Merchant, AI Investment and Affiliate
The three modules a normal build leaves out — the STORE_RESTRICTED_MODULES build flag that compiles them in, the server switch that AI Investment and Affiliate also need, why Merchant has no switch, what each combination shows, and the store rules that make them a risk.
Three modules run into app-store rules on crypto apps: Merchant (accepting payments, from the Payment Gateway addon), AI Investment (fixed-return plans) and Affiliate (the referral programme). A normal build does not contain them. Putting them in your app takes two deliberate decisions — one when you build, one on your server — so that nobody ships them by accident.
You publish the app under your own Apple and Google developer accounts. If a reviewer rejects or removes an app for one of these modules, it is your listing and your account on the line. Build them in only if you publish outside the stores, or have decided to accept that risk.
The two locks
| Module | Build flag | Server switch | Addon it follows | KYC feature | Licence attestation |
|---|---|---|---|---|---|
Merchant (gateway) |
Needed | None | Payment Gateway | use_gateway |
Yes |
AI Investment (ai-investment) |
Needed | Allow AI Investment & MLM in the Mobile App | AI Investments | invest_ai |
Yes |
Affiliate (mlm) |
Needed | Allow AI Investment & MLM in the Mobile App | MLM & Affiliate System | — | No |
The locks come on top of the usual checks. With both open, each module still needs its addon installed, switched on and licensed, and passes the KYC and attestation checks when you enforce them — see The module manifest.
The build flag: STORE_RESTRICTED_MODULES
Add it to the build command:
flutter build appbundle --release --dart-define=STORE_RESTRICTED_MODULES=true
flutter build ipa --release --dart-define=STORE_RESTRICTED_MODULES=trueThe same flag works with flutter build apk and flutter run. It is the only
--dart-define the app reads; its other settings come from app_config.json.
Without it, the three screens are not in the app at all. The flag is a compile-time constant, and every route into the three modules sits behind it, so a normal build does not merely hide them — the compiler leaves them out.
That is the point of doing it at build time. A screen shipped in the binary and switched on later from a server is what Apple's guideline 2.3.1 calls a hidden feature, which the guidelines forbid. Code the compiler removed is not hidden; it is not there.
What follows from it:
- It is per build. A build made without the flag cannot be given these screens later by any setting. You need a new build and a store update.
- Pass it every time. Forget it on one release and that release silently has no Merchant, AI Investment or Affiliate tiles.
- Nothing records it. No build tool, including the release preflight, checks or reports whether a build was made with the flag. Keep your own note of which releases carry it.
In a build made with the flag, the three tiles join the end of the Trading Tools row on Home — Merchant ("Accept payments", badge "Business"), AI Investment ("Investment plans", badge "Plans") and Affiliate ("Referral programme", badge "Referral") — when the server allows them.
The server switch
Admin → System → Platform Settings (/admin/system/settings), tab
Features, group Verification: Allow AI Investment & MLM in the Mobile
App. It ships off. Its description in the admin panel says:
Offer AI Investment and the referral (MLM) programme in the mobile app as well as on the website. App Store and Google Play rules do not permit fixed-return investment products or paying currency for recruiting users, so apps carrying either are commonly rejected or removed. You publish the app under your own developer account, so that rejection risk is yours. Off by default; the website is unaffected either way. The app shows these screens only if it was also built with STORE_RESTRICTED_MODULES=true. Binary options and forex investment plans stay unavailable in the app whatever this is set to.
While it is off:
- The module manifest reports
ai-investmentandmlmasDISABLED(orNOT_INSTALLEDwhen the addon is missing), so their tiles are absent, even in a build made with the flag. - Your server refuses the app's AI Investment requests — the plan list, the customer's investments, starting one, opening one and cancelling one — with HTTP 403 and: "AI Investment is not available in the mobile app. It offers a fixed return over a fixed duration funded from a custodial wallet, which app-store rules on financial products do not permit."
- It refuses claiming an affiliate reward from the app with: "The multi-level referral programme is not available in the mobile app. App-store rules bar a cryptocurrency app from offering currency for recruiting other users."
While it is on, both modules follow their addons like any other module. AI Investment is also licence-gated: with attestation enforcement on, it needs a licence row for the customer's country. A licence row for AI Investment changes nothing in the app while this switch is off.
The website is never affected by this switch. Like every change to what the app shows, turning it on or off changes the tiles a signed-in customer sees the next time they sign in or reopen the app. The refusals above do not wait for the app: your server checks the switch on each request.
Merchant has no server switch
Merchant needs only the build flag. After that, it is an ordinary module: the
tile appears when the Payment Gateway addon is installed, switched on and
licensed, and it opens when the customer also passes the use_gateway KYC
feature and — with attestation enforcement on — the licence check. A customer
who fails either of those sees the tile dimmed, with the reason. Accepting payments on behalf of
others is a regulated payment service almost everywhere, which is why Merchant
is one of the nine licence-gated modules. With attestation enforcement on,
becoming a merchant from the app is also refused to a customer whose country
has no Merchant licence row, with the same country refusal as the other
licence-gated modules.
The Payment Gateway's own settings do not hide the tile. In particular its
enable setting (gatewayEnabled) is deliberately not what the manifest reads,
so that an existing merchant keeps a way to their refunds and balance.
To keep Merchant out of an app built with the flag, the options are:
- Build without the flag — the only way that also removes AI Investment and Affiliate from the binary.
- Switch the Payment Gateway addon off — which switches it off on your website too.
Recording no Merchant licence row, with attestation enforcement on, does not remove the tile: it shows dimmed, with the message that Merchant is not offered in the customer's country — or, when the server does not know their country, the message asking them to add it.
What each combination shows
| Build flag | Server switch | Merchant | AI Investment | Affiliate |
|---|---|---|---|---|
| Off | Either | Not in the app | Not in the app | Not in the app |
| On | Off | Follows Payment Gateway | Absent; the server refuses the app | Absent; reward claims refused |
| On | On | Follows Payment Gateway | Follows AI Investments | Follows MLM & Affiliate System |
"Follows" means the normal manifest checks decide: addon installed, switched on and licensed, then attestation and KYC where they apply.
Why the stores object
The server's own refusal texts give the short version: a fixed return over a fixed duration from a custodial wallet, and currency paid for recruiting users. Apple's cryptocurrency rules say it outright for the second — guideline 3.1.5(v): cryptocurrency apps "may not offer currency for completing tasks, such as … encouraging other users to download". The package's installation guide puts merchant payment processing in the same group, as something both stores restrict in crypto apps; it is also a regulated payment service almost everywhere, which is why Merchant is licence-gated.
Nothing about your server configuration cures these objections. A licence row changes who in which country can use a module; it does not change what the product is.
Before you decide, read Before you buy, Licences by country and Licence attestations.
What no switch unlocks
Binary options, forex investment plans and launching a token (the ICO creator side) are never in the app, whatever the flag and the switch say. They have no screens, no module entry, and your server refuses them to the app. The full list, with the server's wording, is on What is in the app.