Before you submit: the account layer
Apple requires a paid developer membership with a verified entity, Google Play a one-time $25 registration. Both need real contact details, and Apple's verification is the slowest step in the whole process, so it belongs first on the calendar.
Both stores now require a data safety answer: what data the app collects, whether it is linked to the user, and whether it is used for tracking. Answering honestly matters twice: the review team checks it against what the app actually does.
What the review actually looks at
The listing basics: a name that matches the app, a category that fits, screenshots that reflect the current version, and a valid support URL. Then the app itself: it must launch, not crash, and not show placeholder content, empty pages, or a 'coming soon' state.
Permission prompts are a common rejection. If the app asks for notifications, location, or camera access, the prompt must be tied to a real feature the user sees. A generic 'we need this' prompt is the easiest rejection to get and the easiest to avoid.
The checklist itself
Privacy policy live and linked from the listing and the app. Real contact email and support URL. App icon present at every size the store asks for. Screenshots from a real device, not resized web images. Category, age rating, and data-safety answers consistent with the app. No placeholders, no test builds, no 'beta' wording in the listing.
Go through that list once, before you hit submit, and most first-time rejections disappear. The rest are genuinely store-specific and both stores tell you the exact reason in plain language when they reject.