I took a new app right up to release. Thirteen per-task code reviews passed, my own go/no-go audit passed, unit tests passed, zero lint errors.
Then I ran one full review over everything. Two blockers came out, and neither was code.
Does your release checklist look outside the code?
First: I contradicted myself
The store description, in 15 languages, said:
Your records never leave your device. Nothing is sent anywhere.
The data safety form I filled out in the same session declared:
Collects purchase history and device identifiers.
Both are true. The records the user writes genuinely never leave the device, and the billing SDK genuinely receives purchase history. The problem is that I collapsed those two facts into one sentence on the store page. The app connects to the billing service on every launch.
Two documents submitted to the same console contradicted each other, and I wrote both on the same day.
Second: a sentence written without checking
The same description also said:
Long-pressing the volume key only changes the volume.
Opening the code, the long-press handler only accepts events with repeatCount > 0. But the first event of a long press is always repeatCount == 0. That first signal goes to the counter.
One long press on an emulator took the number from 10 to 9.
Third, I wrote that the app requests "exactly three" permissions. The shipping package contains five, because billing adds its own.
Why thirteen reviews passed it
Per-task reviews look at that task's output. The task that wrote store copy checked whether the copy read well. The task that filled the data safety form checked whether the form was accurate. Each was correct.
Nobody put the two in one table.
My own audit said "code GO" because it only looked at unit tests and lint. During that audit I had dirtied the device database and left the instrumentation suite red — and the audit never re-ran instrumentation once.
A fork in the road
When this surfaces right before release you can fix the copy and ship, or fix the process that let it get this far.
How far would you go?
I fixed the copy and shipped. For the process I left one rule:
Store copy is only verified once checked against code. Unit tests, lint and a bundle do not entitle you to say "code GO."
Self-check
- Do you check that two documents filed in the same review do not contradict each other?
- Have you ever grepped the code for the feature claims in your store description?
- Are you counting permissions and collected data by hand, or extracting them from the build output?
The honest part
The app was approved, with no review notes. Which means review would not have caught this contradiction. There is no automated check reconciling store copy against the data safety declaration, or if there is, it does not reach this far.
So this is not a story about nearly failing review. It is the more uncomfortable version: it would have shipped, and a sentence telling users something false would have gone out in 15 languages.
Same place as the paywall that sold a feature that was not there. Not the code — the sentences I wrote had drifted from the product.
Pick one feature claim from your store description and grep for its call site.