TidyDiscover
public
I

Shared Tidy list

iOS App Store Readiness

Imported from the uploaded iOS App Store Readiness Handbook. Use this to keep track of all necessary tasks to get your iOS app in the App Store.

TOTidy Official
Open in Tidy
112 items10 groups7 views
0 of 112 done

Account, legal, access, and business setup

0/10
  • Choose the seller/legal owner.

    Decide individual vs. organization before creating the app record.

  • Create or verify the Account Holder Apple Account with two-factor authentication enabled.
  • If enrolling as an organization, verify legal entity name, D-U-N-S Number, authority to bind the organization, work email, and public website.
  • Enroll in the Apple Developer Program and confirm active membership.
  • Accept the latest Apple Developer Program License Agreement in App Store Connect.
  • Sign the Paid Apps Agreement if the app is paid or uses in-app purchases/subscriptions.
  • Complete banking and tax forms if the app will receive payments from Apple.
  • Add team members with correct App Store Connect roles: Developer, App Manager, Admin, Finance, Marketing, Customer Support, or Access to Reports as needed.
  • Set up internal process ownership for App Review replies, production incidents, support, privacy updates, and SDK updates.
  • If distributing in the EU, provide and verify Digital Services Act trader status.

App identity, bundle ID, capabilities, and signing

0/10
  • Choose final app name, bundle identifier, SKU, primary language, and platform.
  • Create an explicit App ID / bundle ID in Apple Developer.
  • Enable required capabilities in Apple Developer and Xcode.
  • Confirm entitlements match the app’s actual features and are not over-requested.
  • Configure Xcode target signing team and bundle identifier.
  • Use development signing for device testing and distribution signing for App Store archives.
  • If signing manually, create and install the Apple Distribution certificate and App Store provisioning profile.
  • Confirm APNs, Associated Domains, iCloud containers, App Groups, Merchant IDs, Sign in with Apple, or other linked identifiers are production-ready.
  • Create the App Store Connect app record and bind it to the correct bundle ID.
  • Confirm bundle ID cannot need changing after first build upload.

Project and build readiness

0/15
  • Install the currently required Xcode version and SDK for App Store upload.
  • Set deployment target, supported devices, supported orientations, display name, version number, and build number intentionally.
  • Use Release configuration for archives; remove debug-only flags, test endpoints, and developer menus unless intentionally reviewer-accessible.
  • Confirm production backend, API keys, push environment, auth callbacks, universal links, and webhooks are live.
  • Verify no placeholder content, lorem ipsum, fake buttons, empty legal pages, test images, disabled settings, or broken links remain.
  • Use public APIs only; remove private API usage and unsupported framework calls.
  • Confirm the app is self-contained and does not download executable code that changes features after review.
  • Add all required Info.plist purpose strings for camera, microphone, location, photos, contacts, calendars, Bluetooth, motion, tracking, health, local network, or other permissions used.
  • Test on real devices and simulators across supported device sizes and OS versions.
  • Test fresh install, upgrade from previous build, cold launch, background/foreground, poor network, offline state, and account recovery flows.
  • Test IPv6-only networking.
  • Test accessibility basics: VoiceOver, Dynamic Type, sufficient contrast, focus order, captions/transcripts where relevant, and reduced motion behavior.
  • Verify crash reporting, logging, analytics, and dSYM upload for symbolication.
  • Archive, validate, and upload a build to App Store Connect.
  • Resolve App Store Connect processing warnings, missing compliance status, signing warnings, entitlement problems, or SDK/privacy warnings.

Privacy, data, security, and SDK compliance

0/14
  • Create a data inventory for first-party code, backend services, analytics, ads, attribution, support tooling, crash reports, and all third-party SDKs.
  • Publish a privacy policy URL and make the privacy policy accessible from inside the app.
  • Complete App Privacy Details / privacy nutrition labels in App Store Connect.
  • Confirm App Privacy answers include third-party partner and SDK data practices.
  • Use ATT if the app or SDKs track users across apps/websites or access IDFA for tracking.
  • Do not gate unrelated functionality behind tracking, push notification, or location consent.
  • Add or verify the app privacy manifest.
  • Declare required-reason API usage in privacy manifests where required.
  • Audit Apple’s listed third-party SDKs for required privacy manifests and signatures.
  • Generate and inspect Xcode’s privacy report before submission.
  • Store auth tokens and secrets securely, preferably in Keychain; do not ship private API keys that cannot be exposed to clients.
  • Use TLS and avoid sending sensitive data through push notifications, logs, analytics events, or crash metadata.
  • If account creation exists, implement in-app account deletion initiation and document backend deletion behavior.
  • Verify data deletion, consent revocation, logout, and support-contact flows work in production.

