Why my apps will soon be gone from the Google Play Store
frozenfractal.com
frozenfractal.com
That's something I just can't understand. If the old API is insecure or whatever, then surely the OS can put some sort of a secure emulator sandbox around old apps. You can run 35 years old NES games but not a 5 years old app? This doesn't make sense.
I never particularly liked Microsoft but userspace compatibility is something they got right and Google got wrong.
Except those selling GNU/Linux phones running desktop operating systems. Sent from my Librem 5.
It doesn't make sense to keep supporting APIs only a fraction of the user base needs, progress means leaving some users behind.
It's been mentioned time and time again, but it's worth mentioning again — Windows maintaining backwards compatibility is what maintained its hegemony, as compared to it, Linux and macOS look like hobby projects. For the young as well, because games still run on it, without worrying that Apple will invalidate their library due to not being in the mood to maintain 32-bits APIs.
I bet if you pay Apple similar amounts of money per year, they'll keep specific APIs available just for you.
And it's not like updating the app to a new iOS version is a massive undertaking, in most cases it's just a matter of opening the project in XCode, adjusting the OS version, compiling and publishing it again.
[0] https://money.cnn.com/2015/06/26/technology/microsoft-window...
And also, it's unreasonable to expect all software projects to need updates, forever. My hammer doesn't need updates.
Something that just has to be done, and not doing it has a clear cost.
Linux has dedicated people working for free to support the weirdest hardware and software
Now the new API adds fine-grained access and removes complete access.
What are they gonna do? Give the old gallery app fake file access, making it completely useless?
This would make for a very bad user experience. It works for emulators, because noone expects emulators to be well integrated with the system. But it doesn't work for native apps.
Many features cannot be preserved. They could preserve some features, but doing so would result in some weird 50% support for old APIs, which wouldn't be great either.
In my view, dropping old APIs entirely makes sense.
> I never particularly liked Microsoft but userspace compatibility is something they got right
With the result of having absolutely zero sandboxing.
Just to be clear: I don't disagree with you. I think it's completely normal to have APIs be deprecated, and this means eventually your app will break and be removed from the store. I just don't think this specific example was entirely justified.
I actually use GrapheneOS which does exactly that. I don't know why I didn't think of it.
Can you elaborate on your example here? Couldn't they just do something like replace oldGalleryAppOpensOrWritesToAnyPlace() to askPermissionsForWhichFilesAndFoldersCanBeWrittenTo() or ifSensitiveDirIsNoLongerAccessibleAskPermissionOnWhichFolderToUseForCompat() ?
Yes. When any API is used for the first time, pop up a toast saying "this legacy app is trying to use File Access permissions. [Allow access to whole device] / [ Restrict to apps own files ]".
If the user hits 'allow', grant the legacy API. If the user hits 'restrict', give a fake filesystem.
The dialogue box should be provided by the OS, and if the threading model doesn't allow pausing the app to wait for user interaction, simply kill the app to ask the question, and restart it with the permission.
Also, TBH dev convenience is secondary to user safety
And anyway it's a false dichotomy. If the old API is implemented on top of the new API then it can be as safe as you want it.
Real scenario, real problem, semi-common attack vector. Enough that it's a serious problem for Google.
If the new API can give a sensible way to restrict file access without too many prompts, then the old-over-new API layer can do exactly the same.
You've got an old app that uses an API that assumes full access to the device. A new API that restricts that access _cannot_ just guess what the app actually needs / uses - the only sane thing to do is to ask the user what the app actually needs.
The problem there is that the user is not incentivised to precisely curate the permissions boundary of the app, they're incentivised to _make the damn popup go away_.
This stuff is highly non-trivial.
No. It knows which actual paths the app tries to access. They can be grouped into exactly the same permission bundles (access to camera images, access to downloads etc) which are used for newer apps. Then presented to the user for approval, like they are with newer apps.
The only difference is, you may not get all permission popups at once -- but that's already the case with many newer apps. They only ask for permissions to e.g use camera when you actually need it. And I like it so much better than the old approach when the apps would refuse to run without camera even though I don't need this particular feature.
> The problem there is that the user is not incentivised to precisely curate the permissions boundary of the app, they're incentivised to _make the damn popup go away_.
Right, and exactly the same problem applies to new apps natively built against the new API. The app can request unreasonably wide permissions and the user will make the damn popup go away. It's not relevant to the problem of maintenance of old apps.
> With the result of having absolutely zero sandboxing.
