> I'm not sure how familiar you are with Google Play Services, but it's designed to [permit Google to silently update any application on the phone].
Unless Google also deactivates signature verification for the originally-not-signed-by-Google app that it pushes to the target's phone, the design of both Android and the Android Market make this impossible. You can't silently update an app signed with one key with an app signed with a different key.
If -however- you're talking about Google installing software that snoops on the conversation between the Signal software and Signal servers, then -in that case- Google gets nothing that any other adversary that has access to at least one node between those two points gets... namely, undecryptable cyphertext.
If you're trying to make the stronger claim that Google inserts special code (that they don't include in AOSP) that they use to read the unencrypted data of interest from RAM and transmit to their servers, then I reply:
"All modern computers -including Apple devices- suffer from this class of problem. You have to trust everyone who wrote kernelspace code loaded into your system, the OS authors, the people who put the boards in your computer into their housing, and the folks who made the boards and chips to begin with. This is a hard problem. Frankly, Google's solution to this problem is just about the best consumer-level solution in the industry, and keeps getting better as time goes on."