How to Publish an App on the App Store and Google Play in 2026: Accounts, Requirements and Review
Building the app is only part of the job. Before anyone can download it, your business has to open developer accounts, pass identity checks, complete privacy disclosures, meet each store's current technical rules and get through review. Several of these steps have waiting periods you cannot shorten, so they need to start well before the code is finished.
This guide explains how to publish an app on the Apple App Store and Google Play as the rules stand in October 2026. Each requirement links to the official Apple or Google page it comes from, because these rules change every year.
Quick answer
- Own the accounts. Open an Apple Developer Program membership and a Google Play Console account in your company's name, not your agency's. Organizations need a D-U-N-S number for both.
- Start verification early. Google says organization verification can take up to 30 days.
- Build with current tools. Apple requires Xcode 26 and the iOS 26 SDK. Google Play requires new apps and updates to target Android 16 (API level 36).
- Complete the privacy forms. Apple's App Privacy details and Google's Data safety form are mandatory and cover third-party SDKs.
- Allow time for review. Apple reports most submissions are reviewed within 24 hours; Google recommends a buffer of at least a week.
- Plan for maintenance. Both stores restrict or remove apps that fall behind.
Step 1: Decide who owns the developer accounts
The developer account is the legal publisher of the app. It holds the store listing, ratings and reviews, signing identity and payout details. If your agency publishes the app under its own account, the agency is the publisher on record, and moving the app later requires a formal transfer.
The better arrangement: the business owns both accounts and invites the development team as users.
- Apple: the Account Holder accepts legal agreements, renews the membership and approves banking changes. Agencies can be added with narrower roles such as Admin, App Manager or Developer (Apple's program roles). Team roles are a feature of organization memberships.
- Google: the account owner is the first registered account and the only one who can manage payment settings. Everyone else is invited by email with account-wide or app-specific permissions (Play Console users and permissions).
Register with a company-controlled email address, not a staff member's personal account. If an app is already published under someone else's account, both stores support transfers that keep ratings and reviews (Apple, Google), but transfers have conditions and take planning. Our guide to outsourcing software development from the US and UK covers the wider ownership terms to settle in the contract.
Step 2: Open the developer accounts
Both stores offer an individual (personal) and an organization account type. For a business, the organization type is almost always right: the store shows your company name as the seller, you can add a team, and you avoid the testing rule Google applies to new personal accounts (Step 6).
| Item | Apple Developer Program | Google Play Console |
|---|---|---|
| Fee | 99 USD per membership year; prices vary by region and are shown in local currency at enrollment | 25 USD one-time registration fee |
| Individual / personal | Apple Account with two-factor authentication, legal age of majority, legal name, email, phone and address (no P.O. boxes) | Age 18 or over, verified legal name and address, contact email and phone; testing and device verification before distribution |
| Organization | Legal entity, D-U-N-S number, a person with legal binding authority, work email on the company domain, a functional public website | D-U-N-S number, organization name and address matching the D-U-N-S profile, organization phone and website, a named contact |
| Shown publicly | Legal name as the App Store seller | Personal: legal name, country, developer email. Organization: legal name, legal address, developer email and phone |
Sources, checked October 4, 2026: Apple enrollment requirements, Google Play Console sign-up and Google's account type requirements. Apple also offers fee waivers to eligible nonprofits, accredited educational institutions and government entities.
Points that catch businesses out
- The D-U-N-S number. This nine-digit identifier from Dun and Bradstreet is how both stores confirm your company exists at the address you give. Look up or request yours first; organization enrollment cannot proceed without it. Government entities are excepted.
- Legal entity names. Apple does not accept DBAs, fictitious names, trade names or branches. A US LLC or corporation, or a UK limited company, enrolls under its registered name. A US sole proprietor or UK sole trader without a separate legal entity would normally enroll as an individual, and the store shows that person's legal name.
- Matching details. Google takes the organization name and address from your Google payments profile and expects them to match the D-U-N-S record, with verification taking up to 30 days.
- EU distribution. Apple asks every developer to declare whether they are a "trader" under the EU Digital Services Act and displays verified contact details for traders (Apple's DSA trader requirements). This affects US and UK businesses with EU customers. Take legal advice if you are unsure of your status; this article is not legal advice.
Step 3: Meet the current technical requirements
Both stores refuse builds made with outdated tools. Ask your developers to confirm the following before submission.
