That's been happening randomly to me.
Their review process is advocated as usually within 24 hours (and heavily advertised by Apple as such, see https://developer.apple.com/distribute/app-review/) and it is taking now much longer.
In the last month, I had to go through the review process twice, and twice I needed to contact them personally after waiting for 1 week of waiting. It did however helped, after every human contact I was reviewed within a few hours.
I got this explanation from them...
> We are currently experiencing a higher-than-normal amount of inquiries and have been unable to respond in the time frame that we would prefer. During these periods of high volume, the app review time will take longer than average, and we cannot currently provide a concrete timeline for when your specific app(s) will be finished with the process
I'm guessing, AI slots invading the store.
I know Github's commit numbers have been pretty staggering YoY.
Also, sometimes, apps will go in review and then just stay in that state for 3-4 days before approval. No idea why.
It let users cash out their Google Play Credits for real cash, which I automatically wired them.
Someone then hacked in to a major bookstore chain, stole piles of Google Play Gift cards, activated them using their access, and used my app to get cash for them.
Luckily, the whole thing blew up on me before I got in serious trouble, rightfully so, and the app was removed by Google, then an investigation followed. A ton of copycat apps popped up immediately after, then a few months months later Google announced their app review process.
It was risky because I didn't actually receive any money from Google until about a month later.
This is the reason I never made a mobile version and all mobile users use it in a browser.
The biggest problem (bug) with this approach is that iOS limits the RAM usage to 2 GB per website. I have to tell many of my users to ditch their $1000 iPads and get a used $150 Macbook for better experience.
I think Apple does it on purpose https://bugs.webkit.org/show_bug.cgi?id=268816
The Google Play process is more thorough. There are a lot of steps and you need to clear them one by one. This means waiting several days between each step. The Play Console dashboard is quite well documented to be honest but can be overwhelming. The main obstacle is that you need to find at least 12 testers to play your game for 2 weeks straight. I ended up paying a service to test my app.
On iOS, the process is a bit more obscure. It's fairly easy to submit an app, but then you don't really know what's happening. You can only see a status like "Pending review". And then one day, you are approved.
Overall, the iOS process felt easier for me. As long as your build succeeds and you provide the correct information, your game can be live within a week. The Android process took more than a month in total.
Once you get over that hurdle for your first release, at least you don't have to do it for every update.
The Play Console is a bit fiddly and I'm always getting random warnings that I need to comply with some new rule by an arbitrary date or my app will get delisted.
[1] https://play.google.com/store/apps/details?id=com.gads.hamil...
That's an understatement and a half. It's massively over engineered and complicated, especially when compared with (say) the dashboard on Itch.
The next update won't be huge, (Google required us to make all screens 'edge to edge'[0], which took up most of my time last month). I'm hoping for some solid improvements now that's out the way, once the release pipeline has returned to normal.
Feel free to get in touch if you fancy contributing.
[0] https://developer.android.com/develop/ui/views/layout/edge-t...
The way I did it was to firstly get accessibility identifiers on everything. Then have it record everything I do on an emulator to navigate the entire app. Then left it for a while to work out how to actually use the app via the emulator. Once you have this sort of baseline. A lot of changes are really quite pleasant. I often ask for an HTML gallery of screenshots covering a few device sizes as the step before I bother running it on a device myself.
* We target minSdk 24
* We're still using XML views
* We target a large variety of form factors
* We have a lot of screens, and these have a lot of configuration options.
I really wish it was "point an agent at it, and walk away", but many screens ended up being hours of iteration with Fable driving my phone/an emulator to produce an acceptable outcome.
Given that my Pixel 9 Pro has system screens which are still broken under edge to edge, it's not an easy change, and takes up time which could have been going towards feature development.
The explosion in LLM app development has clearly created a bottleneck at the human review steps. Not only delays but much more “dumb” rejections from likely over-stressed humans.
