MMashDiv

Merchant, AI Investment and Affiliate

The three modules a normal build leaves out — the STORE_RESTRICTED_MODULES build flag that compiles them in, the server switch that AI Investment and Affiliate also need, why Merchant has no switch, what each combination shows, and the store rules that make them a risk.

6 min readUpdated 26 September 2026mobile, restricted, merchant, ai-investment, affiliate, mlm, build, store-review

Three modules run into app-store rules on crypto apps: Merchant (accepting payments, from the Payment Gateway addon), AI Investment (fixed-return plans) and Affiliate (the referral programme). A normal build does not contain them. Putting them in your app takes two deliberate decisions — one when you build, one on your server — so that nobody ships them by accident.

You publish the app under your own Apple and Google developer accounts. If a reviewer rejects or removes an app for one of these modules, it is your listing and your account on the line. Build them in only if you publish outside the stores, or have decided to accept that risk.

The two locks

Module Build flag Server switch Addon it follows KYC feature Licence attestation
Merchant (gateway) Needed None Payment Gateway use_gateway Yes
AI Investment (ai-investment) Needed Allow AI Investment & MLM in the Mobile App AI Investments invest_ai Yes
Affiliate (mlm) Needed Allow AI Investment & MLM in the Mobile App MLM & Affiliate System — No

The locks come on top of the usual checks. With both open, each module still needs its addon installed, switched on and licensed, and passes the KYC and attestation checks when you enforce them — see The module manifest.

The build flag: STORE_RESTRICTED_MODULES

Add it to the build command:

flutter build appbundle --release --dart-define=STORE_RESTRICTED_MODULES=true
flutter build ipa --release --dart-define=STORE_RESTRICTED_MODULES=true

The same flag works with flutter build apk and flutter run. It is the only --dart-define the app reads; its other settings come from app_config.json.

Without it, the three screens are not in the app at all. The flag is a compile-time constant, and every route into the three modules sits behind it, so a normal build does not merely hide them — the compiler leaves them out.

That is the point of doing it at build time. A screen shipped in the binary and switched on later from a server is what Apple's guideline 2.3.1 calls a hidden feature, which the guidelines forbid. Code the compiler removed is not hidden; it is not there.

What follows from it:

  • It is per build. A build made without the flag cannot be given these screens later by any setting. You need a new build and a store update.
  • Pass it every time. Forget it on one release and that release silently has no Merchant, AI Investment or Affiliate tiles.
  • Nothing records it. No build tool, including the release preflight, checks or reports whether a build was made with the flag. Keep your own note of which releases carry it.

In a build made with the flag, the three tiles join the end of the Trading Tools row on Home — Merchant ("Accept payments", badge "Business"), AI Investment ("Investment plans", badge "Plans") and Affiliate ("Referral programme", badge "Referral") — when the server allows them.

The server switch

mobileAllowRestrictedProductstype: switchdefault: false
Offer AI Investment and the referral programme in the mobile app as well as on the website.

Admin → System → Platform Settings (/admin/system/settings), tab Features, group Verification: Allow AI Investment & MLM in the Mobile App. It ships off. Its description in the admin panel says:

Offer AI Investment and the referral (MLM) programme in the mobile app as well as on the website. App Store and Google Play rules do not permit fixed-return investment products or paying currency for recruiting users, so apps carrying either are commonly rejected or removed. You publish the app under your own developer account, so that rejection risk is yours. Off by default; the website is unaffected either way. The app shows these screens only if it was also built with STORE_RESTRICTED_MODULES=true. Binary options and forex investment plans stay unavailable in the app whatever this is set to.

While it is off:

  • The module manifest reports ai-investment and mlm as DISABLED (or NOT_INSTALLED when the addon is missing), so their tiles are absent, even in a build made with the flag.
  • Your server refuses the app's AI Investment requests — the plan list, the customer's investments, starting one, opening one and cancelling one — with HTTP 403 and: "AI Investment is not available in the mobile app. It offers a fixed return over a fixed duration funded from a custodial wallet, which app-store rules on financial products do not permit."
  • It refuses claiming an affiliate reward from the app with: "The multi-level referral programme is not available in the mobile app. App-store rules bar a cryptocurrency app from offering currency for recruiting other users."

While it is on, both modules follow their addons like any other module. AI Investment is also licence-gated: with attestation enforcement on, it needs a licence row for the customer's country. A licence row for AI Investment changes nothing in the app while this switch is off.

The website is never affected by this switch. Like every change to what the app shows, turning it on or off changes the tiles a signed-in customer sees the next time they sign in or reopen the app. The refusals above do not wait for the app: your server checks the switch on each request.

Merchant has no server switch

Merchant needs only the build flag. After that, it is an ordinary module: the tile appears when the Payment Gateway addon is installed, switched on and licensed, and it opens when the customer also passes the use_gateway KYC feature and — with attestation enforcement on — the licence check. A customer who fails either of those sees the tile dimmed, with the reason. Accepting payments on behalf of others is a regulated payment service almost everywhere, which is why Merchant is one of the nine licence-gated modules. With attestation enforcement on, becoming a merchant from the app is also refused to a customer whose country has no Merchant licence row, with the same country refusal as the other licence-gated modules.

The Payment Gateway's own settings do not hide the tile. In particular its enable setting (gatewayEnabled) is deliberately not what the manifest reads, so that an existing merchant keeps a way to their refunds and balance.

To keep Merchant out of an app built with the flag, the options are:

  • Build without the flag — the only way that also removes AI Investment and Affiliate from the binary.
  • Switch the Payment Gateway addon off — which switches it off on your website too.

Recording no Merchant licence row, with attestation enforcement on, does not remove the tile: it shows dimmed, with the message that Merchant is not offered in the customer's country — or, when the server does not know their country, the message asking them to add it.

What each combination shows

Build flag Server switch Merchant AI Investment Affiliate
Off Either Not in the app Not in the app Not in the app
On Off Follows Payment Gateway Absent; the server refuses the app Absent; reward claims refused
On On Follows Payment Gateway Follows AI Investments Follows MLM & Affiliate System

"Follows" means the normal manifest checks decide: addon installed, switched on and licensed, then attestation and KYC where they apply.

Why the stores object

The server's own refusal texts give the short version: a fixed return over a fixed duration from a custodial wallet, and currency paid for recruiting users. Apple's cryptocurrency rules say it outright for the second — guideline 3.1.5(v): cryptocurrency apps "may not offer currency for completing tasks, such as … encouraging other users to download". The package's installation guide puts merchant payment processing in the same group, as something both stores restrict in crypto apps; it is also a regulated payment service almost everywhere, which is why Merchant is licence-gated.

Nothing about your server configuration cures these objections. A licence row changes who in which country can use a module; it does not change what the product is.

Before you decide, read Before you buy, Licences by country and Licence attestations.

What no switch unlocks

Binary options, forex investment plans and launching a token (the ICO creator side) are never in the app, whatever the flag and the switch say. They have no screens, no module entry, and your server refuses them to the app. The full list, with the server's wording, is on What is in the app.