple does not accept DBAs, fictitious businesses, trade names, or branches. | Personal or organization accounts. Organization accounts require a D-U-N-S Number. |
| Organization account required for | Cryptocurrency wallet apps. | Financial services (including crypto wallets and exchanges), health apps, VPN apps, government apps. |
| Privacy | Privacy policy link in App Store Connect and inside the app. Account deletion inside the app if the app supports account creation. | Data safety form and a privacy policy link for every published app. |
| Pre-launch step | Working demo account or demo mode, live backend, and review notes. | Closed test with at least 12 testers for 14 days (personal accounts created after November 13, 2023). |
| Crypto exchange apps | Only in countries or regions where the app holds licensing and permissions. | Registration or license by jurisdiction, declared in the Financial Features Declaration. |
| Real-money gambling | Licensing in every location where the app is used, geo-restriction, free download. | Separate policy for real-money gambling, games, and contests. |
| Appeals | App Review Board, one appeal per submission. | Appeal through the enforcement notice or the appeal troubleshooter. |
The rest of this guide follows the order of the process: account, privacy, content rights, submission, regulated categories, and what to do when something goes wrong.
Step 1: Set Up the Developer Account Correctly
The account is a legal decision. Apple requires an enrolling organization to be a legal entity that can enter into contracts with it, so the choice of entity matters from the first step.
Apple
Apple lets individuals and organizations enroll. An organization has to be a legal entity that can enter into contracts with Apple, and it has to provide a D-U-N-S Number registered to that entity (Apple Developer: D-U-N-S Number, checked 24.09.2026). Apple does not accept DBAs, fictitious businesses, trade names, or branches. A company that plans to use a trade name as the publisher name needs to check that before enrollment, not after the first rejection.
The account type also decides what you can publish. Under Guideline 3.1.5(i), wallet apps that facilitate virtual currency storage must be offered by developers enrolled as an organization (App Review Guidelines, checked 24.09.2026). An individual account cannot carry that app.
Apple also asks every developer to declare a trader status under the EU Digital Services Act. Developers assess for themselves whether they act as a trader under EU law. If they do, contact details are shown on the App Store product page. Organizations show a phone number, an email address, and the address taken from the D-U-N-S record. Individuals show an address or P.O. Box, a phone number, and an email address. A developer who is not a trader must accept that EU consumers are told consumer protection rights won’t apply to contracts with them (Apple Developer: EU Digital Services Act trader requirements, checked 24.09.2026). Publishing personal contact details on a public product page is a privacy decision as well as a compliance one.
Google Play
Google separates personal and organization accounts. Organization accounts require a D-U-N-S Number, and Google describes that as mandatory for organizations and businesses. An organization account is also mandatory for certain app types: financial services such as banking, loans, stock trading, investment funds, cryptocurrency software wallets, and cryptocurrency exchanges; health apps in the Medical and Human Subjects Research categories; VPN apps that use the VpnService class; and apps developed by or for a government agency (Play Console Help: choose a developer account type, checked 24.09.2026).
Personal accounts created after November 13, 2023 face an extra gate before launch. They must run a closed test with at least 12 testers who stay opted in continuously for at least 14 days, and only then can they apply for production access. Google says it typically completes that review within seven days or less (Play Console Help: app testing requirements for new personal developer accounts, checked 24.09.2026). The launch calendar has to include those 14 days plus review time.
Both platforms use the D-U-N-S Number to verify the organization, so it has to exist before enrollment. Start that process early, and check that the company name and address on the Dun & Bradstreet record are correct and match what you submit.
Step 2: Privacy Policy, Data Disclosures, and Account Deletion
Privacy rules apply to every app on both platforms, and the disclosures have to match what the app really does.
What Apple Requires
Guideline 5.1.1(i) says all apps must include a link to their privacy policy in the App Store Connect metadata field and inside the app in an easily accessible way. The policy has to say what data the app collects, how it collects it, and every use of that data. It has to confirm that any third party receiving user data, including analytics tools, advertising networks, and third-party SDKs, provides the same or equal protection. And it has to explain retention and deletion, and how users can revoke consent or request deletion (App Review Guidelines, checked 24.09.2026).