Before that we had a hotfix update (a very small change) and still it took longer than a week and a support ticket (after which it had been approved in a day)...
Was only 48-72 hours until this year, where it randomly jumped to 2 weeks or longer like it still is.
It's really frustrating, and makes it very difficult to develop with, let alone reliably release features across platforms.
And before someone says "well akshully you can technically do it on Android," Google has been working tirelessly to make it as onerous as possible for both developers and customers. For example, users need to separately authorise each app (browser, files manager, alternative store, etc) to install an APK from outside the Play Store. Google also does background scans using "Play Protect" which will periodically delete apps Google doesn't approve of. This happened to me with SmartTubeNext. I have a dozen other ways Google ensures users are discouraged from stepping outside the Play Store.
I'm not saying we have the perfect system but anything that slants the system towards "easier downloads" or "less gatekeeping" brings large, obvious risks. I don't see how regulation would address them.
My banking works in my 'unprotected' computer browser. So I'd expect giving anyone equivalent freedom. I don't mind if there's a default for gate-keepers as long as they allow competition. but I would expect to have same freedom on my mobile devices as on my laptop.
We should have web installs by now. The only reason we don't is because Google and Apple like cash and their little monopolies are easy money.
Big tech loves to "protect us". See Anthropic and OpenAI worried about intelligence.
Google doesn't care that its AdSense ads marketplace is flooded with malware. Or that YouTube is rife with scams. Wonder why not. The blatant policy contradiction couldn't be because money, right?
They were a massive issue before, and now they're barely a thought for most people.
These review processes have been good for the general population.
And I'm sure everyone remembers ransomware.
No one is saying OS shouldn't have security measures, permissions/entitlements and app sandboxing, user land, etc.
I still don't understand why my desktop/laptop is allowed to be 'owned' by me. but my iPhone is a closed-gardened where I'm just a guest in a device I own. and that's nearly what Google is now doing.
Even though review processeses generally do not exist for computers, they are part of that same trend.
Vulnerabilities aren't intentional.
> reviewed apps that were used for fraud or access as bad actors
The App Developer Verification program, Android Advanced Protection Mode, and Play Protect are all systems put in place in response to "bad actors".
1. don't force auto-updates
2. still review apps uploaded to Google Play, but don't force users to use Google Play
If the concern is what if users use an alternate source for apps and those have viruses, then.... okay. If the user wants to stay with strictly Google-vetted apps, they can. If desired, you could have an option on setup that users could choose to select that would put the device in a restricted mode that can only use apps installed from Google Play.
But the motivation here isn't just security, it's control. Google doesn't want anyone to have an Android device that is independent of Google services.
So this doesn't solve the issue pointed in the OP.
> don't force auto-updates
I'm sure everyone would love non-technical people to stay behind dozens of security patches for apps they may use everyday because they forgot to press update.
this is identifying the tension yeah, but if a review process regularly takes weeks or months, then the security patches are still missing
Yes it does. This is their point:
> The fact that we cannot download and install software from the internet onto our phones JUST like we can do with our computers is a symbol of our inept and ineffective politicians.
It should be as easy for me to use an alternate storefront - or download directly from a site - straight to my phone. The googleplay store, which is (somewhat) curated and (generally) "safer" can also exist. I, as a user, get to decide which path I want to take. This is literally no different from my desktop and laptop, we already live this life. MacOS allows me to download .dmg files and install (though they are admittedly getting increasingly annoying/friction-y about it) at my own risk. Why should my phone be any different? It’s a small computer. That’s it.
It’s about user choice. It’s my hardware, so I can do with it what I want so long as I’m not using it to inflict harm on others.
I mean, probably not technically due to some EULA you were forced to sign which says the hardware is actually Google/samsung/etc and not yours. Giving them the right to brick your phone the moment you step out of the bounds they define.
