Store policy record · Google

Google Play policy on proxy and bandwidth-sharing SDKs

Google Play allows an app to facilitate proxy services for third parties only when that is the app's primary, user-facing core purpose, and Google has used Play Protect to warn about and remove apps carrying some proxy SDKs.

Status
Primary purpose only
Basis
published policy
Checked
2026-09-27
Platform
Google Play
Store
Google Play Store (Android)
Owner
Google
Status
Primary purpose only
Evidence
published policy
PROXIES.SX SDK
The Android SDK (minSdk 24) can be built into an app whose primary, user-facing purpose is sharing the device's connection. It is not for games, utilities or any app where sharing is a side feature.

What the sources say

“Apps that facilitate proxy services to third parties may only do so in apps where that is the primary, user-facing core purpose of the app.”
Google Play Device and Network Abuse policy
“We ensured Google Play Protect, Android's built-in security protection, automatically warns users and removes applications known to incorporate IPIDEA SDKs, and blocks any future install attempts.”
Google Threat Intelligence Group, 29 January 2026
“Consumers should be extremely wary of applications that offer payment in exchange for "unused bandwidth" or "sharing your internet."”
Google Threat Intelligence Group, 29 January 2026

Timeline

Dated events
DateWhat happenedSource
29 Jan 2026Google disrupts a large residential proxy network; Play Protect warns about and removes apps carrying its SDKs.Google Threat Intelligence Group
3 Jul 2026Google acts against a second residential proxy network; Play Protect warns users and disables apps carrying its SDKs.Google Threat Intelligence Group
30 Sept 2026Android developer verification begins for installs from participating stores in Brazil, Indonesia, Singapore and Thailand on certified devices running Android 7+, with a global expansion planned for 2027.Android developer verification

What it means for publishers

  • Sharing must be the app's main, visible purpose, not a monetisation layer in another kind of app.
  • Show an in-app disclosure and get consent before sharing starts; the SDK has no consent screen.
  • Declare the SDK's permissions accurately, including READ_PHONE_STATE, in your listing and privacy policy.
  • Plan for rejection or removal risk even when the policy text is met.

Sources