The app legal checklist, with an AI audit prompt
9 ways app builders get fined or sued without knowing it, other legal blockers to check before launch, and a prompt that has your AI agent check your code.

Matt Neves··6 min read
On this page
Every item on this list comes with real money behind it: penalties set by law, users who can sue, and companies that have already paid the FTC. Most founders who get caught didn't set out to break a law. They shipped a signup flow, an SDK or a subscription screen without knowing the rule existed.
This is the checklist I use to catch those before launch, plus a prompt that has your AI coding agent check your app for all of them.
This is not legal advice. It's a free, educational starting point I put together from public sources (linked on every item), researched in September 2026. It isn't a complete list of the laws that apply to you, laws change, and which ones apply depends on where you and your users are. Nothing here creates a lawyer-client relationship. Do your own research, and talk to a qualified lawyer before making legal decisions about your app.
How to use it
Go down the list and mark each item done, needs work or doesn't apply. Then run the prompt at the bottom inside your app's code (Claude Code, Cursor or Codex). It checks your actual code for these issues and gives you a fix list, plus the questions worth taking to a lawyer.
The 9 from the video
1. Marketing emails with no unsubscribe link
- Every marketing email has a clear, working way to opt out, and opt-outs are honored within 10 business days.
- The email includes your valid physical postal address.
- The from name and subject line aren't misleading, and ads are identified as ads.
Why it matters: the FTC says each separate email that violates CAN-SPAM can cost up to $53,088. FTC CAN-SPAM guide
2. Texting users promotions they never agreed to
- You have clear consent before sending marketing texts, and you keep a record of it. A phone number typed in for login codes is not consent to marketing.
- STOP works, and opted-out numbers never get another marketing text.
Why it matters: under the TCPA, people can sue for $500 per violation, and a court can triple it to $1,500 if the violation was willful or knowing. 47 U.S.C. § 227
3. Not having a privacy policy
- You have a privacy policy that matches what your app actually collects, why, and who it's shared with.
- It's linked in your app, on your site and in your App Store listing (Apple requires this for every app).
Why it matters: California's privacy law (CalOPPA) requires a posted privacy policy if you collect personal information from Californians, and the California Attorney General warned app developers that "companies can face fines of up to $2,500 each time a non-compliant app is downloaded." California AG, 2012
4. Fake reviews on your landing page
- Every review and testimonial comes from a real customer and reflects their real experience. No invented customers, no AI-generated fake reviews.
- You never bought followers or views to look bigger than you are.
- You disclose when a reviewer got something in return (free access, payment, a relationship).
Why it matters: the FTC's rule banning fake reviews took effect in October 2024. It specifically calls out AI-generated fake reviews and followers or views generated by a bot, with civil penalties of up to $53,088 per violation. FTC fake reviews rule
5. Saying your AI can do something it can't
- Every claim about your AI (accuracy, "replaces a lawyer/doctor/accountant", "fully automated") is something you've tested and can back up.
- The marketing matches what the product actually does today, not the roadmap.
Why it matters: DoNotPay marketed itself as "the world's first robot lawyer." The FTC's final order required it to pay $193,000 and notify past subscribers. FTC DoNotPay order
6. Your privacy policy says you don't share data, but your analytics tools do
- You know every SDK and pixel in your app (analytics, ads, crash reporting, session replay, AI providers) and exactly what each one receives.
- What they receive matches what your privacy policy promises. Health, financial and other sensitive data gets extra care.
Why it matters: according to the FTC, GoodRx promised users it would never share their health information with advertisers, then shared it with Facebook, Google and others through tracking tools. GoodRx agreed to a $1.5 million civil penalty. FTC GoodRx action
7. Scanning faces without consent
- If your app (or a vendor you use) creates face geometry, voiceprints or fingerprints, you get written consent first and publish a retention and deletion policy.
- You know whether you have users in states with biometric laws (Illinois, Texas and Washington, for example).