With the result of having useful machines that do useful work, instead of toys that "protect" users and prevent them from ever doing anything interesting.
I don't think people are complaining about API deprecation being a thing, either. They complain about it being a thing that happens too often.
Could you present a concrete example, outside of the "system configuration" apps? These are expected to break as the "system" moves on.
I fail to see though why 100% userspace apps that often have no permissions whatsoever can't be maintained.
This applies even to apps that don't request any permissions. I have some plain OpenGL games there and they still require this useless maintenance for them, which I'm probably won't be bothering with anymore.
If you are willing to fill your phone with emulators of every single version of Android, then yes, you can run any old app. This is how we run 35 years old NES games.
Sad as it may be, I imagine that lack of desire also comes from consumer demand. Most people don't care about running those 15 year old games, so what's the motivation?
For archival's sake, you should be able to seek old APKs and run older ROMS through an android emulator. So the minority of those who care have options.
they both have their ups and downs. Windows 11 still has parts of the base OS that feel like they never updated from XP. and I'm sure there's a lot of legacy cruft that ultimately slows down the boot process or many low level OS management. you add a .lot of cruft to make sure you can support 30+ years of legacy software.
https://howtomarketagame.com/2021/11/01/dont-build-your-cast...
This happens so quickly: 1. you are not allowed to root your phone or your bank apps will stop working
2. you are not allowed to take the screenshot of a move/cartoon (for meme purposes) because of policy
3. you are no longer allowed to use MHL to send video to your HDMI screen (use some smart-sh* itv)
etc.
if someone has his new kingdom filled, they will quickly build walls, introduce taxes and start oppression — same with Spotify artists, youtube ads etc etc.
I spent days trying to get my numbers verified. I tried using 3 different internet providers (init7, Swisscom, Yallo/Sunrise) and still received the 429 (Too many requests). It took me a 4th connection (cyberlink) and using my private cell phone which is now publicly visible on my Google play company profile. I still have an open case at Google Support which is over a week old with no reply. When I try to edit my number now to set my business phone number I still get 429.
On a second note. DO NOT PAY for your DUNS number. DnB does not charge for this number, only 3rd parties do. Contact DnB directly and they will issue you the number or send you your current number. I am in Switzerland and I can not lookup my number online but I can fill out a form at DUNS at which point a few days later you get your number via email. I used this link: https://www.dnb.com/en-ch/duns-request.html
As for official company document. Google accepted a PDF copy my Swiss Companies registration entry in the official register which you can just download online at no cost.
And as a final note. Google will re-review your apps. One of mine has now been removed from the app store and I am waiting for the appeal..: https://news.ycombinator.com/item?id=41667488
Once I had to register my company there and they wanted to "verify" the information. They did it by randomly calling me 2 weeks later and asked if it is real and asked me to give a phone to someone next to me to confirm I am not lying.
https://en.wikipedia.org/wiki/Data_Universal_Numbering_Syste...
I would have expected that the money they siphon thanks to the likes of Apple and google would be sufficient for them to verify the numbers with a reputable third-party broker.
Shh.
The long tail concept was conceived before the development of central gatekeepers. As this post demonstrates, frictions introduced at these choke points (for valid or invalid reasons) can demolish that long tail in an instant.
> While [paid company ID] may be just some paperwork and a small expense, the next requirement is more insidious: “a phone number and email address for Google Play users to contact you”. I’m fine showing an email address, but I absolutely do not want my phone number to be available to anyone on the internet.
It's exactly the same, only cheaper and faster - some dumb extra cost/paperwork: get an extra phone number for this form and never use it/forward everything to voicemail, keeping your main phone private. The same goes for email, although that one would be free
But yeah, good idea if you're in the US.
I keep my numbers at didww.com now where I pay a small fee but they won't just delete my number.
"Superfast Response Times As we access the entire mobile number portability (MNP) database in every country where number porting is in operation, Velocity can truly live up to its name, providing answers at lightening speed (typically less than 5ms)"
I have another number which I only use for the local pay-with-phone system. Second sim in a cheap dual-sim phone. And then there's a phone number which I only use for handing over to those services requiring a phone number ([1]the only exception to this whole thing is that my local bank actually has my personal number, but that's a voluntary exception).
There's no rule that "phone number" should equal "my personal phone number".
Except for the phone number thing though, I completely sympathize with the author.
I wonder what would happen to their metrics if they are reported to ignore support? And I wonder what would happen when Google ignores support?
My relative had an android though.
