The App Store Review is the review process that Apple and Google Play subject every submitted app and update to before publication. Only once an app has passed this review does it become publicly available. The review is not merely a formality: a significant proportion of all submissions are rejected, usually for a limited number of recurring reasons. Knowing these reasons before the first upload helps to avoid rejections and, consequently, delays to the launch date.
The term ‘App Store Review’ is used in the narrower sense to refer to Apple’s review process, but in a broader sense it describes the comparable process on both major platforms. Both platforms review every version before approval, both publish guidelines against which apps are assessed, and both penalise breaches, which can result in rejection or the removal of the app. For developers and product managers, the review is therefore the final hurdle between a finished build and public availability, and at the same time the one most frequently underestimated.
How the review process works
Apple and Google share the same objective but employ different review methods. Apple relies more heavily on manual checks by reviewers, whilst Google relies more on automated processes. Both platforms have now supplemented the process with AI-supported checks, amongst other things to detect fraud, policy violations and security issues more quickly. In both cases, it is not only the programme code that is examined, but also the so-called metadata – i.e. the title, description, screenshots, age rating and privacy information.
Apple App Store Review
At Apple, every submission is checked against the App Store Review Guidelines, a comprehensive set of rules covering security, performance, business model, design and legal matters. Apple’s official App Store Transparency Report for 2024 shows around 7.8 million submissions reviewed, of which approximately 1.9 million were rejected – roughly a quarter. Review times averaged around 24 hours in 2023/24; due to the sharp rise in the number of submissions, the range has widened in 2026 and now varies, depending on the app, from around 24 to 72 hours, or several days in individual cases. The review is predominantly carried out by human reviewers, who install the app on a real device and test its core functions.
Google Play Review
Google Play uses a similar technical review process but requires additional mandatory information such as the Data Safety Form, a privacy policy, a content rating and a target audience declaration. A special rule has applied to new developer accounts since November 2023: anyone who created their account as a private individual after 13 November 2023 must carry out a closed beta test with at least 12 testers over 14 consecutive days before the app is released to the public. This figure was originally 20 and was reduced to 12 on 11 December 2024. The rule does not apply to organisational accounts. Google describes this step as a quality measure designed to prevent unfinished or irrelevant apps from entering the live catalogue.
The most common reasons for rejection
Apple categorises rejections according to specific guidelines. Four of these cover the majority of cases:
- Guideline 2.1 – App completeness: the most common reason. Crashes, broken core functions, visibly unfinished features, placeholder content or a lack of demo access for apps requiring login.
- Guideline 2.3 – Correct metadata: Screenshots, preview videos or descriptions do not reflect the app’s actual state.
- Guideline 4.3 – Minimal Functionality and Spam: the app merely displays a website within a frame (web view wrapper) without any significant native added value.
- Guideline 5.1 – Data Protection: missing or misleading app data protection information, a missing privacy policy or a missing privacy manifest.
In addition, the Human Interface Guidelines are a less common but regular point of review: apps that do not adhere to platform conventions or break on certain display sizes are flagged in the design section. On Google Play, incomplete or contradictory information in the Data Safety Form, as well as breaches of the guidelines on sensitive permissions, regularly lead to rejections.
Data protection requirements in the review
Data protection is the area that has seen the most significant tightening of requirements between 2024 and 2026, and is consequently a frequent cause for rejections. In the Apple App Store, the app’s privacy information (known as ‘Privacy Labels’) must honestly and fully list what data is collected and how it is used. Anyone using cross-app tracking or personalised advertising also needs the App Tracking Transparency (ATT) consent framework, which requires explicit permission before accessing the advertising identifier. Since 1 May 2024, the Privacy Manifest has also been mandatory. On Google Play, the Data Safety Form fulfils a similar role: it is mandatory for every published app and must correspond to the app’s actual data practices. In both stores, an accessible privacy policy in the form of a URL is mandatory. Passing data on to third parties, such as AI services, without clear disclosure and consent is a sure-fire reason for rejection.
