Permissions, privacy policy, update history and the shape of the ratings — four signals that save you the regret later.
An app being in an official store means it passed an automated scan and a basic review. It doesn't mean it respects your privacy, that it's maintained, or even that it works. A quick check before installing saves a lot.
1. Permissions: do they serve the app's function?
The only useful question is: does this app genuinely need this permission to do its job?
- A photo editor needs access to photos — reasonable. It doesn't need the microphone or your contacts.
- A word game needs neither location nor camera.
- A flashlight asking for contacts and location is the classic example of an app selling data rather than function.
The most sensitive permissions are background location, microphone, camera, contacts, SMS, and Accessibility — that last one lets an app read what's on your screen, and should only ever go to an app you fully trust.
2. The privacy policy and the data safety section
Every major store shows a summary of what an app collects. Read it, even quickly, and note three things:
- Does it collect data linked to your identity, or anonymised data?
- Does it share that data with third parties?
- Can you request deletion?
The privacy policy link should work and lead to a real page about this specific app. A broken link or a generic copy-pasted page is a bad sign in itself.
3. Update history
An app that hasn't been updated in two years isn't necessarily bad, but it's probably no longer receiving security fixes and may break with the next OS version. Look at the last update date and at the release notes: does the developer write what actually changed, or repeat "bug fixes and improvements" every time?
4. The shape of the ratings, not just the number
A 4.8 average means nothing on its own. Open the reviews and look at:
- The distribution: a real app has a natural curve with some middling ratings. A distribution made only of 5 stars and 1 star suggests purchased reviews.
- Review language: short, similar phrases posted within days of each other is a known pattern.
- Negative reviews: read them first; they tell you the real problem — excessive ads, crashes, a subscription that's hard to cancel.
- Developer replies: genuine responses to complaints are a meaningful positive signal.
5. Signals to stop at
- A generic developer name with no website and no contact email.
- An app imitating a famous app's name or icon with one character changed.
- A huge download count alongside a very recent publication date.
- A request to install from outside the store via an APK file someone sent you.
- A request for "device admin" or Accessibility with no clear reason.
After installing
Review the permissions actually granted from your system settings rather than inside the app, and revoke what isn't needed — most apps carry on working after an unnecessary permission is withdrawn. And review your installed apps every few months and remove what you no longer use; every installed app is extra attack surface and extra battery drain.
Written for the Store of Apps blog. Corrections and feedback: contact@storeofapps.com.