Product page metadata and assets

0/19
  • App name is final and 2–30 characters.
  • Subtitle is final and no more than 30 characters.
  • Promotional text is no more than 170 characters.
  • Description is accurate, complete, and no more than 4,000 characters.
  • Keywords are no more than 100 bytes and avoid competitor names, irrelevant terms, and misleading claims.
  • Support URL is live, public, and useful.
  • Privacy policy URL is live, public, and matches actual data practices.
  • Marketing URL is added if useful.
  • Category and optional secondary category are selected accurately.
  • Age rating questionnaire is complete and honest.
  • Content rights declaration is complete.
  • Standard Apple EULA or custom EULA is selected.
  • Copyright owner/year is correct.
  • Accessibility Nutrition Labels are evaluated and filled out if you choose to disclose support.
  • App icon is final and follows Apple’s current Human Interface Guidelines.
  • Screenshots are uploaded for required display sizes and localizations.
  • Screenshots show the real app in use and do not imply unavailable features.
  • App previews are added where useful and comply with App Store preview rules.
  • Localization metadata and localized screenshots are complete for every launch language.

Monetization, StoreKit, IAP, and subscriptions

0/10
  • Decide free, paid, in-app purchase, subscription, or eligible external purchase flow.
  • If using paid app or IAP/subscriptions, confirm Paid Apps Agreement, tax, and banking are complete.
  • Create IAP products/subscriptions in App Store Connect with correct product IDs, prices, durations, localization, and review screenshots.
  • Implement StoreKit purchase, restore purchases, transaction verification, entitlement sync, subscription status handling, refunds/revocation handling, and server validation if used.
  • Verify credits/currencies do not expire unless Apple rules permit the model.
  • Test IAP/subscriptions with Sandbox Apple Accounts and TestFlight.
  • Make purchasable items visible and reviewable; explain purchase paths in App Review notes.
  • Submit first-time IAP/subscriptions with the app version when required.
  • If linking to external purchase/account flows, confirm eligibility for the relevant Apple entitlement and storefront rules.
  • If using Apple Pay, confirm it is used appropriately and required price/recurring-payment disclosures are shown.

Compliance, territories, and regulated features

0/8
  • Select App Store countries/regions intentionally.
  • Answer export compliance encryption questions and upload documentation if Apple requires it.
  • Complete DSA trader information if distributing in EU storefronts.
  • Verify rights to trademarks, logos, brand names, screenshots, music, video, datasets, fonts, icons, and user-facing content.
  • Review local requirements for each selected territory, including ratings, licensing, tax, consumer disclosures, privacy, and payments.
  • If medical or health-related, determine whether regulated medical device declarations or approvals are needed.
  • If finance, crypto, lending, banking, gambling, cannabis, legal, healthcare, VPN, or MDM-related, confirm Apple guideline fit and legal-entity requirements.
  • If the app is for kids or marked Made for Kids, review child privacy, ads, analytics, third-party SDKs, and irreversible App Store Connect choices.

TestFlight and QA

0/9
  • Create internal tester group and assign the uploaded build.
  • Prepare external beta test information if using external TestFlight testers.
  • Submit the build for Beta App Review if required for external testing.
  • Test with reviewer-like accounts and permissions, not developer-only states.
  • Test empty-state, first-run, returning-user, logged-out, expired-session, and blocked-permission states.
  • Test IAP/subscription flows in sandbox/TestFlight if monetized.
  • Review TestFlight crash reports, feedback, screenshots, and logs.
  • Fix blocking issues and upload a new build if needed; increment build number for every upload.
  • Confirm the final candidate build is the build selected for App Review.

Submission package

0/10
  • Select the processed build in the app version page.
  • Complete App Review contact name, phone, and email.
  • Provide demo account credentials if login is required.
  • Ensure demo account does not expire, is not region-blocked, and has all required data/features enabled.
  • Add detailed App Review notes for setup, non-obvious flows, hardware, region behavior, subscriptions/IAP, permissions, or test content.
  • Attach supporting documents if required: licenses, medical approvals, financial permissions, content rights, or regulatory documents.
  • Confirm no missing-compliance status remains on the build.
  • Add app version, IAP/subscriptions, events, or other items to the same review submission if needed.
  • Click Submit for Review after adding items for review.
  • Monitor status and App Review messages until approved or rejected.

Release and post-launch

0/7
  • Choose release mode: manual, automatic, automatic no earlier than a date/time, or phased release for updates.
  • Verify final pricing, availability, age rating, screenshots, description, and support links before release.
  • Coordinate backend flags, server capacity, push campaigns, support coverage, and launch communications.
  • Monitor crashes, performance, App Store Connect analytics, IAP/subscription issues, server logs, reviews, and support tickets after release.
  • Reply to App Store reviews where useful and route support issues to a real support channel.
  • Keep privacy labels, privacy policy, support URL, SDK manifests, screenshots, and compliance answers updated when the app changes.
  • Track future Apple SDK, Xcode, privacy, and third-party SDK requirements before the next update.