Why it matters: under Illinois' biometric privacy law (BIPA), people can sue for $1,000 per violation, or $5,000 if it was intentional or reckless. Facebook settled its BIPA class action over photo face-tagging for $650 million. 740 ILCS 14/20 · CBS News / AP
8. Collecting data from kids without their parents' consent
- If your app is aimed at kids under 13, or you know kids under 13 use it, you follow COPPA: verifiable parental consent before collecting their personal information, plus the notices and deletion rights that come with it.
- The SDKs in your app don't collect kids' data behind your back.
Why it matters: Epic Games agreed to pay a $275 million penalty for violating children's privacy law with Fortnite. It was the largest penalty ever for breaking an FTC rule at the time. FTC Epic Games action
9. Making your subscription hard to cancel
- Price, trial length, renewal and how to cancel are shown clearly before anyone pays, and they actively agree to it.
- Canceling is simple, and it actually stops the billing. Test it.
Why it matters: Amazon agreed to pay $2.5 billion ($1 billion civil penalty plus $1.5 billion in refunds) to settle FTC allegations that it signed people up for Prime without clear consent and made it "exceedingly difficult to cancel." Some states, including California, have their own auto-renewal laws on top of federal law. FTC Amazon settlement
More legal blockers worth checking
Not every one of these applies to every app. They're the ones that come up most for indie builders.
- Account deletion. Apple requires apps that let people create an account to also let them delete it from inside the app, and Google Play has a similar rule. Apple guideline 5.1.1(v)
- App Store privacy labels and Play Data safety. Your store disclosures should match what your app and its SDKs actually collect.
- Terms of service. Your rules, refund terms and limits on your liability, written down before people pay you.
- Users outside the US. If you have users in the EU or UK, GDPR can apply to you even as a US company. That can mean consent for non-essential tracking, and letting people access and delete their data. European Commission
- US state privacy laws. California and a growing list of states give users rights over their data once your business crosses their thresholds.
- Security basics. No API keys or secrets in your app or frontend code, database rules that stop users from reading each other's data (row-level security if you're on Supabase), and a plan for what you do if data leaks. Every US state has a data breach notification law.
- Your name, logo and assets. Search your app name for existing trademarks before you invest in it (USPTO search), and make sure you have the rights to your fonts, images, music and any open-source code you ship (some licenses, like the GPL, come with obligations).
- Accessibility. Web and app accessibility lawsuits are common in the US. Test your core flows with a screen reader and readable contrast. DOJ guidance
- Taxes on web payments. Apple and Google generally handle sales tax and VAT on in-app purchases. If you sell on the web (Stripe, for example), that can become your job.
- Regulated features. Health, money, gambling, and AI that makes decisions about people (hiring, lending, housing) come with their own rules. Get a specialist review before you launch those.
The prompt
Paste this into Claude Code (or Cursor or Codex) opened in your app's repo. Fill in the brackets first. It works read-only, so it won't change anything until you tell it to.
You are reviewing my app for legal and compliance risks. This is educational issue-spotting, not legal advice, and you must not tell me my app is "compliant" or "legally safe". Your job is to find likely problems in my actual code, show me the evidence, and give me a practical fix list plus the questions I should take to a lawyer.
About my app:
- What it does and who it's for: [FILL IN]
- Platforms (iOS / Android / web): [FILL IN]
- Where my company is and where my users are (countries / US states): [FILL IN]
- Could kids under 13 use it? [FILL IN]
- Do I send marketing emails or texts? With what provider? [FILL IN]
- Do I charge subscriptions? Through what (App Store, Google Play, Stripe)? [FILL IN]
- Anything else sensitive (health, money, biometrics, AI features): [FILL IN]
Work READ-ONLY until I say otherwise. Do not send emails or texts, charge cards, touch production data or deploy anything. Never print secrets or real user data in your answer; redact them.
