Blog

What it takes to ship to both stores

Publishing a Flutter app — or a Swift one — means two store checklists. App Store submission and Google Play release are not the same review.

  • App Store
  • Play
  • Release
A sealed handset-shaped form on an unprinted tray — the object that App Store submission actually ships.

A Flutter codebase produces two artifacts. They do not share a review. “We deploy” is not a plan. This note is what App Store submission and Google Play release actually contain, from a studio in Riyadh.

Flutter is the default when both stores matter from the first release. Swift follows the same Apple checklist when the product belongs on Apple. The Android half falls away. The Apple half does not get shorter.

One codebase, two binaries

IPA is what Apple reviews. AAB is what Play reviews. flutter build ipa writes an archive and an IPA. flutter build appbundle writes an AAB. Play prefers the bundle over an APK. Play App Signing means you keep the upload key and Play holds the app-signing key.

The client’s account holds both stores. Credentials stay theirs. We upload. We do not own the listing.

Accounts before week twelve

The Apple Developer Program sits on the client’s Apple Account. An individual listing carries a personal name. An organization listing needs a D-U-N-S number. Healthcare-class products should not sit on a personal name. Apple says as much.

Play has the same fork: Personal or Organization. A new personal Play account created after 13 November 2023 cannot go to production until a closed test is done. Most commercial Saudi products should be an Organization account. The fees are public — ninety-nine dollars a year at Apple, twenty-five dollars once at Play. We will not turn them into a table.

The Apple checklist

As of 28 April 2026, iOS apps uploaded to App Store Connect must be built with the iOS 26 SDK. That is Apple’s rule, in force. Then: a bundle ID, an App Store Connect record, a privacy nutrition label, purpose strings that match the binary, screenshots that show the app in use, a demo login, a live backend, review notes, a support URL, a privacy policy.

  • Xcode 26 / iOS 26 SDK — already required.
  • Localized screenshots of the app in use, not a splash. Guideline 2.3.3.
  • Demo account or an approved demo mode, and a backend that is live. Guideline 2.1.
  • TestFlight internal every week. External if you need a wider ring — the first external build is reviewed.

Apple publishes the figure: on average, 90% of submissions are reviewed in less than 24 hours. That is Apple’s sentence. We do not sell it as ours. First submissions, medical apps, and anything with user-generated content sit in the slower tail. Incomplete submissions delay or fail. Over 40% of unresolved issues relate to guideline 2.1. Also Apple’s number. The common fail is completeness, not “strict Apple.” Medical extra care — guideline 1.4.1 — sits in the healthcare note.

The Play checklist

A signed AAB. A unique applicationId. From 31 August 2026, new apps and updates must target Android 16 / API 36. A store listing. Data Safety. A content rating. Then the tracks.

  • Internal — up to 100 testers, minutes, optional. The weekly Android build.
  • Closed — named testers. The production gate on new personal accounts.
  • Open — after production access.
  • Production — the store.

On a personal account created after 13 November 2023, closed testing is the road to production: at least twelve testers, opted in continuously for fourteen days, then you apply. Production-access review is usually seven days or less. Google does not promise it. Testers who opt out and back in restart the fourteen days. Internal testers do not count toward closed. Someone on internal who never opts into closed does not move the gate.

Organization accounts are not under that twelve-and-fourteen rule. They should still test before production. Health, finance, and government products belong on an Organization account.

TestFlight is not Play closed testing

Pair them as the weekly habit. Then keep them separate. TestFlight internal is the team — up to 100, no extra review. TestFlight external is App Review of the beta, then up to 10,000 testers. Play internal is the fast Android ring. Play closed is named testers, and for those new personal accounts it is the only road to production.

Do not tell a founder “we’ll TestFlight Android.” The words are not interchangeable. The work is not interchangeable.

What you sell, and how you charge

Digital unlocks and subscriptions go through In-App Purchase. Guideline 3.1.1. Physical goods and services consumed outside the app use methods other than IAP — Apple Pay, or a card. Guideline 3.1.3(e).

Naqrah.app books real clinic visits in Oman. That is a real-world service. Apple Pay or a card. Not IAP. T-CODE publishes offers a shopper redeems in a Saudi store. Same rule. We do not invent a payments architecture around either of them. We name the guideline they fall under.

Arabic and English on the Saudi storefront

Apple’s SAU row: default language English (U.K.), additional language Arabic. Arabic is not automatic. You add it. Metadata, screenshots, keywords. They must match the binary. Claiming Arabic and shipping English screenshots is how 2.3 fails.

Xcode’s locale list is a second checklist. Flutter’s l10n files do not fill App Store Connect. The bilingual work inside the app is its own note.

What we will not say

We submit a complete app, under your account, with a live backend. We do not guarantee approval. We do not sell Apple’s average as our SLA. The work is on the schedule from week one. Write to us with the stores you need to be on, not with a launch date we cannot sign.

Tell us what you’re building.

Write to us with the product you want built. You will get a considered reply from the people who would do the work.

Start a conversation