DeGoogled Phones · Big Tech Watch

Sideloading Apps on Android Is Under Threat. Here's What Google Is Doing and What It Means for You

By Tony · FreedomTech · 11 min read · Updated May 2026

Not affected on GrapheneOS Enforcement Sept 2026 Based on primary sources
Finger pressing a glowing lock button, symbolising Google's 2026 crackdown on sideloading apps on Android

Sideloading apps is about to get a great deal harder on Android, and Google has already put the date in writing.

Google's own developer documentation says it plainly: "Starting in September 2026, Android will require all apps to be registered by verified developers in order to be installed on certified Android devices."

One sentence. That's the whole story. Android has always been different from Apple's iPhone in one genuinely important way: you could install whatever software you wanted on it. Not just apps from Google's official store, but any app, from any source, built by anyone. That openness is what let privacy-focused apps flourish, what let open-source stores exist, and what made Android genuinely different from the walled garden Apple built. Google is now moving to end that, on the 95-plus per cent of Android devices that run Google's certified software.

77
malicious apps slipped through Google's own Play Store, racking up over 19 million downloads before removal. Uncovered by Zscaler ThreatLabz in August 2025. Verified does not mean safe.

This post is based on my own research across Google's official documentation, statements from the open-source community, and independent technical analysis. I'm not a developer or a lawyer. The situation is still developing, and I'd encourage you to read the primary sources, all linked throughout, and form your own view. For the broader picture of how Big Tech operates and what it costs you, read our post on Big Tech companies in Australia.

The short version

  • If you're on a FreedomTech deGoogled phone running GrapheneOS, nothing changes. Sideloading apps keeps working exactly as it does today: F-Droid, Aurora Store, Accrescent, and direct APK installs all carry on.
  • From September 2026, certified Android devices will block apps from any developer who hasn't verified their identity with Google, no matter where the app comes from.
  • F-Droid, the home of open-source apps for over 15 years, says the policy as written ends the project on certified devices.
  • Google's "advanced flow" for power users is 10 steps, a 24-hour wait, and runs through Play Services, which Google can change or pull at any time.
The Basics

What is sideloading apps, and why does it matter?

Before we go any further, a quick translation of the terms you'll hear thrown around in this conversation.

  • APK stands for Android Package Kit. It's the file format Android uses to install apps, like a .exe file on Windows. Every app you've ever downloaded, from anywhere, arrived as an APK.
  • Sideloading means installing one of those APK files from a source other than the Google Play Store: a developer's website, a community repository, an alternative app store, or a file you downloaded yourself. Android has always allowed this.
  • Open-source apps have code that anyone can read, audit, and verify. You don't have to take the developer's word that the app doesn't spy on you. Many of the best privacy tools in the world are open-source.

Sideloading apps is how open-source app stores work. It's how the apps we install on every FreedomTech device reach your phone. And it's exactly what Google is now putting conditions on.

The Policy

What Google is actually requiring

Under the new policy, every app installed on a certified Android device must come from a developer who has registered with Google and verified their identity. That covers not just the Play Store, but every app from every source. Sideloading apps, downloading directly from a developer's website, installing from alternative stores, all of it requires a verified developer from September 2026.

To register, developers must go through Google's Android Developer Console and hand over their legal name, home address, email address, and phone number. In most cases they'll also need to upload a government-issued ID. Organisations need a D-U-N-S number on top of that, a business identifier that can take up to 30 business days to obtain.

There's a free Limited Distribution tier for students and hobbyists that skips the government ID and allows distributing to up to 20 devices. The paid Full Distribution tier costs US$25 as a one-time fee and requires full identity verification. Enforcement begins September 2026 in Brazil, Indonesia, Singapore, and Thailand, with global rollout following in 2027.

The Casualty

What happens to F-Droid, and why that matters

F-Droid has been the gold standard for open-source app distribution on Android for over 15 years. It hosts around 5,000 apps, all open-source, all reviewed for privacy compliance before listing. If you're running a FreedomTech deGoogled phone, F-Droid is your primary app store, and every app in its catalogue is publicly auditable. That's not a marketing claim, it's technically verifiable by anyone with the time to look.

The problem F-Droid faces is structural, and it has no clean answer on certified Android devices. F-Droid doesn't just host apps. It takes open-source code, reviews it, compiles it, and distributes it signed with F-Droid's own cryptographic key, not the original developer's key. Google's new system wants each app tied to one verified developer identity. As the New Stack reported in a March 2026 interview with F-Droid board member Marc Prud'hommeaux, Google wants only one signature per app, which breaks every version of an application distributed through F-Droid or any other store.

That leaves F-Droid two options, both impossible. Compel thousands of anonymous volunteer developers, many of whom are anonymous for good reason and many of whom will simply say no, to hand their personal identity documents to Google. Or register every app under F-Droid's own identity, claiming ownership over code it didn't write.