We really need some sort of open firmware legislation that mandates manufacturers of computer components need to opensource their drivers and firmware. There's no "special sauce" in that software that warrants a company being able to keep it secret. It's literally just so they can force you to purchase new devices when they get bored of supporting their old devices.
Splitting git tech-monopolies it is a survival need. Or we do it, or we will end up with a collapsed society. Entities that spy on all citizens and gatekeep access to news and services are contrary to basic human rights and democracy.
MacOS has been moving to a more locked down model over the years - increasingly difficult to install unsigned applications, SIP, etc.
> Windows
I think Windows is incredibly impressive for its ability to run binaries from many years ago, but I don't think there's much people would point to as a positive regarding Windows’ approach to app security.
Even super basic stuff like remembering a single secure password instead of reusing the same 2 or 3 basic initials-dob-symbol permutations that were probably pwned 10 years ago seems insurmountable.
If people want to have dumb passwords and download malware, then so be it. You think they can’t do that today with the google play store? Of course they can. Most malware on android comes from the Google play store.
People that accidentality cut their fingers in lawnmowers due to lack of safety features are allowed to sue the lawnmower company.
What I would agree is that it is about time computing gets the same liability laws that the rest of the world already has in place and no EULAs that work around local laws should be considered valid in any form or shape.
Lets stop talking about open source as special snowflakes where everything is excused.
Lets strive for quality in software.
Anyone is allowed to sue the lawnmower company. Did they win?
I agree that the defaults should be secure, but you can't force security on people without creating parallel issues which are maybe worse. Centralizing this power in a single point can have orders of magnitude bigger blast radius than a security failure on an app.
At some point users have to take responsibility and be accountable for their actions. We can't just infantilize them forever as if a magical hand will always be over them protecting and having their best interest in mind. And we certainly shouldn't punish every user for the sake of some of them.
The worst part is that Google gets the benefit of putting itself as the central point of control over the ecosystem based on a promise to keep users safe, but without any of the liability from failing to keep that promise. When the app store is chock full of malware I'm really starting to suspect that their goal is actually only the control. And all those people defending it with "but people don't know better, they need a hand to guide them" were equally misled. What do you think?
The computer itself won't really do anything. But I'm sure suicides go up when people lose all their money, or get personal private details leaked, and so on.
Therac-25 is an important software-development case study but a torturous stretch of "Using a computer wrong"
And, honestly, if you think the endpoint safety problem doesn't apply to you, you are part of the problem.
Is that true - do you not see significantly fewer of those installs on random PCs now than you did years ago? And that's even with the current situation not being what I'd call fully locked down.
For free (like for real no microtransactions) that is different. For the rest, they already have that.
As for doing without Google, I'm kinda doing that myself (using a Linux phone even). But tbh, I think that nowadays moving to another country to escape a government you fundamentally disagree with is easier than moving away from Google.
If you're banned from Google? Good luck, you're fucked.
I would be shocked if you could publish an iOS app without Apple being able to tell the government who you are. Less because Apple cares and more because Apple requires you to pay, which is very hard to do anonymously for something like this (I’d bet the options they offer are effectively “credit card only”).
Clearly we need to regulate the kitchen knife industry more. There should be a central authority that sells authorized kitchen knives with at max 6cm length and all other knives should only be available to certified chefs.
Once we have outlawed the longer knives and strong restrictions on ordinary kitchen tools become normal we should just outlaw knives altogether. You can still hurt yourself with a short knife. Only chefs should ever be allowed to own such a dangerous tool. Just buy or order readily prepared food. Why would you do this weird nerd thing called cooking anyway? Just choose from the official list of allowed foods.
The idea that we have to prevent people from being in control of their own computers — that's what a smartphone is — is deeply dystopian and authoritarian.
People are rightfully nervous when they see someone walking down the street swinging a knife i.e openly misusing it or treating it casually
People don't realize how much software is being misused or treated too casually. They might be similarly bothered by lax security on databases and data leaks if they realized that it represented a threat to them
When companies get hacked and millions lose their personal data, nobody cares. When individuals get hacked, it's a major issue that justifies locking down consumer's hardware to protect them from the burden of controlling their own devices. See how that works?
