Launch readiness
Passing the closed test gets you the right to apply. What is inside the build decides how the rest goes: the API level it targets, the permissions it declares, the data its SDKs collect, and anything a stranger could pull out of the APK.
Each guide covers one of those checks, how to confirm it in your own build, and how to fix it before Google finds it.
- Start here
Google Play pre-launch checklist for 2026
What to check before your app goes live on Google Play in 2026: closed test, target API 36, permissions, Data safety, App content and keys in the APK.
Firebase config in an APK: what's public and what protects data
Your Firebase API key is visible in your APK, and Firebase says that is fine. What protects your data instead: Security Rules, App Check, restricted keys.
How to fill in the Data safety form for the SDKs in your app
Google Play holds you to what every SDK in your app collects. How to list the SDKs in your build, read their disclosures, and answer the Data safety form.
Google Play's target API level 36 requirement for 2026
From 31 August 2026 new apps and updates must target API level 36. How to check your build's target and change it in Gradle, Flutter, React Native or Expo.
How to check your APK for leaked API keys before you publish
Anyone who downloads your APK can read it. Which keys are safe to ship, which never are, where they hide in a build, and what to do if you find one.
Is your Supabase anon key safe in an Android app?
The Supabase anon or publishable key is meant to ship in your app, but only Row Level Security stands between it and your data. How to check every table.