Skip to main content
HatchCheck
Open menu

HatchCheck cookie preferences

Essential only. Optional cookies need your choice.

Method and limits

Independent from the implementer—not independent certification.

HatchCheck is an evidence and recheck service for founder-built mobile apps. These five answers explain the boundary before you share anything.

HatchCheck, a Lungeable product. Operated by X&R Ventures LLC.

What does HatchCheck check?

HatchCheck compares the safe launch materials you provide with current Apple and Google guidance HatchCheck tracks, plus clearly labeled internal checks. Missing evidence stays not verified.

What does independent mean?

HatchCheck is separate from the coding tool, developer, or freelancer implementing the fix. It is not certification, Apple or Google affiliation, legal approval, or an outcome guarantee.

What should I never upload?

Never upload credentials, private keys, signing certificates, production environment files, customer or payment data, private links, raw logs, cookies, tokens, or real demo passwords.

Who reviews the report?

Xuru Ren performs routine private manual beta reviews. Automation prepares evidence-linked findings, but serious findings are checked before delivery. Paid activation remains paused until a named backup reviewer and calibration record exist. Sensitive or ambiguous issues can remain marked for appropriate human or legal review.

What does HatchCheck not guarantee?

HatchCheck does not guarantee approval, certify legal compliance, submit the app, or verify anything the checked evidence does not support.

Current validation status

Xuru Ren's use of HatchCheck on Lungeable launch-preparation work is first-party product dogfooding. It is not independent customer validation, certification, or evidence that production and commercial gates are complete. Backup reviewer coverage and reviewer calibration remain incomplete.

How HatchCheck reaches a decision

Tracked sources were last reviewed July 11, 2026. The registry records each source, allowed claim scope, mapped rules, freshness status, and review decision. Source-refresh checks flag stale or changed records for owner review; they do not silently convert changed guidance into a pass.

  1. 1Compare the evidenceHatchCheck compares the supplied material with tracked Apple or Google sources and clearly labeled internal checks.
  2. 2Record every supported findingEach serious finding keeps its evidence, severity, confidence, source or heuristic, recommended change, exact proof request, and any separate-review flag.
  3. 3Select one current taskHatchCheck selects the most serious supported issue for the included developer-ready task while keeping every other finding open.
  4. 4Independently recheck proofA developer or coding-tool claim does not change a finding by itself. HatchCheck checks the returned proof for the recorded scope and preserves the original report.
Data and retention
  • Project and app profile details
  • Guided intake answers
  • Safe launch artifacts and metadata
  • Selected-file scanner summaries
  • URL check results
  • Findings, evidence items, reports, and report exports
  • Read-only integration summaries where a customer explicitly connects or provides them
  • Audit logs and security event summaries
  • Private-link access and record retention are separate. A private link can expire while limited records remain under the published policy; retention does not guarantee recovery of expired material.
  • Planned artifact retention target: 90 days unless a project/report policy says otherwise.
  • Planned report retention target: 365 days unless delivered-report policy requires retention.
  • Planned audit log retention target: 730 days.
  • Until automated retention is fully available, users can request deletion, export, correction, or account-closure support by emailing privacy@gohatchcheck.com.
Access and security
  • Project access is checked on the server. Sensitive operations use safe audit metadata.
  • Selected safe files are optional. A full repository is not required.
  • HatchCheck is not SOC 2 certified and does not claim production operations are fully proven.
AI and integrations
  • No real AI provider call is required for the current V1 checkup flow.
  • If AI assistance is added to a report step, customer content must be redacted, schema-validated, and governed by the configured provider settings before use.
  • Secrets, raw provider payloads, raw customer data, and production credentials must be excluded before AI use.
  • AI output must pass schema validation, prohibited phrase scanning, evidence requirements, and source/rule grounding before it can be treated as report-ready.
  • HatchCheck does not auto-submit to Apple or Google.
  • HatchCheck avoids write-access platform integrations in this workflow.
  • Future integrations will use minimal scopes, encrypted token references, revoke/disconnect behavior, and server-side access checks.
Support, refunds, and data requests
  • For report delivery, upload, refund, satisfaction-review, or product-quality concerns, email support@gohatchcheck.com with the project/report or order reference and a short summary.
  • Paid report support includes a draft satisfaction-review path when a report is generic or not app-specific. A later Apple or Google rejection by itself is not a refund reason.
  • Deletion, export, correction, account-closure, or upload-security concerns can be sent to privacy@gohatchcheck.com while automated controls mature.

Keep private material out

Start with safe screenshots, public links, store drafts, review notes, and short summaries. If you are unsure whether material is safe, do not upload it.

Ready for an independent evidence review?

Start with a no-charge fit request. Missing optional material is allowed and remains not verified.