"Those who would give up essential Liberty, to purchase a little temporary Safety, deserve neither Liberty nor Safety."
It's partly lawsuits that are pushing Google to do this in the first place - because people download shady apps and get scammed or hacked.
The more regulation we get, the more it's going to push towards central app stores that are inaccessible to small devs.
Do you want to bring back those glorious days?
Back in the day users didn't really have much valuable and sensitive stuff on their machines and malware was rather benign - just sending spam, not trying to fuck up that specific user. Could be a bit different when it's a smartphone user depends on.
Code signing with warnings about non-signed apps is enough
There is major regulation in place already. EU's Digital Markets Act forces these OS gatekeepers to allow alternative app stores and external payment methods. It also prevents Apple from playing anti-competitive games with App Store rules, like banning hyperlinks within apps that could be used to allow the user to make a payment elsewhere.
The current US government won't do anything to follow suit, but hopefully a future one might.
So does that mean:
1. People in the EU can continue to use F-Droid etc. exactly as they have in the past, permanently? No Google verification of developers needed? 2. People are free to install apps from any APK they choose?
This is exactly why I use a GNU/Linux phone that runs a desktop operating system with no artificial restrictions. Debian repositories are good enough to save me from malware, aren't they?
As for SmartTube, their keys were compromised. Inconvenient, but it wasn't about hostility to self-installed applications.
Key compromise sucks and is hard to protect against. That said the Apple/Google app stores are also full of scams where people lose a lot of real money:
https://www.macrumors.com/2026/07/27/apple-app-store-fake-bi...
And yes, they also have apps besides games on their stores, and support external keyboards and mices.
Anyone can put up a PWA. The only org that hates this is Apple.
The complaint is about a shared resource, which would require governments to adopt open source policies and _pay_ for it just like they do the post office.
But ya'll hate government, so here we are.
This is all documented in great detail in the links i shared
Paradoxically, as long as WebKit is mandatory on iOS, the open web is safe: Websites have to build for a lowest common denominator standard instead of building for Chrome proprietary APIs.
Comparing phones to PCs isn't a great comparison because PCs don't have a great track record and the amount of personal data and ease of installing lots of apps is quite different. Of course the current arrangement is far from perfect, but acknowledging the problems it's trying to solve is an important step towards trying to find a solution that is better.
I imagine nearly all the security review is automated scans, and not the source of the delays.
this position of privilege is what the OS vendor (google in this case) wants, because it spells profit.
I dont trust it.
The only trust i have is community trust. Piracy works on this trust, and it has worked for very long.
FYI Samsung's is even worse.. 6-8 weeks. Hope you get it right the first time you submit your app.
I submitted Signage Sync (https://signagesync.app) last year, still on my third review. Fingers crossed:)
At the time I couldn't imagine paying $99 for an Apple Developer account and waiting a week to publish my app...
Endless more information on all of this at
Remember, Blink began as Google's 2013 fork of WebKit. They've embraced and extended it, but thankfully the "extinguish" step is taking longer than they thought. This makes the "open web, as long as it's my engine" people upset.
Safari's PWA support is not as complete as Chrome's today, but it's as good as Firefox's support and perfectly capable of supporting rich, standards-based apps. https://pwascore.com/
I'll simply say that if you bothered reading anything (let alone objectively), you'd clearly see that no one is arguing for a blink monoculture. They're arguing for allowing everyone to choose whichever browser and browser engine that you want. Safari included.
