Skip to content
itzgee.com

Blog Privacy

You bought the phone. Who decides what runs on Android?

Google will soon want ID from the people who make Android apps. The scam problem behind it, and why a register of developers matters to you.

Geeitzgee.com12 min read

Android has always had one thing the iPhone did not. You could install an app from anywhere: Google’s app store, the phone maker’s own store, or a file downloaded straight from the person who wrote it. That last route has a clumsy name, sideloading, and it is the one Google is about to put a gate on.

A campaign called Keep Android Open has spent a year arguing that this ends the phone being yours. Google says it is protecting people from scams. Each side has a real point, and each leaves something out. This post goes through both, then spends longest on the part that gets the least attention, which is the ID check.

What is actually changing

In August 2025 Google announced that an app would only install on a certified Android phone if the person or company behind it had registered with Google. Certified means a phone sold with Google’s own apps on it, which covers the Android phones most people own.

A standard account costs $25 and needs government ID. The rule covers every app, including ones that never go near Google’s app store.

It arrives in two steps.

  • 30 September 2026. It began in Brazil, Indonesia, Singapore and Thailand, and for now only for apps that come through Google Play and the phone makers’ own stores. Google’s own guidance says apps downloaded directly are not checked there yet.
  • 2027. Everywhere else, the UK included, and for every app. Google has not given a date.

After months of complaints, Google made two changes in November 2025. There is now a free account, with no ID, for students and hobbyists who share an app with up to 20 devices. And the owner of the phone can switch the check off. You turn on the developer settings, confirm that nobody is talking you through it, restart the phone, wait 24 hours, then confirm with a fingerprint or PIN. You do it once per phone. Installing an app over a cable from a computer is not affected at all.

The safety case

The scam Google has in mind starts with a phone call. Someone says they are from your bank, or that a relative is in trouble, and that you need to install an app right now. They stay on the line and talk you past each warning. The app then reads your security codes or takes over the phone.

Google says its own analysis found over 50 times more malware (software built to do harm) in apps installed from the web than in apps from Google Play. It picked the four launch countries because they are hit hard by this kind of fraud.

The 24-hour wait is built around that phone call. The restart cuts off anyone who is on the line or watching your screen. The day’s wait gives the panic time to wear off, and gives you time to ring the bank yourself or ask someone you trust. A scam that depends on rushing you does badly against a rule that makes you wait until tomorrow.

That is careful design, and it will stop some people losing their savings. Any argument against the rule has to start by admitting that.

The control case

Google compares the new check to showing ID at an airport, which is a separate thing from having your bags screened. The comparison says more than it was meant to. The check confirms who made an app. It says nothing about what the app does, and Google is clear that it is not reviewing the contents.

The bag screening already exists. Android has scanned apps for known malware for years, wherever they came from. So the new rule adds a name to each app. The benefit comes later, when a developer who is caught and banned finds it harder to come back under a new name. That is useful, but it works by making people traceable.

The reach is new as well. Google has always decided what goes in its own store. Now it decides who may write software for the phone at all, including software that never goes near the store. We have seen the same move before, when Google’s browser changed the rules for ad blockers.

The way round it belongs to Google too. The campaign points out that the 24-hour route is delivered through Google’s own software on the phone, so it can be changed later without asking the owner.

Why would an app maker need to show a passport?

This is the part most coverage skips, and the part we think matters most.

To get a standard account, a developer gives Google their legal name, their address, an email and phone number, and an official identity document. An organisation also gives a business identity number and its website. On top of that goes a list of the apps they make.

Google’s reason is the one above. Scammers hide behind made-up names, and a real identity is harder to throw away.

Put those accounts together and you have something that has not existed before: one list, held by one company, of the real names and addresses of the people who write software for Android phones. It takes in people who have never used Google’s store and never wanted to, the makers of ad blockers, private messaging apps and VPNs among them. The volunteer who wrote a small app under a nickname, and would rather stay a nickname, is on it too.

Google says the information is used to verify identity and is handled under its privacy policy, and that contact details are not shown to phone users. That is fine as far as it goes. The trouble is what a list like this can be used for once it exists.

A list of names is something that can be asked for. Google, like every large company, hands over data when a government makes a lawful demand, and in some countries a lawful demand is whatever the government says it is. The Electronic Frontier Foundation made the point when the plan was announced: build a gate and the authorities will want to use it, build a database and governments will want to see inside it.

There is a record to go on. In September 2021, on the eve of an election, Google and Apple removed a voting app made by supporters of the Russian opposition leader Alexei Navalny. Reports at the time said Google staff in Russia had been threatened with prosecution. Whatever you think of that decision, on Android it had a limit. The app was gone from the store, but the phone would still install it from anywhere else.

A register takes that limit away. It only works if a developer can be struck off, and once they are, their apps stop installing on certified phones wherever they were downloaded from. A decision that used to remove an app from one store can now reach it everywhere, and the company making that decision holds the developer’s name and address.

Critics call this surveillance. Two things are fair to say on the other side. The 24-hour route asks nothing of the developer, so an anonymous app can still reach anyone prepared to wait a day. And the register is of the people who make software, and does not list the people who use it. That is a narrower thing than the word surveillance suggests.

