Most people tap Install and move on. The Play Store shows a green badge, a star rating, and a million downloads. That feels like enough.
It is not. Google’s Data Safety labels are self-reported by developers and, according to Mozilla’s 2023 audit, inaccurate in roughly 80% of cases. The star rating tells you whether the app crashes, not whether it is safe. The download count tells you it is popular. Popular and safe are different things. Here is how to actually check.
Step 1: Read the Permissions Before Installing
Before you tap Install, scroll down on the Play Store listing to the “About this app” section. Tap “App permissions” at the bottom. This shows you every permission the app will request.
What to look for: microphone, camera, contacts, precise location, phone state, call logs. These are what Android classifies as “dangerous permissions.” They are not inherently bad. A navigation app needs location. A video calling app needs camera and microphone. The question is whether the permission matches the function.
A flashlight app requesting microphone access is not just suspicious. It is a clear signal that something else is going on. A calculator asking for your contacts has no legitimate reason to do so. We wrote a full breakdown of how to evaluate permission requests and what the common traps are.
The key habit: if an app asks for something it should not need, do not install it. There is always an alternative that does not.
Step 2: Check the Developer
Scroll up to the developer name at the top of the listing. Tap it to see their full profile: other apps they have published, their website, their contact email.
What to look for:
- Is the name a real company or a random string? “Shenzhen Hawk Internet Co.” publishes apps. So does “asdfjkl games.” One of those is easier to trace if something goes wrong.
- How many other apps do they have? A developer with 40 nearly identical utility apps is farming installs, not building software.
- When was the app last updated? An app that has not been updated in two years is either abandoned or not being maintained against security patches.
- Do they respond to reviews? Legitimate developers engage with user feedback. Abandoned or fraudulent apps do not.
Shady developers often publish multiple copycat apps targeting the same search terms. If you see five “PDF Scanner Pro” apps from the same publisher, that is not a product line. That is a funnel.
Step 3: Read the Reviews Carefully
Ignore the star rating. A 4.2 tells you nothing useful. Open the reviews and sort by most recent, then scroll to the 1-star and 2-star entries.
The reviews that matter contain specifics: “started showing ads after the first week,” “asked for camera permission after update,” “battery drain got worse after the last version,” “can’t uninstall without disabling device admin.”
These are user reports of real behavior changes. A pattern of similar complaints is more informative than any marketing copy. Look especially for reviews that mention permission changes after updates. That is a common vector for spyware-like behavior on Android.
Step 4: Check the Privacy Label (But Do Not Trust It)
Google’s Data Safety section appears on every Play Store listing. It shows what data the app collects, whether it shares data with third parties, and whether data is encrypted.
The problem: it is entirely self-reported. Google does not verify any of it. Developers fill out a form, and whatever they write appears on the listing. Mozilla’s “Privacy Not Included” team compared these labels to actual app behavior across hundreds of apps in 2023. The labels were inaccurate or misleading in roughly 80% of cases. Developers declare “no data shared with third parties” while bundling six advertising SDKs that do exactly that.
We covered what four independent studies actually found about app store claims in detail. The short version: the labels are not lying in the criminal sense. They are just not checked, not enforced, and not reliable.
Read the label. Note what it claims. Then verify it with something that looks at the actual code.
Step 5: Scan the APK Before or After Installing
This is the most reliable step and the one most people skip.
Static analysis reads the compiled bytecode inside an APK and matches it against known tracker signatures, permission patterns, and code structures. It does not depend on what the developer claims. It checks what the compiler actually packaged.
AppXpose runs this analysis locally on your device. It reads DEX bytecode from the installed APK, matches against over 270 verified tracker signatures, checks APK signing integrity, and cross-references against malware databases. No upload, no cloud processing, no account. The scan takes about three seconds. You can read how the full detection pipeline and scoring model works.
For apps you have already installed, this is straightforward. For apps you are considering, install them and scan before opening. The scan reads the package. It does not need the app to run. If you want a deeper technical walkthrough, we covered how to find hidden trackers in Android apps step by step.
Red Flags That Mean Do Not Install
Some signals should stop you immediately:
- The app requests permissions completely unrelated to its function
- The developer has no other apps or registered their account very recently
- The Data Safety label says “No data collected” but the app requests microphone, camera, or location
- The app is a clone of a popular app with a slightly different name or icon
- There is no privacy policy link on the listing
- The app has not been updated in over two years
- Reviews mention behavior changes after updates, especially around permissions or ads
- The APK size is unusually large for what the app does (a flashlight at 80MB is carrying extra cargo)
None of these alone proves an app is malicious. But two or three together should make you close the listing and look elsewhere.
Apps That Look Safe But Are Not
The hardest cases are the ones that pass every surface check. Millions of downloads. Recent updates. Real developer. Decent reviews. And 30 trackers inside.
In the AppXpose corpus, “AI Browser - Safe & Fast” contains 30 tracking SDKs despite the name explicitly promising safety. Finance apps average 13.5 trackers per app. Your banking app likely contains more tracking code than most social media apps. Weather apps, which should be among the simplest, hit 20 trackers just to show you a forecast.
Even apps from major companies are not clean. Facebook’s scan results show a HIGH risk profile with multiple advertising and analytics SDKs. These are not bugs. They are business models. The app is free because your behavioral data pays for it.
You can explore the full research data covering 3,745 analyzed apps to see the category breakdowns and the most tracker-heavy apps in the corpus.
Before You Install: A Quick Checklist
- Check permissions in the Play Store listing. Do they match the app’s function?
- Tap the developer name. Google them. Check their other apps.
- Read the 1-star reviews. Look for patterns about permissions, ads, or battery drain.
- Check the last update date. Anything over a year old is a risk.
- Scan with AppXpose after installing. See what is actually inside before you open it.
Installing an app takes two seconds. Checking whether it is safe takes two minutes. Most people skip those two minutes and spend the next two years with 12 trackers running in the background.
The information is there. The tools exist. The only missing piece is the habit.
If you want to start building it, AppXpose is free on Google Play. Five scans a week, full results, no account required.