Requested is not the same as granted
An APK manifest declares permissions the app requests. Actual access depends on Android’s permission rules, the device and, where required, a user’s runtime decision. A static list does not show what the app actually accessed. Android’s permissions overview explains normal, signature and runtime permissions.
What should you look for?
Read the package identifier and requested permissions of the actual file, not just the branded name on a download page. Consider why it asks for location, storage or notification access. A declaration of a privileged permission does not mean an ordinary third-party app will receive that privilege.
Data safety and reviews have limits
Google Play’s Data safety section contains developer-provided disclosures that can vary by region and change over time. Reviews describe other users’ experiences. Neither identifies a different shared APK supplied by an unrelated directory, and neither replaces inspecting the actual installer.
Our inspection does not certify safety
We statically read the configured file’s manifest and hash; we did not execute the app, observe its network traffic or independently audit its data handling. The shared-file snapshot lists the ten permissions found on 7 October 2026. If the publisher or file identity is unclear, pause installation rather than bypassing device warnings.
Update record
7 October 2026: guide created using Android platform documentation and the site’s static installer snapshot. Read our editorial policy for the exact verification boundary.