Playbix

Data safety

Last updated 11 August 2026

How to work out what an app can reach before you install it — and, just as importantly, what we are not able to verify on your behalf.

What we show you, and where it comes from

Every listing shows a permissions section. That list is read out of the app file itself, not copied from a form the developer filled in. A developer cannot understate it, because we never ask them for it — we decompile the app's manifest and take the real answer.

This is the most important thing on this page. Anything else on a listing is a claim; the permissions list is a fact.

Reading the permissions list

Ask one question: does this make sense for what the app says it does?

  • A camera app asking for the camera: expected.
  • A puzzle game asking for the camera: ask why.
  • A flashlight app asking for your contacts: do not install it.

These are the ones worth a second look wherever you find them:

  • Accessibility service. Can read everything on screen and act for you. Genuine accessibility tools need it; almost nothing else does. Every app requesting it is flagged for closer review here, and it is the most abused permission on Android.
  • Draw over other apps. How overlay phishing works — a fake login screen placed on top of a real app.
  • Read or receive SMS. Can intercept one-time passcodes from your bank.
  • Install other apps. Expected from a store or updater. In a game, treat it as a red flag.
  • Query all packages. Lets an app see everything else you have installed, which is a strong fingerprinting signal.

What we verify

  • The permission list is genuine — extracted from the file, as described above.
  • The app is malware-free as far as multiple antivirus engines can tell, checked before publication.
  • Updates come from the same developer. We pin the signing key on first release and reject any update signed differently, so a hijacked account cannot push you a tampered build.
  • A real person published it. Developers verify their identity with a government ID before approval, so there is someone accountable for the software.
  • A human reviewed the listing against our Content Policy.

What we cannot verify

This is where honesty matters more than reassurance:

  • Where your data goes once inside the app. A permission tells you what an appcan access, not what it sends, to whom, or how long they keep it. Only the developer's privacy policy covers that, and we cannot audit whether it is accurate.
  • What happens on the developer's servers. We have no visibility into their infrastructure.
  • Novel malware. Antivirus engines catch known threats. Something written last week may pass every scan.
  • Behaviour changes over time. An app can be well-behaved for a year and then ship something harmful. We re-review on report, but we are not continuously watching every app.

Steps worth taking

  • Read the permissions before installing, not after.
  • Open the developer's privacy policy — the link is on the listing when one exists.
  • Check who published it. The developer page shows their other apps and when they joined.
  • Deny permissions at first launch where Android lets you. Most apps keep working, and the ones that refuse to are telling you something.
  • Uninstall what you no longer use. An unused app with permissions is pure risk.
  • Never install a "premium unlocked" or cracked build from anywhere. It is the most common way Android malware spreads, and it is banned here.

What Playbix itself collects about you

Briefly, because you should not have to read a policy to find out:

  • Browsing and downloading needs no account.
  • When you download an app we record which app and version, the time, your approximate country, and a salted hash of your IP address — not the address itself.
  • No advertising cookies, no third-party analytics, no session recording.
  • The Android app tells us only which apps you installed from Playbix, so it can offer updates. It never sends your full installed-app list.

Full detail in the Privacy Policy and Cookie Policy.

Found something wrong?

If an app collects data it does not disclose, report it and choose "Collecting personal data without disclosure". Undisclosed collection breaches our policy and is grounds for removal. For anything urgent, email abuse@playbix.store.