If the app supports account creation, Apple also requires account deletion inside the app under 5.1.1(v). Deactivation is not enough.
What Google Requires
Every developer with a published app must complete the Data safety form, including developers whose apps collect no user data. The form needs a link to a privacy policy, added in the App content section of Play Console. Google places the responsibility on the developer alone: “You alone are responsible for making complete and accurate declarations in your app’s store listing.” If Google finds a discrepancy between the declaration and the app’s behavior, it may take enforcement action. Apps that don’t become compliant face blocked updates or removal from Google Play (Play Console Help: Data safety section, checked 24.09.2026).
Where This Goes Wrong
Problems tend to come from a mismatch between what the documents say and what the app does. For example:
-
The privacy policy describes a simple analytics setup, and the app ships with three advertising SDKs.
-
The Data safety form says no data is shared, and a third-party SDK sends device identifiers to its own servers.
-
The policy promises deletion on request, and the app has no mechanism to do it.
-
The policy was copied from a template written for a different product.
Each of these is a legal problem in addition to a review problem, because the policy is also a statement to users and regulators. A privacy policy for an app store listing should be written after a data-flow review, not before it. Our work on privacy policies, terms of service, and EULAs for apps follows that order.
Step 3: Content, Trademarks, and Third-Party Rights
Guideline 5.2.1 says an app may only include content that the developer created or is licensed to use, and that apps should be submitted by the person or legal entity that owns or has licensed the intellectual property and other relevant rights. It also bars misleading or copycat names, and third-party trademarks, copyrighted works, and patented ideas used without permission (App Review Guidelines, checked 24.09.2026).
Three situations are worth checking before you submit:
-
The name. An app name or keyword field that uses someone else’s trademark is a rejection risk and a takedown risk. Clearing the name first is easier than rebranding after launch.
-
Third-party services. Under 5.2.2, an app that uses or displays content from a third-party service must be specifically permitted to do so under that service’s terms of use, and authorization has to be provided on request. An app built on another platform’s API depends on that platform’s terms.
-
Publisher mismatch. If the developer account belongs to one company and the IP belongs to another, Apple’s rule that the submitting party must own or license the rights applies directly. Agency-built apps and white-label deployments are typical examples.
Step 4: Submit for Review
Apple’s “Before You Submit” checklist is short, and each item is something a reviewer can check. Test for crashes and bugs. Make sure all metadata is complete and accurate. Keep your contact information current. Give App Review full access, which means an active demo account or a fully featured demo mode. Keep backend services live during review. Explain non-obvious features and in-app purchases in the review notes, with supporting documentation where appropriate (App Review Guidelines, checked 24.09.2026).
Two details deserve legal attention. First, Guideline 2.1 allows a built-in demo mode in place of a demo account if you can’t provide one due to legal or security obligations, but only with Apple’s prior approval. That option matters for apps that handle regulated user data. Second, the review notes are the place for supporting documentation on a regulated app, such as a license or a legal opinion, so the reviewer has it without asking.
On timing, Apple states that on average 90% of submissions are reviewed in less than 24 hours (Apple Developer: App Review, checked 24.09.2026). For regulated features, plan for more time. Apple’s gambling guideline tells developers to be prepared for extra time during review.
Regulated Categories: Where Approval Depends on Your Licenses
For some app categories, licensing and legal compliance are conditions of approval, on top of the usual technical checks.
Apple App Store Requirements for Crypto Apps
Apple’s Guideline 3.1.5 sets out five rules for crypto apps (App Review Guidelines, checked 24.09.2026):
-
Wallets. Apps may facilitate virtual currency storage if they are offered by developers enrolled as an organization.
-
Mining. Apps may not mine cryptocurrency on the device. Processing must happen off device, for example in cloud-based mining.
-
Exchanges. Apps may facilitate transactions or transmissions of cryptocurrency on an approved exchange, but only in countries or regions where the app has the appropriate licensing and permissions.
