Review intake preview
Know exactly what a complete intake requires
Do not send app access or credentials just to ask about the review. Request a review first. Revo will confirm availability, fit, the agreed flows, and the safe handoff method. The 24 to 48 clock-hour delivery window begins only after scope and payment are confirmed and AppShield emails “Intake complete.”
The single-store preflight scope
The $99 introductory price applies to scopes accepted and paid by October 31, 2026. Each engagement uses one narrowly defined submission; anything broader is discussed before materials or payment are requested.
Runnable build vs video-only review
Full human preflight
Requires a runnable current build: a TestFlight invite, APK, or internal-testing link that lets Revo independently navigate the agreed flows. This is the evidence needed for a full in-scope readiness assessment.
Limited materials review
If a runnable build genuinely cannot be shared, a video may support a narrower comparison of the recording, listing, screenshots, and declarations. App behavior that cannot be independently exercised is marked Not Evaluated. A video-only report is labeled limited and is not presented as a full build review.
What a complete intake includes
- Scope identifiersApp name, target store, build number or version, store locale, primary user role, and the agreed list of no more than 12 core screens or flows.
- Runnable build accessA TestFlight invite, APK, or internal-testing link for the exact build in scope. Source code is not required for this review.
- Draft store listing textTitle, subtitle or short description, full description, category, and other claims as you intend to submit them.
- Final listing assetsScreenshots, icon, any preview video, and release notes, checked against what the build actually shows.
- Draft privacy label or Data Safety answersCompared with visible build behavior and the other materials supplied. Unseen server-side collection cannot be established by this review.
- SDK, permission, and data inventoryYour current list of relevant SDKs, requested permissions, collected data, purposes, and recipients. This is developer-supplied evidence, not proof of unseen backend behavior.
- Age rating questionnaire answersCompared against what's actually visible on screen.
- Live policy, support, and deletion URLsThey need to be reachable and intended for the submitted app, not placeholders.
- A disposable test account, if login is requiredOne least-privilege account for the role in scope, populated only with invented test data.
- Purchases and account-flow informationIAP or subscription names, prices, billing periods, paywall locations, entitlement restoration or management and cancellation paths, account-creation and deletion steps, and sandbox or license-tester access if those flows are in scope.
- Reviewer notes and previous rejection textEverything the store reviewer needs to reach the scoped flows, plus earlier store feedback that should be rechecked.
Never send
Safe handoff after acceptance
- Wait for the scope-confirmation replyIt identifies the accepted app, store, build, locale, user role, agreed flows, and handoff method. Do not send access before that reply.
- Confirm you are authorized to share the app and materialsThe requester must own them or have permission to provide them and to authorize test-account creation, deletion requests, and sandbox purchases within the accepted scope.
- Use a restricted shared folder for review materialsGrant only the access needed, keep real customer information out, and set an expiry or revoke the link after the recheck window.
- Share the disposable test credential separatelyUse the agreed one-time secret link or password-manager share. Never place a password, token, or secret in the email body, shared-folder name, or URL query string.
- Remove access afterwardRotate or delete the test-account password and revoke the TestFlight, internal-test, and folder access after the review and focused recheck are complete.
What the report records
- Review identityThe app, store, build, locale, user role, report date, and test environment used.
- Observed evidenceThe screen, step, behavior, supplied claim, and supporting screenshot or note behind each finding.
- Source and classificationThe current official Apple or Google requirement where one applies; non-policy recommendations are labeled separately.
- Correction and severityA prioritized correction and recheck condition for each policy conflict, high-risk, medium, or note finding.
- Not EvaluatedEvery material area the supplied access could not establish, including server-side behavior, devices, roles, locales, and flows outside the accepted scope.
What happens next
Review request
You describe the app and intended scope. No build access or credential is needed for this step.
Scope accepted
Revo confirms availability, the exact submission and flows in scope, whether a runnable build is available, and the safe handoff method.
Intake summary
After payment, complete the client intake summary using the approved scope ID. It records readiness without collecting files or credentials.
Intake checked
The materials are checked for completeness. Missing items are named; the delivery clock has not started yet.
Intake complete
After scope and payment are confirmed and every usable item has arrived, AppShield emails “Intake complete” and the 24 to 48 clock-hour delivery window starts.
Review begins
Revo exercises the agreed flows, compares the store package and declarations, records evidence, and states every Not Evaluated boundary.
Report delivered
Written report delivered as PDF and Markdown within 24 to 48 clock hours of complete intake.
One round of written clarification
Follow-up questions on the report, answered in writing.
One focused recheck
Within 7 days, scoped to the items flagged in the original report.
Data and access boundaries
Reviewed personally by Revo Lue Shin. AppShield is independent and is not affiliated with, endorsed by, or certified by Apple or Google. The review does not require store-console access, signing material, production credentials, or customer data.
Downloaded active working copies are used only for the accepted review and are deleted within 7 days after the focused recheck window closes. The final report, scope confirmation, and ordinary correspondence may be retained as service records; email and storage-provider backups may persist until their normal retention cycle expires. Credentials are not reproduced in the report. You remain responsible for revoking shared links and rotating or deleting the disposable test account. Reports and client materials are not published without written permission.
See the method before you request
Read the fictional sample preflight report and the full review scope and limits before sending anything. A request is an availability and scope check, not a purchase or reservation.