The math isnt mathing on that site... And, no, safari is NOT capable of PWAs - which is the primary point of contention (not obscure APIs, though safari generally lags in all of that as well). They deliberately hobble PWAs and make them very difficult to install.
edit: also, your site is just obviously biased/poorly done, because there exist many better comparisons of web features, which show how vastly far behind Safari is, often even of Firefox. This is unsurprising given your chosen style of rhetoric
> And, no, safari is NOT capable of PWAs…
Incorrect, see my link. PWA installation on iOS is simple and idiomatic, and the same as it is for all websites: Share > Add to Home Screen.
your argument amounts to "this person is incapable of being objective, let alone decent, because they work at xyz". Moreover, you literally didn't address a single thing presented in either link that i shared - which directly refute your nonsense. Pure ad hominem, and worse.
You are not a serious person if you think that PWA installation is "simple and idiomatic on iOS". It is buried multiple menus, taps, drags etc... deep. Most chromium browsers present a button right in the address bar or at least conspicuously in the main menu. Moreover, they allow developers to ask for the ability to prompt users to install the app.
https://adactio.com/journal/18252
https://adactio.com/journal/22757
Apple forces their employees to debase themselves in order to defend this status quo. eg:
https://github.com/w3ctag/design-reviews/issues/1245
https://github.com/WebKit/standards-positions/issues/619
Take care. And keep that math not mathing!
If you can offer recommendations for data-based improvements, I'd sincerely appreciate it! It was made without any concern for Safari "winning", as is probably obvious since it has the lowest score. Methodology described here: https://pwascore.com/about
About PWA Scores:
• The main score shown is weighted for feature importance
• Only stable (non-experimental) features are counted
• Tap or hover any score to see:
– Raw scores (simple % of supported features)
– Experimental feature scoresHit the share button, "Add to Home Screen" is very difficult to install?
I generally see my legal system create severe delays (regardless of how much that victimises or costs everyone involved)
Better a delay that getting your account closed without recourse. But you are right, years of conservative governments have starved the government and its services are slower than they should around the west world.
Very much likely an automated triage based on code change or complexity.
When Shopify announced their shift from React Native, this is actually what was on top of mind for me. Week+ delays for critical bugfixes is insane. Being able to patch things with OTA updates is tablestakes at this point.
It allows the users to discover my web app through the Google Play Store. My app was also available as a PWA but I mostly push the TWA currently.
Itch.io is an option for people who don't want to set up a site or handle payments. While they focus on games, they're cool with distributing non-games:
https://itch.io/blog/32835/itchio-isnt-just-for-games-check-...
Only apps that get flagged by the AI reviewer then have to go through a separate, slower human review process.
Google Play is regularly slower now than App Store Connect, which never used to be the case
As someone new to the app publishing world I am surprised at how strict the requirements are, given the absolute dross you can find published.
Getting a new app on the store is a bit cumbersome, but it should be.
A new era for choice and openness : https://android-developers.googleblog.com/2026/03/a-new-era-...
It's unfortunate the official f-droid client is an unusable mess. (I stopped using it years ago, maybe they fixed it.)
There's also f-droid classic, can't remember why I use foxy droid over it.
This is fight for big dogs now.
On the flip side, googles release infra provides much more functionality for apps that already has scale. I wish apple were more production oriented too.
What's most galling is that if you use CapacitorJS or similar you can ship app updates instantly to your users but if you write native first-class OS citizen apps you are penalized.
There is nothing quite so annoying as having a fix for a bug people are running into and have zero control over when it will get out to them.
Perhaps I'm misunderstanding what you are saying here but less than a month ago I released a brand new app with no beta period, direct to production (white labeled app, which is why I didn't need a beta)
https://support.google.com/googleplay/android-developer/answ...
Ah yes, the extremely diverse offering of OpenAI, Google, Anthropic, Microsoft, and Mistral (a fake "euro" chatbot). Mozilla is truly a "people's" company.
Lesson in there.
Apple has it's own issues, they often just answer with a random question so they can kick the review down the line. "Are you sure this is your pricing?" "Can you confifrm you have not selected that country" and then you have to wait another 2 days.