No playstore option. Downloaded the apk from their site, launched it. Access to your location? Photos? File system? Wifi networks? Etc? ETC? E.T.C.?
The thing is, it asks it every time you tap “connect” or “on” despite everything being disabled in settings. And of course it doesn’t work without permissions (bluetooth was on). Idk which are critical because none of them are acceptable.
That’s basically my average experience with apks. When you guys celebrate wins over apple, I wonder what future will look like and something tells me I’ve already seen it.
either the iphone app already asked for perms and you granted it all, or they didn't try to invade your privacy in iphone land at all (since an app review might scrutinize it).
But an apk might want to extract from you maximally, and there's nothing stopping them. That's why the android version is the way it is.
The problem isn't android itself, but that an open system is more vulnerable to being abused. However, i still prefer that over the closed garden.
Exactly.
I prefer my lights to not know my location and photos, and to not even ask for it. With the fall of apple scrutiny, almost everything will work as described above. Cause it demonstrably does when allowed.
The problem isn't android itself
Android could (1) disallow repeating permissions popups, (2) feed empty or arbitrary data to apks because of the nature of their “habitat”.
F-droid and other non-standard firmware is incompatible with banks, other apps and hardware, so this is out of question.
an open system is more vulnerable to being abused. However, i still prefer that over the closed garden.
I respect your preference. In my case I should explain the situation to my relative and suggest to choose between the two approaches.
But I don’t see mutual respect when reading happy celebrations about destroying the protective garden. Not a thing in our conversation, but I hear it often and dread the results, where there will be nothing to choose from.
As for faking empty/arbitrary data: this is a thing in Android, and has been a thing for several versions now. The unfortunate problem is that for reasons that I'm sure aren't tied to the big G's economic interests, the UI around "granted but not really" is complete dogwater (it's basically only functional for the gallery permission these days).
You can use something like appops[0] to forcibly override these permissions options, but it really should be made more user friendly.
I think the main problem with the closed garden is that it expects Apple to be a fair and unbiased steward of their ecosystem, when it's been proven over and over again that they absolutely aren't. They allowed the app store to be flooded with ad-riddled junk, allow for paid search results that make it harder for people to install government apps[1], press smaller app devs into adding more payment schemes and even on the most basic level demand a continuous resource drain with their licensing schemes that ensures that "just make a good app and sell it once" is eventually an unsustainable business model. And that's just the stuff that ends up hurting the customer; the dev experience from what I've been told is even more miserable.
This isn't to defend Android as being superior (the Play Store also has many of these issues), but at least with Android I can substitute the Play Store for F-Droid when it comes to non-government and non-banking apps. F-Droid at least ensures that I don't wake up one morning to realize that I have to plan a full week of support for relatives because an app decided to start milking it's userbase for money and ruin the experience; when Simple Mobile Tools went to shit, I was able to just spread that stuff out over a couple weeks at my own pace since F-Droid never shipped that version. (And it helped the fork get off the ground too.)
[1]: Probably one of the most frequent requests I got when I did tech stuff for the elderly was just "help me set up the government app to see [some service they were using]"; invariably the App Store would push some healthcare insurance nonsense or other vaguely related thing as the first result, which confused the hell out of them. It's unacceptable and I don't get where the "my low-tech relatives like it" idea comes from.
Yes, I understand development issues for apple, but at the same time the end result is my lamp
- works on iphone
- sort of does work on android iff I accept the unacceptable
This is probably not a very “tech” case, but in my view it is pretty consumer-average, and it’s not the first app which does that (I had an android for a while). As a developer, I understand and share your concerns. As a consumer, my vote goes to the status quo. I think that developers interesrs shouldn’t go ahead of consumers.
deny it then. They want location to help with voice commands. Photos are to label your light profile. If you did either on IOS, you already gave permission. If not, you miss those features. I prefer the explicit choice.
better yet, Andoid can let you grant the permission for a short time then disable it on demand.
>F-droid and other non-standard firmware is incompatible with banks, other apps and hardware
Then make those exceptions or don't use them on your phone. This isn't rocket science. Just because there's choice doesn't mean some apps won't choose to stay stuck on google.
> I don’t see mutual respect when reading happy celebrations about destroying the protective garden.
because that perspecive isn't respectful in and of itself. Your garden isn't damaged, other peple are tilling new land. No one's making you go out of your garden, and if suddenly some killer app isn't in there you have a choice. You're not forever tainted from downloading another store and downloading one more app while 99% are from the App store.