F-Droid's own position, stated in their September 2025 response and reaffirmed in the February 2026 open letter signed by 56 organisations worldwide, is that this policy ends the F-Droid project on certified Android devices. That's not hyperbole. That's their assessment of their own situation.

Alternative Stores

What about the other app sources?

F-Droid isn't the only way people sideload. Here's where the main alternatives stand under the new rules.

Aurora Store

Aurora Store lets you download Play Store apps without a Google account. Because those apps come from already-verified Play developers, most should keep working. But Aurora Store itself is an unverified app and has confirmed it will not register with Google, so getting it onto a certified device may itself need the advanced flow.

APKMirror

APKMirror hosts official APKs verified by their original cryptographic signatures, largely Play Store apps distributed directly. Most come from developers already verified through Play Console, so they should generally keep working. Apps from unverified developers will still be affected.

APKPure

APKPure distributes both Play Store and non-Play Store apps. According to WebProNews, it's bolstering its own security frameworks in response. Apps from unverified developers will face the same restrictions as any other unverified APK.

Accrescent

Accrescent is the privacy store best positioned to survive. It lets developers sign apps with their own keys, so app identity stays with the original developer. It has already registered with Google and comes from within the GrapheneOS community. On a FreedomTech device it sits alongside F-Droid as a main app source.

The Loophole

Google's workaround: the "advanced flow"

After the initial backlash, Google announced that power users would be able to install unverified apps through what it's calling an "advanced flow." On 19 March 2026 it published the details, and the Keep Android Open campaign has documented the full process. Read it and decide for yourself whether this is a genuine solution or deliberate friction:

  1. Tap the build number in About Phone seven times to enable Developer Mode.
  2. Open Developer Options. Find "Allow Unverified Packages."
  3. Flip the toggle. Confirm you're not being coerced.
  4. Enter your PIN.
  5. Restart your device.
  6. Wait 24 hours. Yes, really.
  7. Return to the unverified packages menu.
  8. Scroll past more warning screens. Choose "Allow temporarily" (7 days) or "Allow indefinitely."
  9. Confirm again on a final warning screen.
  10. You can now install unverified apps.

Ten steps. A mandatory 24-hour delay. Multiple warning screens engineered to make you feel like you're doing something dangerous. And a 7-day expiry if you chose the temporary option, meaning you get to do it all again.

The part that should concern you most: the entire flow runs through Google Play Services, not the Android operating system itself. Google can change it, restrict it, or remove it entirely at any time, without updating your phone's OS and without asking your permission.

As of this writing, the advanced flow doesn't exist in any shipping Android software. It's a blog post and some mockup screenshots.

"The community is being asked to accept a product announcement as a functional safeguard five months before the mandate takes effect."
The Solution

The good news: if you're on GrapheneOS, you're fine

This is what I tell every FreedomTech customer who asks me about this. Based on It's FOSS, the Keep Android Open campaign, Reclaim the Net, the Consumer Rights Wiki, and the GrapheneOS community forums themselves: GrapheneOS, CalyxOS, LineageOS, and /e/OS are outside the scope of this policy.

The reason is technical and worth understanding. Google enforces this policy through Google Play Services. GrapheneOS deliberately does not include Google Play Services. It is not a certified Android device in Google's ecosystem, so the enforcement mechanism simply isn't present. The GrapheneOS forum thread on this is titled, in plain terms, "Are we screwed? (no, doesn't apply to GOS)." That's a pretty clear answer.

If you're running a FreedomTech deGoogled phone on GrapheneOS, you can keep using F-Droid, Aurora Store, Accrescent, and direct APK installs exactly as you do today. Nothing changes for you.

One more thing worth mentioning: in March 2026, Motorola and the GrapheneOS Foundation announced a partnership to engineer future Motorola devices with GrapheneOS compatibility. For the first time, GrapheneOS is expanding beyond Google Pixel hardware. The project isn't retreating, it's growing. That said, this is a practical exemption based on how Google currently enforces the policy, not a written guarantee, so it's worth keeping an eye on grapheneos.org for updates.

The Argument

Is Google's security argument convincing?

Google's stated reason for all of this is reducing malware. Their August 2025 announcement claims that apps installed from outside the Play Store contain over 50 times more malware than Play Store apps.

I'll give them this: there is a real malware problem in the Android ecosystem. Scam apps are genuinely hurting people, particularly in markets like Indonesia, Brazil, and Thailand, which, not coincidentally, are the first countries where enforcement begins. That part isn't manufactured.

But the argument has an obvious hole. As the Keep Android Open campaign notes, Google's own Play Store distributed 77 malicious apps that racked up over 19 million downloads. The platform Google holds up as its security benchmark has repeatedly hosted the exact malware Google claims to be fighting.

