Guide · 9 min read
App Store Age Verification Laws 2026: What Indie Developers Must Do Across 4 States
Three US states — Texas, Utah, and Louisiana — already have enforceable app store accountability laws requiring parental consent for minor users, and California follows on January 1, 2027. There is no exemption for indie developers or small teams. No grandfathering for apps that predate the laws. The compliance steps are specific and technically achievable, but the developer community has been slow to act. Here is exactly what each law requires, state by state, and what you need to implement before December 31, 2026.
Four States, Four Laws: What Texas, Utah, Louisiana, and California Each Require
Four US states have enacted app store accountability legislation with active developer obligations. Texas SB 2420 has been enforceable since January 2026 — the Fifth Circuit Court of Appeals stayed a preliminary injunction blocking it on May 28, 2026, putting the law back in force. A Supreme Court application to vacate that stay remains pending as of publication, so Texas enforcement could shift, but the legal default today is that it applies to you. Utah SB 142 placed developer obligations in effect May 6, 2026. Louisiana Act 481 went into effect July 1, 2026. California's Digital Age Assurance Act takes effect January 1, 2027.
What the laws share: all four require developers to request an age category signal from the app store at download, purchase, or first launch — and to use that signal to enforce any age-based restrictions in the app. Texas, Utah, and Louisiana additionally require parental consent for users under 18, meaning both an age bracket and a consent flag must be consumed and respected. California is the lightest: it requires only an age gate (four brackets — under-13, 13–15, 16–17, 18+) with no parental consent requirement.
The laws draw a hard line between app store obligations and developer obligations. The app store — Apple or Google — is responsible for verifying user age at account setup. You, the developer, are responsible for requesting and acting on the verified result via the store's API. You are not building a verification system from scratch. That means the compliance burden is real but bounded: it is an API integration, not an identity infrastructure project.
Apple and Google Handle the Verification — Your App Consumes the Signal
You never touch unverified user age data under these laws. Apple and Google verify age at account creation using trusted signals (payment method, government ID in supported markets, Family Sharing parental controls). Your app receives a pre-verified age category — one of four brackets — and a parental consent status. On iOS 18+, the relevant path is the FamilyControls / AuthorizationCenter framework and the age category APIs Apple has wired up for these state compliance requirements. On Android, the Google Play Families API provides equivalent age category and parental consent signals at install and first launch.
The query must happen at a specific moment: when the user downloads, purchases, or first launches a pre-installed app. You cannot defer the check to a later session. Under Utah's requirements specifically, you are permitted to re-query age category data only once per 12-month period after the initial check. If you query at install time via the app store API, you do not need to re-query on first launch — confirm which event is the trigger in your implementation before shipping.
Neither Apple nor Google has published documentation labeled explicitly as "age verification act compliance." The signals come through existing FamilyControls / Family Sharing and Play Families frameworks. Apple's App Store Review Guidelines now note that apps in covered states should check age category and parental consent at first launch. Build this into your app launch sequence before any paywall, feature gate, or onboarding prompt.
App Age Rating: The Required Prerequisite You May Have Gotten Wrong
Before you can comply with any of these laws, your app must have an accurate age rating in both App Store Connect and Google Play Console. Your age rating determines what bracket restrictions apply to your app and what the app store gates for underage users. If your app is currently rated 4+ or Everyone when its content warrants a higher rating, that is a compliance risk — and a policy risk with Apple and Google independently. The app content rating questionnaire guide covers the most common answers that result in an inaccurate rating for indie apps.
The age rating you assign has a direct consequence under these laws: an app rated 17+ (iOS) or Mature 17+ (Play) requires parental consent for every download by a user under 18 in Texas, Utah, and Louisiana. An app rated 4+ for a productivity tool that added a social feature or user forum — and never updated its rating — is under-rated. Under-rating is not a minor documentation error once parental consent requirements are in force; it is a misrepresentation that shifts your exposure from an unintentional oversight to a knowing violation.
