Information about an app includes its app ID and an app certificate.
There are development and production certificates. Released apps contain a production certificate.
You have to have the app on a device. The app ID/certificate extraction app can read the necessary information from an installed app and, with the proper credentials, upload the app ID and certificate to SDC.
Potential issue: if you have an app loaded and try to re-load it with a different certificate. If you have a filter with an app defined with an app ID and upload a different certificate for that app, you may affect how that filter matches.
A filter that uses an app ID will verify against any uploaded certificate.
Having a developer version on a device implicitly prevents you from having a release version on the device.
Only need certificates for policies that will be part of purchasable features for plans offered in the store.