Example: the demo account trap
A typical, easily avoidable reason for rejection concerns apps that require registration. If an app requires a login, a working demo account must be provided in the review notes (the ‘App Review Information’ field in App Store Connect). If this is missing, the reviewer is presented with a login screen, cannot access the app and rejects it under Guideline 2.1 without ever having seen the rest of the app. A related issue is the Privacy Manifesto (PrivacyInfo.xcprivacy), which has been mandatory since 1 May 2024: If this is missing for apps that use certain ‘Required Reason APIs’ or corresponding third-party SDKs, App Store Connect will reject the submission as soon as it is uploaded – i.e. even before the actual review takes place. What both cases have in common is that it is not about the quality of the app, but rather a technical oversight that can be avoided with just a few minutes’ preparation.
What can be checked before submission
Many rejections can be prevented by a quick preliminary check. It has proven useful to go through the following points before each submission:
- The app has been tested by clicking through it on a real, freshly installed device, without any crashes or broken core functions.
- For apps requiring login, a valid demo account is specified in the review notes.
- Screenshots and previews are taken from the exact build being submitted.
- The privacy policy is available via an accessible URL, and the privacy details are complete and correct.
- The Privacy Manifest is present (iOS) and the integrated third-party SDKs have been checked.
- The app clearly offers native added value beyond that of a standard website.
- For a new Google Play private account, the closed test with 12 testers has been running for at least 14 days.
Beta testing prior to public review
Before public release, an app can be distributed to selected users via test tracks. At Apple, this is handled by TestFlight: external testers receive pre-release versions that undergo a separate, generally less rigorous beta app review process, rather than the full App Store review. On Google Play, there are internal, closed and open test tracks. For purely internal test tracks, for example, the Data Safety Form is not required, whereas closed, open and production tracks make it mandatory. These test stages serve a dual purpose: They uncover crashes and usability issues before they lead to rejection during the public review process, and in the case of new Google Play private accounts, the closed test involving 12 testers over 14 days is even a prerequisite for being allowed to publish to production at all.
Review times and launch planning
As the review process takes time and, in case of doubt, may result in a rejection followed by corrections and a resubmission, a launch date should never be planned down to the exact day. Updates generally go through the process more quickly than initial submissions. On Google Play, the 14-day mandatory testing period acts as a fixed lead time for affected new private accounts, and this cannot be expedited. Anyone with a fixed release date – for example, due to a trade fair or campaign – should plan the review as a separate milestone with a buffer, rather than as the final step on the deadline day.
The review in the context of release
The App Store review is just one of two hurdles between a finished build and a successful app. First, the app must pass the review without being rejected. After that, it needs to be found in the first place, which is achieved through App Store Optimisation (ASO) – namely via the title, subtitle, keywords, screenshots and reviews. Both steps form part of the release planning: the review determines whether the app is allowed to go live, whilst ASO determines whether it reaches users afterwards. Those who release apps regularly or manage multiple apps incorporate review preparation and ASO firmly into the development and release process, rather than treating them as separate, downstream tasks. Even the early choice of technology has an impact: an app with genuine native functionality passes the review more easily than a pure web container, which fails under the minimum functionality guideline.
Frequently asked questions about the App Store review
How long does the App Store review take?
In 2026, the typical review time for new apps is around 24 to 72 hours, or several days in individual cases. Updates are usually reviewed more quickly. The duration depends on the complexity, account history and the completeness of the submission.
What happens after a rejection?
Apple and Google provide the reason for the rejection, often referring to the guideline that has been breached. Once the issue has been resolved, the app is resubmitted and goes through the review process again. In some cases, metadata corrections alone can be submitted without uploading a new binary. With Apple, there is also the option to raise queries via the Resolution Centre or to appeal a decision if you believe the rejection was a mistake. It is important to fully resolve every reported issue, as otherwise a resubmitted app will be rejected again for the same reason.
Can the review process be expedited?
Apple offers an expedited review for urgent cases, which you can apply for by providing a valid reason. This is the exception, not a standard, predictable procedure. The 14-day Google Play testing requirement for new personal accounts cannot be expedited.
Does the review process also apply to updates?
Yes. Every update also undergoes a review, though this is usually quicker than an initial submission. The same guidelines on metadata, data protection and functionality also apply to updates.
How do Apple and Google differ in their review processes?
Apple relies more heavily on manual review and places great emphasis on native added value and design. Google relies more on automated checks and requires mandatory formal information such as the Data Safety Form, as well as a preliminary testing phase for new private accounts. Both are increasingly using AI-supported review steps.