- Apple: since April 28, 2026, apps uploaded to App Store Connect must be built with Xcode 26 or later using the iOS 26 SDK, or the equivalent SDK for iPadOS, tvOS, visionOS or watchOS (Apple's upcoming requirements).
- Google: from August 31, 2026, new apps and updates must target Android 16 (API level 36) or higher, with an extension available on request until November 1, 2026. Existing apps must target at least Android 15 (API level 35) to stay available to users on newer Android versions. Wear OS, Android TV, Android Automotive and Android XR have lower thresholds (Google's target API level requirements).
- Upload format: new apps on Google Play must be published as an Android App Bundle.
These rules apply whether the app is native, Flutter or React Native. A cross-platform framework still produces an iOS build and an Android build that must each satisfy its store. If you have not chosen an approach yet, see our comparison of native vs Flutter vs React Native.
Step 4: Prepare the store listings
Each store needs its own listing. Gather these while development is in progress:
- App Store: app name, description (up to 4,000 characters), keywords (up to 100 bytes), a support URL that leads to real contact information, and 1 to 10 screenshots per device size. iPhone screenshots are required for the 6.9-inch display (or 6.5-inch if those are not supplied), plus 13-inch iPad screenshots if the app runs on iPad. See Apple's version information and screenshot specifications.
- Google Play: a 512 by 512 pixel icon, a 1024 by 500 pixel feature graphic, at least two screenshots, a short description of up to 80 characters and a full description (Google's preview asset requirements).
- Both: an age or content rating questionnaire, a public privacy policy URL and a support contact.
Screenshots must show the real app; Apple lists inaccurate screenshots among its common rejection reasons. How the listing is written also affects whether people find and install the app, which is the subject of app store optimization.
Step 5: Complete the privacy disclosures
Both stores publish a summary of what your app does with user data, based on your answers. You are responsible for accuracy, including for code you did not write.
- Apple App Privacy details: required to submit new apps and updates. You declare each data type collected and whether it is used to track users, linked to their identity or not linked, including data collected by third-party partners such as analytics tools, advertising networks and SDKs (App privacy details).
- Google Data safety form: required for every published app, including apps on closed and open testing tracks and apps that collect no data. A privacy policy link is mandatory, and Google states it may take enforcement action if the app's behavior does not match the declaration (Data safety guidance).
- Account deletion: if users can create an account, Apple requires a way to delete it inside the app, and deactivation alone is not enough (Apple's guidance). Google requires an in-app path and a web link for deletion requests (Google's requirements).
Ask your developers for a list of every SDK in the app and what each collects. That list feeds both forms and your privacy policy. The forms do not replace obligations under laws such as UK GDPR or US state privacy laws; handle those with your legal adviser.
Step 6: Test before you submit
Google still enforces a testing rule for personal accounts. Personal developer accounts created after November 13, 2023 must run a closed test with at least 12 testers opted in continuously for at least 14 days before applying for production access (Google's app testing requirements). The rule is written for personal accounts, one more reason for a business to enroll as an organization.
Whatever the account type, run a beta with real users on real devices on both platforms before submitting.
Step 7: Submit for review
Apple states that, on average, 90 percent of submissions are reviewed in less than 24 hours (Apple App Review). Google says processing can take a few hours or up to seven days, or longer in exceptional cases, and recommends a buffer of at least a week between submitting and going live (Google's publishing guidance). Those figures cover one review pass. A rejection means fixing the issue and being reviewed again, so do not tie a public launch date to a first-time approval.
Common rejection reasons
Apple reports that over 40 percent of unresolved review issues relate to app completeness. The most frequent problems are preventable:
| Reason | What the store expects | How to avoid it |
|---|---|---|
| Reviewer cannot log in | Apple: a working demo account or demo mode. Google: sign-in details for restricted areas | Create a dedicated review account and keep the backend live |
| Crashes, placeholder text, broken links | Final, fully functional builds | Test the exact build you submit on physical devices |
| Privacy policy missing or incomplete | A policy covering what is collected, how it is used, third-party sharing, retention and deletion | Write the policy from your SDK and data inventory |
| Unclear permission requests | A clear explanation of why the app needs camera, location or contacts access | Request only what a feature needs |
| App is a wrapped website | Apple expects features and interface beyond a repackaged website | Include functionality that justifies an app |
| Digital goods sold outside in-app purchase | Apple guideline 3.1.1 requires in-app purchase to unlock digital features or content, with storefront-specific exceptions | Settle the payment model before the build starts |
| Submitted by the wrong entity | Apple expects regulated services such as banking or healthcare to be submitted by the legal provider | Publish under the regulated company's own account |
Sources: Apple's App Review Guidelines and App Review page, and Google's Prepare your app for review. Apple allows one appeal per rejected submission and offers expedited review for critical bug fixes and event-related apps.