Put it another way: jailbreaking has been a thing since IOS was a thing, there are already homebrew and unofficial apps (e.g. emulators) that you cannot access on IOS because you are in the garden. Nothing will change from then to later except Fortnite will not be in the App store. But if you were fine without Fortnite on IOS for 7 years, you aren't suffering now.
Nothing will change from then to later
Jailbreaking is a process an average consumer won't do, so it disincentivizes app makers from making jailbreak-only ios apps. Forced regulation will make sideloading a regular thing which will shift incentives to what happened to my relative (please note: not to me). This directly affects the garden. The logic you're using here is naive at best.
I just needed to link a google account and permissions are minimal. nearby devices for the bluetooth/NFCand nothing else. other 5 permissions disabled. worth the convinience since I have control over what it can/'t do.
Remote control: While climbing into bed, I notice through the window that the lights in the garage are still on. Not a problem: I can turn them off from where I am.
Automation: I get up, get around, and leave for work. Did I remember to turn the coffee machine off? The light in the kitchen? Did I remember to dial the thermostat back? I don't have to go back home and check because it doesn't matter: Those things were done for me, automatically, by virtue of leaving.
Later, I get home from wherever I went for work today. It's been a long drive, and it's dark outside, and it's dark inside, and my bladder senses the proximity of a familiar toilet and starts screaming at me before I even start to open the door. By the time I set foot inside of my home, the pathway from the back door to the bathroom has become illuminated so I can get there in a hurry without tripping over a cat.
It's annoying if you have 1 app but if you have many, it's still the same amount of work.
I built a little offline, no frills app for mushroom picking for my dad's birthday and every 2/3 years I need to rebuild it with a new target API. No big deal and it keeps making me think whether it's worth it being there or not: until my dad or I go to mushroom picking then the answer will be yes.
It allows for offline functionality and icon on home screen.
Much lower maintenance too. Could even host in GitHub pages depending on requirements.
I'd still rather open the project, change the minSDK and rebuild than having to mess around with Samsung Browser, UC Browser from hell or else.
If someone with a cheap Xiaomi with a weird default browser comes and tells me that they have an issue with my app/game, I can't get back to them and tell them to fck off because they are not respecting the stats. Or rather, I definitely could but I don't want to.
I developed a small web-based game and even that one required quite a bit of testing and debugging from players' reports as it seems every manufacturer uses a different default browser.
I have a check specifically for UC Browser (had no idea of its existence) as it has a bug regarding dates. Go figure.
And then people downvote me because they think all is Chrome and Firefox, while that's not the whole picture at all.
If they have not gone to the route of directly banning solo developers is just to avoid the pushback.
It's even worse: if you are an individual with paid apps, Google will publish the physical address from your merchant account to your Storefront page. You will not be able to use a PO box / UPS Store box etc.
> The D-U-N-S number is only needed if your Play Store publisher account is for an organization, not an individual.
Same with the requirements for public email and public phone number, these are only requirements if you are an organization
Funnily enough all the actions against Google advertising business monopoly if work out would probably make privacy on the web worse in my opinion.
google is in the business of selling access to that information.
though, i can see the wisdom in painting the alternative even worse.
If they wanted to verify my identity then I would give my national identity card. I'd definitely trust them with my ID card more than most other companies
Is it not obvious that Google does not want "indie developers who make something cool, out it out there, and move onto the next project"?
I'm planning to build a small software company but so far everyone I've asked has strongly suggested to create web applications instead. Can a solo developer publish an app for all major platforms in 2025, or is this a completely crazy idea?
For example I make an IoT device (https://www.stationdisplay.com/) that gets configured via Bluetooth LE. I can not access BLE via mobile browser because most don't support it (https://developer.mozilla.org/en-US/docs/Web/API/Web_Bluetoo...).
Of course there are alternative methods like starting a wifi access point and having users connect to that but this makes it a lot more complicated for the end user. That results in un-happy customers and a lot of extra support costs.
However, based on all the horror stories I've heard, I'm seriously thinking about re-considering my approach and settling for a different, simpler web-only product. It's frustrating to think that the majority of development time is not going to be spent on the app & cool technology but rather on bureaucracy, platform distribution,integration into app stores, and setting up cross-platform CI.
> If your organization does not yet have a DUNS number, or no one knows it, visit the Dun & Bradstreet (D&B) website or call 1-866-705-5711 to register or search for a DUNS number. Registering for a DUNS number is free of charge, so if you encounter any organizations or websites soliciting a fee to acquire a DUNS number it is likely a scam or fraudulent.
