Binary stays out of reach
cleartextTrafficPermitted and custom trust stores are APK problems. Listing scans should name that limit instead of inventing a green “secure transport” badge.
AuditHQ lists binary checks as out of scope and focuses on what the Play page already exposes.
Signals that move installs
Data Safety / tracking copy that fights the privacy policy.
Privacy URL missing, on HTTP, or unreachable.
Developer identity gaps: no website, no support link, free-email contact.
Review clusters about unauthorized charges or password phishing.
Open high/medium findings on the developer or privacy host from the same website scanner used for sites.
Fix loop
Align Data Safety with the policy and the binary. Host the policy on HTTPS. Add a real support URL.
Run an AuditHQ Android listing audit after each Console change so the public story matches what you ship.