Step 8: Choose a release strategy
The first version goes live to everyone in the countries you select. Gradual release applies to updates:
- Apple phased release: an update reaches users with automatic updates over seven days, at 1, 2, 5, 10, 20, 50 and 100 percent. You can pause for up to 30 days in total or release to everyone at any time, and anyone can still download the update manually (Apple's documentation).
- Google staged rollout: you choose the percentage, raise it when satisfied, and can halt the rollout. It can only be used for updates, not a first publication (Google's documentation).
Illustrative scenario: a retailer ships an update that changes checkout. Released to a small percentage first, a payment bug affects a fraction of customers and the rollout is halted, instead of reaching the whole user base. Google's managed publishing option also lets you hold an approved update and publish it when you choose.
Post-launch obligations
- Keep the Apple membership active. The fee is annual, and the Account Holder must accept updated agreements.
- Rebuild regularly. Apple's SDK minimum and Google's target API level have deadlines that move forward, so an app that is never rebuilt eventually cannot be updated or loses availability on newer devices.
- Do not abandon the app. Apple may remove apps not updated in three years that have very few downloads, after asking for an update within 90 days; apps that crash on launch are removed immediately (App Store Improvements).
- Keep disclosures current. Adding an analytics or advertising SDK changes your privacy answers on both stores.
For technical readers
- Apple's requirements page also lists a minimum deployment target: iOS and iPadOS apps uploaded to App Store Connect must target iOS 13 or later, dated September 9, 2026. Check older codebases and dependencies.
- An Android App Bundle defers APK generation and signing to Google Play. Agree who holds the upload key and keep it in the client's secret store, not on a developer laptop.
- Google's Android developer verification program is rolling out. Google's timeline lists September 30, 2026 for Brazil, Indonesia, Singapore and Thailand, with global expansion planned for 2027 and beyond, and it covers apps distributed outside Google Play too. Google says most Play apps are registered automatically; confirm yours in Play Console.
- Apps that use third-party or social login for the primary account must offer an equivalent privacy-focused login option under Apple guideline 4.8, with listed exceptions.
Frequently asked questions
How much does it cost to publish an app on the App Store and Google Play?
The store fees are 99 USD per year for the Apple Developer Program and a one-time 25 USD registration fee for Google Play Console, per Apple's and Google's official pages as of October 2026. Apple says prices vary by region and are shown in local currency at enrollment, so UK businesses should check the amount displayed. Store commissions on sales and the cost of building and maintaining the app are separate.
Can my development agency publish the app under its own account?
It can, but the agency then becomes the publisher on record and controls the listing, reviews and payouts. For a business app, open the accounts in your company's name and give the agency a limited role.
Do I need a D-U-N-S number?
Yes, if you enroll as an organization on either store, unless you are a government entity. Personal accounts do not need one, but they display a person's legal name as the publisher, and new personal accounts on Google Play must complete the 12-tester, 14-day closed test.
Does a Flutter or React Native app follow different store rules?
No. The stores review the final iOS and Android builds, so the same account, privacy, SDK and target API requirements apply. The framework only changes how those builds are produced.
Can I launch on both stores on the same day?
Yes, if you plan for it. Submit to both early, then control the release moment: Google's managed publishing holds an approved release until you publish it, and review timing differs between the stores, so leave at least a week of margin.
Conclusion and next step
Publishing an app is an administrative project that runs alongside development. It goes smoothly when the business owns its developer accounts, requests the D-U-N-S number early, inventories its data collection before completing the privacy forms, and submits a finished build with a working reviewer login and a week of margin.
A practical next step is to open both accounts in your company's name now, since verification is the part you cannot speed up. If you would like help planning the build and the submission, Entrant Technologies builds mobile apps and can scope the work with you: request a quote.