[1] https://www2.illinois.gov/epa/Documents/iepa/grants-loans/st...
Number for users to phone sounds like a nightmare though
And with 3rd party merchants like Fastspring, Mycommerce, Paddle, Paypro, etc.
It's not just the EU, the US money laundering KYC rules are also pretty annoying.
Now they want to publish my full address too, because they believe I make money off of it, and I can't contest this in any way. Fine. I'll let them delete my account and I'll open source that app and put it on F-Droid then.
The more galling aspect is the home address. I just went through this as well and I don’t at all like my home address being available on the Play Store for my apps. Especially since my apps are local (specific to events in my city).
I haven't jumped on the android bandwagon, but I've been thinking about developing an android app and host it on f-droid provided that I am not forced to use proprietary/NDA crap.
Everything else is trivial. Fork AOSP for an environment to test in, find a non-Oracle Java to build the app for (if that fails, the NDK in c++ will work, but complicate matters), figure out the buildchain to produce your APK, and upload to a store like F-Droid.
Your limitations will come based on potential phone features you require. I imagine camera access or permissions may hit a few pitfalls, and I'm unsure in 2025 how easy those are to overcome (they were nearly impossible the last time I professionally developed in 2013). But Google open sources more than you'd think, so you have a lot of tools at your disposal.
-------
Now, is it practical? No, not really. You're playing on hard mode and will probably fall into a lot of non/underdocumented behavior. You're gonna be a trailblazer for all sorts of issues only the largest, most ambitious companies run into (and probably fix inhouse, so good luck researching others' solutions). Monetization opportunities will be shot, and any attempts to expand platforms will have you hit brick walls as Windows/Apple OS's require non-FOSS apis.
You would only be doing this either for a hell of an impressive portfolio piece, or for ideaological reasons. Otherwise you're shooting yourself in the foot.
So the answer is: No, no practical way exists for people to freely (as in speech) develop android apps. I hope Google gets regulated out of existence.
I think this is, (and maybe always has been) the way forward.
With more and more languages being able to either compile down to js or even wasm, I feel like the bar might be a little lower than before.
Times have changed.
But for reference, this author is in the Neverlands and things that seem trivial for US businesses are apparently more involved over there. These small 30 euro costs aren't worth it to update some 10 year old app you'd only update if you just needed some trivial migration updates.
I don't know where the writer writes from (don't care to look it up). From experience, in the UK there are companies were you can outsource (at little cost) most of your admin stuff, and/or you can also mark them as the 'HQ' of your company, using their address instead of yours. I will go ahead and assume that everywhere in the civilized world similar companies exist. Also "is only right morally, but not legally" is very BS. These are the rules, take them or leave them. You can escalate, but not break them, otherwise if YOU pick which rules YOU want to break, then I will pick the rules that I want to break, and then it goes only downhill.
DUNS: I remember when I created an app for Apple Store, they were requesting the same. I did it. It took me 10mins, nothing to see here, move on.
For reference, I had my own Ltd in the UK, I was contracting and was using the same Ltd for my app, so I've actually done this.
Doing business has costs. If the writer doesn't want the costs of doing business, perhaps he/she is in the wrong business (?). But "screw the rules" is not cool.
didn't care to read the article either but provided a dismissive TLDR. The article mentions they are from the Netherlands.
>in the UK there are companies were you can outsource (at little cost) most of your admin stuff, and/or you can also mark them as the 'HQ' of your company, using their address instead of yours.
for a minimimal update on an app you finished 11 years ago that probbably isn't making money? No thanks. I think it's important to remember that this isn't some active business, but a hobbyist that made something at a completely different phase of life.
>DUNS: I remember when I created an app for Apple Store, they were requesting the same. I did it. It took me 10mins, nothing to see here, move on.
Also in the article. Feel free to correct me since you're closer, but apparerntly the Netherlands needs to pay to find the DUNS number that was already registered to the CoC.
>Doing business has costs.\
They aren't a business past adding migration updates to an old app. Yes, it is a big deal to give a private middleman your passport and let them post your address/phone number to the world. It's absurd to get on a high horse to a single dev, especially in a community that I thought valued privacy.
Everyone seems to have a love/hate relationship with app/play stores and these stores have a stranglehold on developers. "This is our new policy. Accept it or we'll kick you out."
The TOS we enter into with app/play store is fully in their favor with no rights to the developers.
For android, worstcase, i can have people download the apk from my website. For iphone there's no way around.