Scope & limits
What this source-only checker evaluates—and what it does not
The live checker reads selected project files for the checks named below. It does not inspect your store-console answers, screenshots, or every runtime and backend behavior. Those require other evidence and, in some cases, a human review.
What the current live checker evaluates
Build configuration
- Target SDK declarationReads the supplied Gradle or manifest files and reports whether the lowest detected target SDK meets the current API 36 requirement. If it cannot find a declaration, it reports "not found," not a pass.
- Play Billing Library declarationReads supplied Gradle and version-catalog files for a detectable Billing Library major version and compares it with the current v8 minimum. Apps with no detectable dependency are reported as "not found."
Payment-flow heuristic
- Possible non-Play payment patternFlags certain third-party processor names near digital-goods wording. This is a narrow text heuristic, not a determination that a payment flow violates policy.
What this source-only checker does not evaluate
Store listing
- Metadata accuracyWhether your store listing, title, and description accurately describe the app. Human reviewers judge this.Human review
- Screenshot contentOutdated, misleading, or non-compliant store screenshots.Human review
- Age-rating correctnessWhether the rating questionnaire you filled in matches your content.Human review
Data & privacy
- Privacy nutrition labelsWhether the data-collection labels you filled in at submission match what your app actually does.Human review
- Server-side data handlingWhat your backend stores, shares, retains, or deletes is not established by the supplied client files or a normal app walkthrough.Separate evidence
Runtime & judgment
- Runtime behaviorCrashes, broken flows, content that only appears when the app runs. Store review runs your app; a scanner doesn't.Human review
- Purchase flows as experiencedWhether your IAP flow is confusing, misleading, or violates pricing-display rules in practice.Human review
- Other contextual policy questionsDesign quality, spam or duplication, content policy, regional behavior, and other issues whose answer depends on the complete app and submission context.Scoped review
What is a scan actually worth?
It is a narrow preflight lint. It checks the three rule families listed above in the files you provide. It does not establish that the project builds, that the submitted artifact matches those files, or that the app will pass review. A pass means only that the detected declaration meets that named check.
Source-only checks stop here. A human can review many visible submission elements and runnable flows before you submit. Server-side handling, untested states, and legal compliance require additional evidence or separate specialist work. See the human preflight scope.
How the rulebook stays honest
AppShield's research registry and the live checker are separate things. The registry tracks 86 policy and engineering items; the live checker currently implements only the three narrow rule families listed on this page. Published store requirements are separated from platform guidance and engineering best practice, and report citations include the official source and the date checked. A registry entry is not presented as a live automated check unless the checker actually runs it.