A while back I wrote that every major browser extension store needs higher standards. The response was bigger than I expected, and the most common reply was a version of the same question: what about the app stores? Aren't Apple and Google supposed to be the grown-ups in the room?
They are. And they're slipping too.
I've spent 15 years publishing software across the Chrome Web Store, Firefox, Edge, Safari, the App Store, and Google Play. I want these platforms to be good, because our small studio lives or dies by them. So let me be fair before I'm critical: the mobile stores are still the best-run app marketplaces we have. That's exactly why their cracks are worth talking about.
Give Apple its due first
When people say app store review is "security theater," they haven't looked at the numbers. In 2025 alone, Apple says it stopped more than $2.2 billion in fraudulent transactions, part of more than $11.2 billion over the last six years. Its reviewers looked at over 9.1 million submissions and rejected more than 2 million of them. Over 371,000 were rejected specifically for being spam, copycats, or misleading. Another 443,000 were rejected for privacy violations. Apple terminated 193,000 developer accounts and blocked 1.1 billion fraudulent customer accounts.
That is what a curated store looks like when someone actually staffs the review team. Compare it to the $5-forever, no-identity, no-recurring-fee reality of the browser extension stores I complained about last time, and Apple looks downright disciplined.
So this isn't a "walled gardens are evil" post. It's the opposite. The walled garden mostly works. The problem is what still climbs over the wall.
Now look at what gets through anyway
Here's the uncomfortable part of Apple's own stat. If reviewers rejected 371,000 submissions for being spam, copycats, or misleading, that's not the junk being stopped. That's the scale of the tide. Nobody rejects a third of a million copycats unless several million are being thrown at the door.
Open the App Store today and search any popular category. You will find:
- Fleeceware. "Free" apps that do almost nothing until a $9.99-a-week subscription slides up three seconds after launch. Technically compliant, practically a scam, and often sitting in the top charts of their category.
- Copycats. A hit game or utility ships, and within a month there are ten near-identical clones with slightly worse icons riding the original's keywords.
- AI slop. Wallpaper apps, "AI" chatbots, and single-prompt novelty apps churned out by the hundred, each one a thin wrapper around somebody else's API.
None of this is as dangerous as a malicious browser extension stealing your cookies. But it's the same rot in a nicer suit: the store's promise is that someone vetted this, and increasingly that promise only half-holds.
Google Play had to delete half its store to fix this
If you want proof the bar was set too low for years, look at what Google just did. Between early 2024 and 2025, the Play Store shrank by roughly 47%, from about 3.4 million apps down to 1.8 million. Not because developers left, but because Google started enforcing a July 2024 policy overhaul and pulled apps with limited functionality, static content, and single-feature gimmicks.
Sit with that number. Google decided that almost half of everything on its store shouldn't have been there. In 2024 it blocked 2.36 million policy-violating apps and banned over 158,000 developer accounts. In 2025 it used AI to help block another 1.75 million bad apps and banned 80,000 more developer accounts. Google's own developer program policy now leans hard on "minimum functionality" and anti-spam language that simply wasn't enforced before.
Deleting half your catalog to "improve the user experience" is the right call. It's also an admission: the standard used to be does this technically run?, and that was never a standard at all.
It's the same disease as the extension stores
Read my browser extension post and swap the nouns. The symptoms are identical. A low barrier to entry. A flood of AI-generated filler. Copycats riding trademarks and keywords. And badges, rankings, and "Editor's Choice" shelves that stop meaning anything once everything qualifies for them.
This is the enshittification of technology playing out one storefront at a time. The platform launches with real curation, earns trust, then quietly lets the standard drift down while the marketing keeps saying "hand-picked." Users don't notice on day one. They notice after the fifth fake-free app in a row, when they stop trusting the charts entirely.
What "higher standards" should actually mean
I don't think the fixes are complicated. Apple and Google already have the machinery, and Apple's numbers prove it. It's a question of where they point it.
Kill the copycats for real
If an app clones a popular app's name, icon, screenshots, or keyword set, it shouldn't rank, and it shouldn't ship. Apple rejected 371,000 misleading submissions last year. The remaining ones in the charts are the ones worth catching.
Make "free" mean free
Fleeceware is the single most user-hostile thing in either store. A hard rule would fix most of it: if the first screen after launch is a subscription wall, the listing can't say "Free" without a visible price and trial terms above the fold. No more $9.99/week hiding behind a tiny "X."
Charge a recurring fee, verify a real identity
Apple's $99/year already does a lot of quiet work here. Google Play's one-time $25 does less. Either way, a recurring fee plus verified developer identity is the cheapest anti-spam filter there is. It's the same argument I made for extensions, and the reason I think an annual fee beats a one-time one.
Make the charts and "Editor's Choice" mean something
A featured slot should be a promise a human is willing to stand behind, not an algorithmic lottery. If you can't staff curation at scale, curate less and mean it. Firefox's tiny hand-vetted "Recommended" list is more trustworthy than a thousand auto-assigned badges.
Review updates, not just launches
The nastiest tricks happen after approval: the clean app that turns fleeceware in version 1.4, the utility sold to a new owner who flips it. Apple already does version-by-version review. It should be the norm everywhere, tied to permission and ownership changes.
Why a small studio actually cares about this
You might expect an indie developer to want fewer rules. I want the opposite, and it's not complicated: we compete for the same shelf space as the clones and the slop.
When we ship something we've actually sweated over, with real design, honest pricing, and a description written by a human who used the thing, we're standing in a line that also contains a hundred AI-generated wallpaper apps and a fleeceware clone of last month's hit. Every low-effort listing that gets in dilutes the trust of the whole store, and that trust is the only reason a stranger installs software from a studio they've never heard of.
Higher standards aren't gatekeeping against small developers. They're the thing that lets small, honest developers be found at all.
To Apple and Google, and anyone listening
You've both proven you can do this. Apple's $2.2 billion and Google's disappearing 1.6 million apps are evidence that the tools work when you aim them. The job now is to aim them at the stuff users actually complain about (the fake-free apps, the copycats, the slop in the charts) and to keep aiming after launch, not just at the door.
Raise the floor. Verify identity. Make "featured" a promise again. Review the updates. None of this is radical. It's the bare minimum for stores that decide what billions of people are allowed to install.
If anyone at Apple or Google wants to talk about it, I'm easy to find: [email protected].
Robert James Gabriel is the founder of Coffee & Fun LLC, a studio building browser extensions, apps, and web tools. He has been publishing software across every major app and extension store for over 15 years.