That's correct.
> Given that apps are sold all the time,
I'm pretty confident that in 90%+ of those cases, developers just sell the signing keys with it.
FWIW, Android does have a mechanism to upgrade keys (app signed with the old key contains in its metadata the new key saying that this key is okay) since like 4-5 years ago. But I expect very few people use that. (I don't even know whether Google Play Store allows using this)
> and developers sometimes lose private keys themselves, this makes no sense.
I guess they don't when their revenue relies on it?