App Store Connect lets you revise your age rating answers in App Information without submitting a new binary. Google Play uses the IARC certification system, which recalculates your rating automatically based on updated questionnaire answers. Review your questionnaire answers before December 31, 2026 — not as part of your next version submission, but as a standalone update now.
The "Significant Change" Pre-Notification Rule: What Triggers It
All four state laws require developers to notify app store providers before shipping a "significant change" to the app. A significant change includes any material modification to: your terms of service, your privacy policy, your app's content rating, your monetization features (adding a subscription, changing pricing tiers), or the core user experience. This is not a paperwork checkbox — failure to pre-notify is explicitly listed as a violation in the Texas and Utah statutes.
In practice, this means treating major version submissions differently from bug-fix releases. Before submitting a version that adds in-app purchase or subscription functionality where none previously existed, update App Store Connect and Play Console to reflect that change before or simultaneously with the binary submission — not after. Apple's existing metadata update process is already the mechanism: updating your privacy policy URL, age rating, or in-app purchase configuration in App Store Connect constitutes the app store notification the statute requires under its plain text.
The significant change rule also intersects with metadata decisions that seem minor. Adding a social or user-generated content feature to your app — which triggers a separate disclosure under Apple's September 2026 social media capability disclosure requirement — also triggers the pre-notification requirement in covered states. A single update that adds social features, a new subscription tier, and a revised privacy policy needs all three reflected in App Store Connect metadata before the binary goes live.
Age Data Handling: Delete After Use, Share With Nobody
All four state laws prohibit sharing age category data with third parties and require deletion once it has served its compliance purpose. This creates a direct conflict with standard analytics and ad SDK defaults. If you pass the age category signal to your analytics SDK, attribution tool, or ad network as a user property, you are likely violating the law in covered states. Audit every SDK in your app that receives user properties before adding age category to your user object.
The deletion requirement means: after you have applied the age category signal to make an access control decision, you do not retain it as a persistent user attribute. You do not need to re-query on every app launch once you have made the initial determination — but you cannot store the raw age bracket in your own database indefinitely. Your App Store privacy nutrition label should not declare "Age" under Data Collected unless you are actively retaining and processing it for an explicitly declared purpose.
The practical implementation: consume the API response, apply any feature gating the returned bracket and consent status warrant, and do not write the raw age bracket to your own user record. If you need to remember that a user is a verified adult across sessions (to skip the re-query), store a boolean — age_verified: true — rather than the bracket itself. On Android, the Play Families API returns consent and age tier at install time; the same handling applies.
Utah's Private Right of Action: Parents Can Sue Developers for $1,000+ Per Violation Starting December 31, 2026
Most app compliance requirements are enforced by a state attorney general — not individual parents. Utah is different. Starting December 31, 2026, parents can file civil lawsuits directly against developers (not just app stores) for violations of the Utah Minor Protection in App Marketplace Act. Statutory damages start at $1,000 per violation, with no requirement to prove actual harm. For a subscription app with thousands of minor users, that exposure is significant enough to treat Utah compliance as a hard deadline, not a backlog item.
What counts as a violation under Utah's private right of action: failing to request age category from the app store at download or first launch; using or sharing age category data for purposes beyond compliance; failing to enforce developer-set age restrictions based on received signals; and re-querying age data more than once in a 12-month period. That last point is a notable constraint — the re-query limit means you cannot use the age API as a periodic user attribute refresh mechanism. It is a compliance signal, not a data source you poll.
Texas and Louisiana do not currently include a private right of action for parents — enforcement runs through the state AG. California's enforcement mechanism for its January 2027 law had not been finalized as of publication. That asymmetry makes Utah the highest-stakes compliance deadline for indie developers: Texas and Louisiana are AG-enforcement risks, but Utah is a direct litigation risk with a December 31, 2026 countdown.