There's also a more principled objection. The open letter signed by 56 organisations, including the Electronic Frontier Foundation, Free Software Foundation Europe, Tor Project, Proton, and Vivaldi, argues that Android already has multiple security mechanisms that don't require handing your government ID to Google. What this policy actually does is give one corporation a chokepoint over every app on every certified Android device on the planet. F-Droid's model, where every line of code is publicly visible and auditable, arguably provides a stronger security assurance than a name and a passport scan.

A verified developer can still ship malware. An open-source app on F-Droid cannot hide what it does. Verified identity does not equal safe software.

Plain English

Who is actually affected

Strip out the detail and it comes down to which side of the certified-device line you sit on. If sideloading apps is part of how you use your phone, this is the part that counts.

You're fine

  • FreedomTech customers on GrapheneOS: not affected. F-Droid, Aurora Store, Accrescent, and direct APK installs all keep working. Nothing changes.
  • CalyxOS, LineageOS, /e/OS users: custom builds outside Google's certified ecosystem, similarly unaffected.
  • Accrescent users: best placed of the alternative stores. Already registered.

You're affected

  • Standard Android users on F-Droid: F-Droid will be significantly restricted on certified devices from September 2026, then globally from 2027, unless a technical fix or regulators intervene.
  • Aurora Store users: verified Play apps should keep working; getting Aurora itself onto a certified device may need the advanced flow.
  • Developers outside the Play Store: must register or be blocked. Many are refusing on principle.
Why It Matters

The bigger picture

This is the thing that should sit with you. Android launched as an open platform. The ability to sideload apps, to install whatever software you chose from whatever source you trusted, was a genuine competitive advantage over Apple and a genuine promise to users. That promise is being walked back.

As It's FOSS put it, centralising all app distribution under Google's registration system hands one corporation the ability to cut off any app on any certified Android device globally. That kind of consolidated authority over a platform used by billions of people is unsettling.

I agree, and I'd add one more thing: this policy means a government anywhere in the world can ask Google to deregister a developer, and that app disappears from over three billion phones. Not just from the Play Store. From everywhere. Think about what that means for journalists, activists, whistleblowers, and ordinary people who rely on apps that powerful institutions would rather not exist.

If you're in Australia or New Zealand and want to raise this with regulators, the Keep Android Open campaign has contacts listed. In Australia, you can report it to the ACCC. In New Zealand, contact the Commerce Commission. You can also give Google direct feedback via their Android verification feedback form. Whether it changes anything is another question.

Common Questions

Sideloading apps: your questions answered

Is this happening now or is it still coming? +
Registration opened to all developers in March 2026. Enforcement, apps actually being blocked, begins September 2026 in Brazil, Indonesia, Singapore, and Thailand. Global rollout follows from 2027. Nothing is being blocked on devices yet.
Will F-Droid stop working on my phone? +
On a standard certified Android phone: yes, that's the direction from September 2026 in the first four countries and globally in 2027. On GrapheneOS: no. F-Droid continues to work exactly as it does today, because the policy doesn't apply to non-certified devices.
What's the difference between an APK and a normal app download? +
There isn't one. Every app you install on Android is an APK, it's just the file format. The distinction is where the APK comes from: the Play Store, or somewhere else. Sideloading apps just means installing from somewhere other than Google's official store. Until now, Android has always allowed it freely.
Is sideloading apps safe? +
It comes down to the source. Sideloading apps from an open-source store like F-Droid, where every line of code is publicly auditable, is arguably safer than trusting a closed app on a verified developer's word. The risk was never sideloading itself; it's installing from a source you can't check. Stick to F-Droid, Accrescent, and reputable signed APKs and you're on solid ground.
Does this affect CalyxOS users? +
CalyxOS is also a custom build outside Google's certified ecosystem and should be similarly unaffected. Monitor the CalyxOS project directly for their official position.
Where can I read more and check this myself? +
Start with the primary sources: Google's official developer documentation, F-Droid's open letter, the Keep Android Open campaign, the Consumer Rights Wiki, the GrapheneOS forums, and the It's FOSS analysis. All are linked throughout this post so you can read them and form your own view.

The permanent fix is a phone Google can't reach into

The most reliable answer to all this, not as a workaround but as a structural solution, is a deGoogled phone running GrapheneOS. No 10-step process, no 24-hour wait, no risk that Google quietly removes your ability to install open-source apps through a Play Services update you didn't ask for and can't refuse. Every phone we build is a Google Pixel running GrapheneOS, configured, tested, and ready to use, with F-Droid and your privacy apps already in place.

Join the conversation

Questions, or just keen to talk privacy with like-minded Australians? Visit our Telegram community.

Join our Telegram

FreedomTech · The Privacy Experts · freedomtech.com.au