Step 1. Map the app. Find every place it collects personal data (forms, signup, analytics events, uploads, camera/mic, location), every third-party SDK, pixel and API it sends data to, and every email, SMS, subscription and account flow. List what you inspected and what you could not see (dashboards, vendor settings, contracts).
Step 2. Check each of these against the code, citing file:line or the screen/route as evidence:
1. Marketing emails: working unsubscribe, physical address, honest from/subject lines (CAN-SPAM).
2. Marketing texts: consent captured and stored before sending, STOP handling, opt-out suppression (TCPA).
3. Privacy policy: exists, is linked in the app, site and store listing, and matches what the code actually collects and shares (CalOPPA, App Store rules).
4. Reviews and testimonials: any hardcoded, invented or AI-generated reviews, fake user counts or fake social proof on the landing page (FTC fake reviews rule).
5. AI claims: marketing copy that promises more than the product does, especially "replaces a lawyer / doctor / accountant" (FTC).
6. Data sharing: what each analytics, ad, crash, session-replay and AI SDK receives, including URLs, event properties and identifiers, compared with the privacy policy. Flag any health, financial or other sensitive data going to third parties.
7. Biometrics: any face geometry, face matching, voiceprints or fingerprints created by my code or a vendor, and whether written consent and a retention policy exist (Illinois BIPA and similar state laws).
8. Kids: signs the app targets or knowingly serves under-13s, and whether parental consent exists before collecting their data (COPPA), including what SDKs collect.
9. Subscriptions: price, trial, renewal and cancellation terms shown before purchase, explicit consent, and a simple cancellation path that actually stops billing (ROSCA and state auto-renewal laws).
10. Also check: in-app account deletion, App Store privacy label / Play Data safety accuracy, terms of service, secrets or API keys in client code, database access rules (e.g. Supabase row-level security), GDPR basics if I have EU/UK users, accessibility of the core flows, and licenses for fonts, images and open-source code.
Step 3. For every law you cite, look up the current primary source (the statute, regulation or regulator's page) and link it. If you can't browse, say the claim is unverified instead of relying on memory. Don't assume a law applies just because a feature exists; say what would make it apply. Don't multiply maximum penalties by my user count.
Step 4. Give me:
A. What you checked, what you couldn't check, and the assumptions you made.
B. A prioritized table: issue | evidence (file:line or screen) | rule and source link | why it may apply | confidence | suggested fix | how to verify the fix | lawyer needed? (yes/no)
C. Quick fixes I can ship today, product decisions I need to make, and a short list of questions for a lawyer.
D. What still needs evidence from outside the code (vendor dashboards, consent records, contracts).
Then stop and wait. Only make changes after I approve them, on a separate branch, and test each fix.
AI can miss problems and can be wrong about the law. Use its findings as a to-do list, not a verdict, and check anything important with a lawyer.
Sources
All the numbers above come from these primary sources, checked September 2026: FTC CAN-SPAM guide · 47 U.S.C. § 227 · California AG · FTC fake reviews rule · FTC DoNotPay · FTC GoodRx · 740 ILCS 14/20 · CBS News / AP · FTC Epic Games · FTC Amazon
Get better at growing apps.
New case studies and guides on how apps grow. Free, straight to your inbox.

Written by Matt Neves
I study how apps grow and break down the case studies for 12,000+ app builders as @agenticmatt. I test what I learn on my own apps, like Prospect Ping (2,500+ users).
More about meKeep reading
Acquisition · 5 min read
Design App Store screenshots with ChatGPT
Turn raw simulator screenshots into a polished, on-brand App Store set, with a hero frame and feature frames, using a guided ChatGPT workflow.
Acquisition · 2 min read
Get your app recommended by AI (AI SEO)
A 3-step prompt process to find out why ChatGPT, Claude, Grok and Perplexity aren’t recommending your app, and exactly how to fix it.
Growth loops · 10 min read
Pick the referral program that fits your app
Discounts don’t make people share. How Harry’s, Morning Brew and Robinhood chose their rewards, how to pick one for your app, and a prompt that designs it.