In 2025, Apple and Google are "tightening" their listing policies for Web3 applications.

Attention to all Web3 app project teams: In 2025, Apple and Google are "tightening" their listing policies for Web3 applications.

The key points are straightforward—

  • On the Apple side:Features with trading or investment attributesmay only be offered in countries/regions where the necessary licenses are held,and such apps should, in principle, be submitted by financial institution entities.

  • On the Google Play side: Exchanges and custodial wallets are subject to license verification on a country-by-country basis; non-custodial walletsare not covered by this specific policy but remain subject to local legal constraints and may be required toprovide supplementary documentationThe countdown to entry into the EU market has begun;starting from 2026-07-01, only CASP authorization under the MiCA framework will be recognized.

  • Do not overlook procedural details:All apps must completefinancial function filingsFor any app involving tokenized digital assets or NFTs, it is necessary toprovide transparent disclosuresand refrain from narratives promising “guaranteed profits” or “high returns”; reviewers may at any time requireadditional compliance materials.

In this article, we adopt a practical perspective to address four topics: (1) a summary of the key points in Apple’s and Google’s latest app store listing rules; (2) scenarios that require licenses and circumstances under which a legal opinion may be requested; (3) compliance strategies for listing different Web3 applications; and (4) our deliverable “listing toolkit.”

 

Red Lines and Yellow Lines of the Two Major App Stores

1.Apple(App Store Review Guidelines)

  • Section 3.1.5 Cryptocurrency Provisions:

  • Wallets: Virtual currency storage functionality is permitted, but must be submitted by an organizational developer;

  • Mining: On-device mining is prohibited;

  • Exchanges: May be offered only in countries/regions where the requisite licenses have been obtained.

  • ICOs/futures/securities-like instruments: Must originate from banks, securities firms, futures commission merchants (FCMs), or other approved financial institutions, and must comply with applicable laws.

  • 3.2.1(viii):Financial transaction, investment, or wealth management apps must be submitted by the financial institution performing such services and must hold the necessary licenses in the jurisdictions where they are listed. The official page was last updated on 2025-06-09.

2. Google Play (Policies and Declarations)

  • “Cryptocurrency Exchanges and Software Wallets” Policy:

  • Non-custodial wallets: Not covered by this specific policy (though local laws must still be observed);

  • Process: Declare in the Financial Features declaration within the Play Console. If the target country is on the list, the system will issue a localized form requiring you to complete/upload local licensing or registration information. If you do not meet the requirements, distribution in that country must be removed.

  • European Union: Starting from 2026-07-01, only MiCA CASP authorization will be accepted; France and Germany have transitional arrangements prior to this date.

  • Blockchain Content and NFTs:

  • Must transparently disclose the existence and purpose of “tokenized digital assets”;

  • Must not promote “making money”; NFT lotteries, betting, and similar activities are restricted;

  • Google may request additional compliance documentation to demonstrate your adherence to regulations in the target jurisdictions.

  • Declaration of Financial Features;

  • All listed applications must complete this declaration. If options such as "crypto wallet/exchange/NFT, etc." are selected, item-by-item disclosure is required in accordance with the guidelines, and licenses or supporting documentation may need to be uploaded.

 

When is a license strictly required? When might a legal opinion be requested?

(I) High-Certainty Scenarios Requiring a License

Based on the implementation of respective provisions and practical experience, the following scenarios essentially operate under the principle of "license review prior to listing consideration":

  • Matching services/exchanges/Alternative Trading Systems (ATS), custodial wallets, fiat currency on-ramps/off-ramps/exchange services, and functionalities involving securities, derivatives, or yield-generating products.

  • Apple explicitly requires that exchange functionalities be made available only in jurisdictions where the operator holds the requisite licenses;

  • Google verifies licenses for "exchanges/custodial wallets" on a country- or region-specific basis, and non-compliant applications must be removed from the relevant country or region. The following outlines Google’s policy:

(II) Gray Areas with a High Probability of Requests for Supplemental Materials or Legal Opinions

The requirement to "submit a lawyer’s legal opinion" is not a uniform mandatory provision in the policies of both platforms. However, in the following gray areas, review teams frequently request "supplemental materials" to demonstrate the applicant’s compliance with laws and regulations in a specific jurisdiction:

  • Non-custodial wallets that additionally incorporate: fiat currency on-ramp services, yield displays, brokerage aggregation, or cross-border advertising campaigns.

  • NFTs or tokenized content that trigger transparency disclosure requirements and involve value speculation.