-
ICOs and crypto-securities. Apps facilitating ICOs, cryptocurrency futures trading, and other crypto-securities or quasi-securities trading must come from established banks, securities firms, futures commission merchants, or other approved financial institutions, and must comply with all applicable law.
-
Rewards. Cryptocurrency apps may not offer currency for completing tasks, such as downloading other apps, encouraging other users to download, or posting to social networks.
Google Play Requirements for Crypto Apps
Google now runs its own licensing regime for crypto apps. Its Cryptocurrency Exchanges and Software Wallets policy requires developers to declare that the app is an exchange or software wallet in the Financial Features Declaration under App content. It then requires registration or a license depending on where the app is offered (Play Console Help: cryptocurrency exchanges and software wallets, checked 24.09.2026):
-
United States: registration with FinCEN as a Money Services Business plus state money transmitter registration, or a federal or state bank charter.
-
United Kingdom: registration with the Financial Conduct Authority.
-
Canada: registration with FINTRAC as a money services business.
-
Japan: registration with the Financial Services Agency as a crypto asset exchange provider.
-
European Union: authorization as a crypto-asset service provider under MiCA, with the requirement applying from July 2026.
Non-custodial wallets are outside the scope of that licensing policy. If your targeted location isn’t on Google’s list, you may continue to publish, but you still have to comply with local law. Google’s account-type rules still list cryptocurrency software wallets among the apps that need an organization account.
Both platforms tie approval to a regulatory analysis that comes first. Whether a wallet is custodial, whether a service counts as an exchange, and which licenses apply in each market are legal questions. Answering them after a rejection means resubmitting under time pressure, so for a crypto product the analysis belongs before the first submission. Learn more about our Legal Opinions for exchanges and platform review.
Real-Money Gambling and Games
Apple’s Guideline 5.3 begins with a warning that gaming, gambling, and lotteries are among the most regulated offerings on the App Store, and tells developers to include this functionality only after fully vetting their legal obligations everywhere the app is available. Under 5.3.4, apps that offer real-money gaming such as sports betting, poker, casino games, or horse racing, and lottery apps, must have the necessary licensing and permissions in the locations where the app is used, must be geo-restricted to those locations, and must be free on the App Store. Under 5.3.3, apps may not use in-app purchase to buy credit or currency for real-money gaming (App Review Guidelines, checked 24.09.2026).
Sweepstakes and skill-game mechanics are treated differently from state to state in the US. Apple’s guideline puts that analysis on the developer, so it has to be done before the app is offered anywhere.
User-Generated Content
Guideline 1.2 requires apps with user-generated content or social networking features to include a method for filtering objectionable material, a mechanism to report offensive content with timely responses, the ability to block abusive users, and published contact information. These are product features with legal consequences, and they belong in the terms of service as well as in the app.
When the App Is Rejected or Removed
A rejection is not final, but how you respond matters.
Apple
If an app fails review and you believe Apple misunderstood the concept or functionality, or treated you unfairly in the review, you can submit an appeal to the App Review Board. Apple sets three conditions: provide specific reasons why the app complies with the App Review Guidelines, submit only one appeal per submission that didn’t pass, and respond to any requests for additional information before appealing (Apple Developer: App Review, checked 24.09.2026).
Because there is one appeal per submission, a vague first appeal wastes the only one you have. Apple also allows expedited review for a critical bug fix or an event-related app.
Google says it will reinstate applications if an error was made and the app does not violate the Google Play Program Policies. Developers appeal by following the instructions in the enforcement notification email or by using the appeal troubleshooter Google provides.
The same documentation states that Google cannot provide legal advice and directs developers to legal counsel where needed (Play Console Help: managing policy violations and appeals, checked 24.09.2026).
The platforms enforce their rules, but Google’s own documentation says it cannot advise on the law behind them. An appeal is stronger when it answers the stated objection directly, with the license, the legal analysis, or the corrected policy that the objection called for.
Where Legal Help Changes the Outcome
The work falls into four areas.
