Skip to content
assetlib

Questions

Are remote images and over-the-air artwork changes allowed by the App Store and Google Play?

Loading images from a server is ordinary app behavior and both stores allow it; most apps with a feed, a catalog, or a profile photo do it. The rules that people worry about are about code: Apple's guideline 2.5.2 says apps may not download or execute code that introduces or changes features or functionality, and Google Play's device and network abuse policy forbids downloading executable code from outside Play. Artwork in a slot the app already has is not executable code and does not change what the app does.

Updated October 9, 2026 · Assetlib

Where is the line?

Reviewers care whether the app they reviewed is the app users get. Swapping the illustration on an onboarding screen leaves the app's features, flows, and purpose as reviewed. Using remote content to reveal a feature that was hidden during review, or to turn a reviewed app into something with a different purpose or age rating, is what the guidelines are written against, however the content is delivered. Keep remote artwork within the app's reviewed purpose and content rating, and keep the reviewed features visible.

Both stores also publish their own routes for large downloadable content: Apple's Background Assets with App Store Connect hosting and Google's Play Asset Delivery. Those exist for asset packs of hundreds of megabytes, with their own review and hosting rules. Small images that an app already has placements for are ordinary remote content.

I read that someone was terminated for using Remote Config. Should I worry?

Reports like that circulate, and the details are usually missing. Remote configuration itself is used by a very large share of apps on both stores. The cases that end badly tend to involve what the configuration unlocked, not the mechanism. If your remote values only choose between images, there is nothing to unlock. If a remote value could enable a feature reviewers did not see, that is the thing to fix, regardless of the tool.

What does Assetlib deliver, exactly?

Image bytes and, in the JavaScript preview, validated Lottie JSON, each listed in a release manifest that the app verifies against a public key you ship in the build. The SDK checks the signature, the byte count, the content hash, and the declared dimensions before it exposes an image, and it falls back to the bundled image otherwise. No code, no scripts, no URLs outside your workspace's delivery origin. The engineering details are in the SDK source.

This page describes how the product is built and how the published guidelines read. It is not legal advice about your listing, and review outcomes are the stores' decisions.