  • Practical experience: App store review or compliance modules may require a legal opinion or compliance statement to substantiate claims of “no securities law triggers,” “licensed,” or “exempt,” particularly for sensitive jurisdictions and financial promotion scenarios. Google’s policies also state that additional information or documentation may be required.

In such communication scenarios, a legal opinion issued by counsel—providing conditional conclusions on “whether licensing is triggered,” “whether exemptions apply,” and “which jurisdictions are open”—is a widely accepted form of documentation.

 

Listing strategies for different product models

1. Non-custodial wallets / pure on-chain tools

  • Strategy: Emphasize the factual statement that funds and private keys are not custodied; launch only in jurisdictions with clear compliance frameworks; complete financial feature declarations in the Play Console and provide transparent blockchain disclosures; avoid any language implying “returns” or “investment promises.”

2. Custody / fiat on-ramps and off-ramps / brokerage services

  • Strategy: Launch first in jurisdictions where licenses, registrations, or clear exemptions are available; use geo-fencing and differentiated versions to gradually expand to other regions; prepare proof of licenses, registration numbers, qualifications of partner institutions, and (where necessary) legal opinions; for Apple, prioritize submission through a developer account held by the licensed entity.

3. Exchanges / Alternative Trading Systems (ATS) / derivatives

  • Strategy: Plan multi-jurisdictional licensing pathways in advance (e.g., EU MiCA CASP, US FinCEN MSB registration plus state Money Transmitter Licenses (MTL) or banking licenses), and implement region-specific toggles and feature differentiation on app stores. Note that in the European Union, only MiCA authorization will be recognized from July 1, 2026 onward.

4. NFTs / tokenized digital assets

  • Strategy: Select and disclose tokenized digital assets in the Play Console; do not drive traffic using narratives centered on “making money”; applications featuring loot boxes, blind boxes, or betting elements with uncertain value are generally unlikely to pass review.

 

How we can help you (the “listing toolkit”)

As lawyers deeply engaged in the Web3 industry, here is how we can assist with the listing of your app:

  • The first step is diagnosis. 

We will use a“Function × Jurisdiction × Store”compliance matrix to align your specific features (such as custody, matching, and fiat currency or yield provisions) with each target jurisdiction, thereby deriving a“Listable / License Required / Geofencing Required / Not Recommended”four-quadrant analysis.

The deliverables include: store strategy (listing regions and phased rollout schedule), “compliant” copy for metadata and screenshots, and draft filings for financial function declarations and blockchain disclosures. These materials are intended both for reviewer assessment and for internal execution by product and operations teams.

  • The second step is the legal opinion. 

For key jurisdictions, we conduct a qualitative analysis based on facts and assumptions (including functional boundaries, fund flows, KYC/AML processes, and open jurisdictions) to address three practical questions:Whether licensing requirements are triggered, whether distribution via the store is permissible, and what disclosures and restrictions are required.The conclusions are framed in terms of “conditional compliance” (for example, listing only in Country A, subject to Process B, or with Feature C disabled), with clear reservations and scope limitations to prevent misuse or overbroad interpretation. When “supporting documentation” is required for communications with reviewers, the legal opinion serves as one of the primary materials.

  • The third step is the compliance documentation package. 

This serves as the “toolbox” for operationalizing compliance: Terms of Service, Privacy Policy (including cross-border data transfer and data residency provisions), risk disclosures and restricted jurisdictions, standard operating procedures for KYC/AML and CFT along with sanctions screening, mechanisms for segregation of client assets and handling refund complaints, key management/custody arrangements and incident response protocols, and guidelines for advertising and financial promotions compliance.

For Google, we will simultaneously prepare the necessary license or registration numbers and partner qualifications required for region-specific forms; for Apple, we will align the submitting entity and functional descriptions to minimize repeated rejections due to “entity mismatch” and “unclear feature descriptions.”

 

Conclusion

Please treat app listing as a “compliance engineering” project rather than a matter of “luck.” Unclear functional boundaries, mismatches between licenses and target distribution regions, and incomplete supporting materials will directly result in rejection during the review process. We recommend that you immediately align the following four elements—Features → Licenses/Registrations → Store Declarations → Supporting Documentation—by initially launching in jurisdictions where compliant deployment is feasible, and then steadily expanding to other regions according to a strategic matrix.

Our role is to solidify this roadmap: conducting diagnostics and developing a market entry matrix (feasibility assessment covering what is permissible, prohibited, and the method of entry), issuing legal opinions (including conclusions, conditions, and disclosures), and providing documentation packages and listing guidance (translating regulatory requirements into copywriting and backend configurations). Compliance is an ongoing process; version updates and regional expansions require renewed review. If your Web3 application encounters issues during the listing process, please feel free to contact Mankun Law Firm.