-
1. Account and entity structure. Choosing the right legal entity to enroll, dealing with the D-U-N-S process, deciding who owns the IP, and making sure the publisher named in the store matches the entity that holds the rights. It is much easier to choose the right entity at enrollment than to correct the choice later.
-
2. Documents that match the product. A privacy policy built from a data-flow review, terms of service and an EULA that fit how the app works, and consistent Data safety and App Privacy declarations. The documents and the declarations have to say the same thing.
-
3. Regulatory analysis for regulated apps. For crypto, gambling, lending, and other financial features: a written analysis of which licenses or exemptions apply in each target market, and where useful, a legal opinion prepared for submission to platform review. The platforms require the licenses to exist. Working out which ones apply is the developer’s job.
-
4. Rejection appeals and reinstatement. Reading the enforcement notice for the real legal basis, preparing a response that addresses that basis, and correcting the underlying issue so the same problem doesn’t return on the next update.
We also review platform terms of service and advertising policy compliance for Google Ads, X, and Meta, and merchant agreements for platforms such as Shopify and WooCommerce, because an app can depend on the terms of another platform. See our Digital Platform and App Compliance services.
A Pre-Submission Checklist
Before you submit to either store:
-
1. The enrolling entity is the entity that owns or licenses the app’s IP, and its D-U-N-S record matches the legal name and address you submit.
-
2. The account type fits the app category (organization for wallets, financial services, health, VPN, and government apps).
-
3. The privacy policy is live, linked in the store metadata and inside the app, and matches the actual data flows, including every SDK.
-
4. The Data safety form and Apple’s privacy disclosures say the same thing as the policy.
-
5. Account deletion works inside the app if users can create accounts.
-
6. Trademarks in the app name, icon, and keywords are cleared. Third-party services used by the app permit that use.
-
7. Regulated features have their licenses or written legal analysis for every market where the app is offered, and the app blocks access where it is not licensed.
-
8. Review notes explain non-obvious features and attach supporting documents for anything regulated.
-
9. A demo account or approved demo mode works, and the backend is live.
-
10. For a new personal Google Play account, the 12-tester, 14-day closed test is already running.
Frequently Asked Questions
Do I Need a Company to Publish an App?
For most apps, no. Apple enrolls individuals, and Google offers personal accounts. But some categories require an organization: Apple requires it for wallet apps, and Google requires it for financial services apps (including cryptocurrency wallets and exchanges), health apps in certain categories, VPN apps, and government apps.
Do I Need a Privacy Policy If My App Collects No Data?
Yes on Google Play. Google requires a privacy policy link and a completed Data safety form even for apps that collect no user data. Apple’s Guideline 5.1.1(i) requires all apps to include a link to a privacy policy.
Can I Publish a Crypto Wallet or Exchange App?
Yes, if the licensing and account requirements are met. Apple requires an organization account for wallet apps and licensing in each region where an exchange app is offered. Google requires registration or licenses by jurisdiction for exchanges and custodial wallets, and treats non-custodial wallets as outside that licensing policy. Local law applies in either case.
How Many Times Can I Appeal an Apple Rejection?
Apple allows one appeal per submission that didn’t pass review, so the first appeal has to state specific reasons why the app complies with the guidelines.
How Long Does Review Take?
Apple says that on average 90% of submissions are reviewed in less than 24 hours. Google says production access reviews for new personal accounts typically finish within seven days or less, after the closed test requirement is met.
Planning a Listing? Talk to Us Before You Submit
Legal Kornet works with app developers, SaaS teams, and crypto and gaming projects on the legal side of app store listings: entity and account structure, privacy and platform documents, regulatory analysis and legal opinions for regulated apps, and appeals after rejection or removal. If your app touches crypto, payments, gambling, health, or user data at scale, the legal review can set the timeline for the launch.
If you’re preparing a submission, or you’ve already had a rejection, tell us what the app does, where you plan to offer it, and what the platform said. We’ll tell you where the exposure is and what needs to be in place. Learn more about our app store compliance and listing support.