It still changes something for you. The apps on your phone exist because somebody was willing to write them. Some of the most useful ones, the kind that block tracking or keep a conversation private, were written by people with good reasons to stay off a list. If fewer of those get written, you will never see what is missing.

The people the rule is aimed at are also the ones best placed to dodge it. A commenter from Brazil made the point on Reddit. Organised fraud there already runs on straw identities, borrowed or bought from real people (the local word is laranjas, oranges). A gang can turn up with someone else’s ID. A hobbyist has only their own.

What Keep Android Open is

Keep Android Open is the campaign against the rule. It was started in October 2025 by a board member of F-Droid, the best-known store for free, open-source Android apps, which says the rule threatens its existence. In February 2026 it published an open letter to Google’s leadership, signed by 71 organisations in 23 countries. The Electronic Frontier Foundation, the Tor Project, Proton and Nextcloud are among them. The letter asks Google to drop compulsory registration altogether.

The site is worth reading, and worth reading knowing who wrote it. It is a campaign page, put together by the people with the most to lose. It tells you that a silent update will block every unregistered app on every phone. It gives much less room to the free account, or to the fact that the first step only covers app stores. It runs a countdown, where Google itself has only said 2027.

On the ID check, though, it is making an argument that few others are making loudly. A register of developers is a new kind of power, and nobody asked the people who own the phones. If you read it and agree, the letter and a petition are there to sign.

The argument on Reddit

The most useful argument we found was in a Reddit thread about the campaign. Both sides in it agree on one fact and draw opposite conclusions from it.

The fact is that ordinary people do not install apps from outside the store. One side says that settles it. The rule costs ordinary people nothing and protects them, enthusiasts can still get through with a day’s wait, and Google has already backed down once. One commenter told the rest to “take the win”.

The other side says it was never about ordinary users. One reply made the point with a student who writes a homework app for the class. Nobody is stopped from installing anything. The classmates just will not sit through a day’s wait and a row of warnings for a homework app, so the app dies. The cost lands on the person who made it, and on everyone who would have used it. Google’s free account covers 20 devices without ID, which answers that for a small class and not for a large one.

Then there is trust. The day’s wait only exists because people complained. Plenty in the thread expect it to get longer, or to disappear, once the fuss dies down.

The thread also shows how easily the facts slip. One comment said Google had planned to ban installing app files altogether. The plan was to require registration, with a cable as the only way round. Another said the rule ends anonymous software, and a reply pointed out, correctly, that the 24-hour route needs no ID from anyone.

Where this leaves us

The scam problem is real, and making someone wait until tomorrow is a good answer to a con that depends on today.

The wait and the register are two separate things, though. The wait is aimed at the phone call. The register is aimed at tracing developers, and it catches the honest ones along with the rest. Google could have shipped the wait as a setting the owner of the phone controls, and left it there. What it shipped puts the decisions with Google: who may write software, on what terms, and how hard it is to opt out.

two separate things

the register of developers

What it is aimed at

Developers who are banned and come back under a new name.

What it asks for

A name, an address and government ID from the people who write apps.

Who ends up on it

Honest developers too, including the ones with good reasons to stay off a list.

the 24-hour wait

What it is aimed at

The scam phone call that rushes you into installing something.

What it asks for

A day of your time, once per phone, and nothing from the developer.

Who controls it

Google, not the owner of the phone. It can be made longer later.

The wait and the register arrived together, but they do different jobs. Only the wait is aimed at the scam phone call.

The test we would apply is one this blog keeps coming back to, which is who can change the rules after you have paid. Every certified Android phone already in a pocket or a drawer was bought when it would install anything. That is being changed from a distance, on a timetable its owner has no say in. Today the way round takes a day. Nothing stops it taking a week next year, because the owner is not the one who sets it.

It is the same position as keeping your things on someone else’s computer. It works well until the other party changes its mind.

iPhone owners already live this way

None of this is new to anyone with an iPhone. Apple has approved every app and identified every developer since its App Store opened in 2008. In most of the world, the UK included, there is no official way to install an iPhone app from anywhere else. Android with a 24-hour wait is still far more open than that.

Google is not being uniquely bad here. People chose Android partly because it made a different promise, and a great many phones were sold on it. The complaint is about changing that promise on phones already sold.

What it means in the UK

Today, nothing. The rule has not reached the UK, and Google has given no date beyond 2027.

When it does arrive:

  1. Most people will not need to do anything. Google says nearly all installs from Google Play already come from registered developers.
  2. If you rely on an app from outside the store, set up the 24-hour route before you need it. A day is a long wait when the app is one you need today.
  3. If you want a say, the UK’s competition regulator, the CMA, gave Google strategic market status over mobile platforms in October 2025, which lets it set rules for how Android is run here. The campaign asks people to write to their regulators.

Between now and then, the thing to watch is whether the day’s wait stays a day.

Written by

Gee

We run itzgee.com, a private cloud in daily use, on servers run by us. How it works has the full picture.