5-Step Compliance Checklist for Indie Developers
Step 1 — Audit and correct your age rating. Open App Store Connect (App Information → Age Rating) and Google Play Console (Content Rating). Re-take the questionnaire with your current app state, including any social features, user-generated content, or in-app purchases added since you originally rated the app. If your current rating is wrong, correct it now. Step 2 — Integrate the age category API. For iOS, implement the FamilyControls framework query at first launch or at download via the purchase API. For Android, integrate the Google Play Families API. Query once at the correct trigger event, apply any feature gating the response warrants, and do not pass the raw result to any third-party SDK.
Step 3 — Update your metadata pre-notification workflow. Before shipping any update that changes your ToS, privacy policy, age rating, monetization model, or core UX, confirm that App Store Connect and Play Console reflect the change before the binary submission. This is a process change to your release workflow, not a code change. Step 4 — Review all third-party SDKs for age data handling. Document that no analytics, ad, or attribution SDK in your app receives the age category signal. Delete the data after use; store only the boolean result if you need session persistence.
Step 5 — Watch the Texas litigation. The CCIA Supreme Court application to vacate the Fifth Circuit stay is pending as of mid-2026 — Texas enforcement status could change on short notice. Utah, Louisiana, and California are not currently under any injunction. Treat all four states as in-scope for your compliance implementation, but build your Texas-specific tracking infrastructure conservatively until the Supreme Court rules. Use the app listing editor to confirm your metadata is consistent across your App Store Connect records — mismatches between your listed privacy policy, age rating, and app binary are the first thing a review or enforcement action will surface.
The compliance window is closing
Utah's private right of action starts December 31, 2026 — fewer than 90 days from publication of this guide. The technical compliance steps are straightforward: age rating audit, API integration, metadata workflow update, SDK review. None of these require a legal team. What they require is prioritizing this before the next feature sprint.
Developers who act now avoid the version of this problem where a compliance gap gets discovered by a parent's attorney rather than an internal audit.
Review your app listing in the editor →
Frequently asked questions
do these app store age verification laws apply to indie developers?
Yes — there is no exemption for small developers, solo developers, or apps with limited revenue. All four state laws (Texas, Utah, Louisiana, California) apply to any developer whose app is distributed through a covered app store, regardless of company size. Utah's private right of action starting December 31, 2026 creates direct litigation risk for any developer with minor users in Utah, without any minimum revenue or install threshold.
does my app need to comply if it is not directed at children?
Yes. These laws cover all apps available through covered app stores, not just apps specifically directed at children. The legal standard is whether a minor user can download your app — not whether your app targets children. If your app is rated 4+ or 12+ (iOS) or Everyone or Teen (Play), a user under 18 can download it, which triggers the age verification and parental consent requirements in Texas, Utah, and Louisiana. Apps rated 18+ effectively restrict minor downloads at the platform level, which satisfies the laws.
how do i assign an age rating to my app in app store connect?
In App Store Connect, navigate to your app's page and select App Information from the left sidebar. Under the General Information section, click Edit next to Age Rating. This opens the interactive questionnaire covering content categories (violence, mature themes, gambling, etc.). Your rating is calculated automatically from your answers. You can update your answers and rating at any time without submitting a new binary — the change goes live as a metadata-only update. See the <a href='/guides/app-content-rating-questionnaire-guide'>content rating questionnaire guide</a> for the specific answer choices that trip up indie devs most often.
what counts as a "significant change" that requires pre-notification to the app store?
Under Texas SB 2420 and Utah SB 142, a significant change includes: material modifications to your terms of service or privacy policy, changes to your age rating, additions or modifications to in-app purchases or subscription tiers, and material changes to the core user experience. Adding a social or community feature, a new paywall, or a revised data collection policy all qualify. The pre-notification mechanism under plain interpretation is App Store Connect itself — updating your metadata to reflect these changes before the binary submission satisfies the requirement.
does california also require parental consent for app downloads?
No. California's Digital Age Assurance Act (effective January 1, 2027) requires only an age gate — your app must request and receive an age category signal from the app store at download, but parental consent is not required. California uses the same four-bracket system (under-13, 13–15, 16–17, 18+) as the other state laws, but the developer obligation stops at consuming the signal and acting on it, not obtaining parental approval for under-18 users. This makes California the lightest of the four state laws.