Google Play pre-launch checklist for 2026
Updated
Most launch delays on Google Play are not about code quality. They come from a handful of things Google checks in the build and in Play Console, each of which takes minutes to confirm and days to recover from if you miss it.
This checklist is in the order it bites. Each item says what Google requires, how to check it, and where the full guide is.
1. Have you passed the closed test?
If your personal developer account was created after 13 November 2023, you need a closed test with at least 12 testers opted in for the preceding 14 days before you can apply for production. Organisation accounts do not.
- The rule and its edge cases: Google Play's 12 testers, 14 days requirement.
- When you will be eligible: the production access date calculator.
2. Does your build target API level 36?
From 31 August 2026, new apps and updates must target Android 16 (API level 36) to be submitted (Wear OS and Automotive: 35; TV and XR: 34). This is the item most likely to stop an upload outright, and the one most often wrong in a build that "should" be right.
Check the built APK with apkanalyzer manifest target-sdk app-release.apk.
How to change it in Gradle, Flutter, React Native and Expo.
3. Is it a release build, uploaded as an App Bundle?
Since August 2021, new apps must be published as an Android App Bundle
(.aab), not an APK. And it should be the release variant:
- Not debuggable.
apkanalyzer manifest debuggableon a built APK tells you. Release build types are not debuggable unless someone turned it on. - No debug logging or test endpoints left in. Android's release guide says to
remove
Logcalls and any test files before building for release.
4. Which permissions need a declaration?
Google restricts sensitive permissions (background location, all-files access,
SMS and call log, QUERY_ALL_PACKAGES, REQUEST_INSTALL_PACKAGES, exact alarms,
full-screen intents, photos and videos, foreground service types, and others) to
apps whose core feature needs them. Each needs a Play Console declaration, and
libraries add them without asking.
- Find yours: paste your merged manifest into the permission declaration checker.
- For each one: what Google allows, what to use instead, and how to remove it.
5. Does your Data safety form match every SDK?
Every app on a closed, open or production track must complete it, and Google counts what your SDKs send off the device as your app's collection. An ads or analytics SDK you forgot about is the usual mismatch. How to fill in the Data safety form for the SDKs in your app.
6. Have you completed App content?
Play Console's App content page collects the declarations Google reviews alongside your app:
- Privacy policy. Required even if your app collects no data: the Data safety form asks for the link.
- App access. If any part of the app needs a login or a membership, Google says "you must provide all required details to enable access to your app". Give reviewers working credentials, or they cannot review what is behind them.
- Ads. Whether the app contains ads, which puts a "Contains ads" label on your listing.
- Content rating. Fill in the questionnaire so the app is not listed as unrated.
- Target audience, and any declarations that apply to your kind of app, such as news or health apps.
7. Is anything secret inside the APK?
Anyone who downloads your app can unpack it. API keys that are designed to be public are fine; secret keys for AI providers, payments, cloud accounts or your database are not. How to check your APK for leaked API keys.
8. Is your backend locked down?
Google does not review your database rules, but the keys in your app point straight at them.
- Supabase: is your anon key safe? It is, only if Row Level Security is on for every table.
- Firebase: what actually protects your data, and how to spot open Security Rules.
9. Ready to apply for production?
With the test passed and the build ready, the application asks about your test, your app and its readiness. How to answer Google Play's production access questions, and how long the review takes.
Sources
- Play Console Help: App testing requirements for new personal developer accounts
- Android Developers: Meet Google Play's target API level requirement
- Android Developers: About Android App Bundles
- Play Console Help: Prepare your app for review
- Play Console Help: Permissions and APIs that Access Sensitive Information
- Play Console Help: Provide information for Google Play's Data safety section