What a first-party access route actually discloses in an Android catalogue app

Comparing direct Play Store installs, sideloaded APKs and operator-mediated access routes — and what each discloses to the visitor before the Install App button is tapped.

Editorial cover image for first-party access route

Three ways an Android app can land on a device

A real-money catalogue app can land on a visitor's device in three ways. The first is a direct Play Store install. The Play Store verifies the package signature, runs safety checks, and pushes updates automatically. The second is a sideloaded APK. The visitor opens the APK, confirms the install source, and Android installs the package. The third is an operator-mediated access route. The visitor opens a URL on the catalogue domain, the URL opens the operator endpoint, and the operator endpoint delivers the package.

The my11 app uses the third path. The catalogue site does not host the Android package. The catalogue site does not embed the operator endpoint URL. The catalogue site points to the verified first-party access route, and the route opens the operator endpoint in a new tab.

What the direct Play Store install discloses

A direct Play Store install discloses the publisher name, the package name, the latest version, the file size, the rating, the download count, the update date, the developer name, the developer address, the developer email, the developer website, the permissions, the screenshots, the description, and the reviews. The Play Store also publishes the privacy policy. The Play Store runs Google Play Protect on the package. The Play Store pushes updates automatically.

The Play Store disclosures are useful for the visitor. The disclosures are not always available for a real-money catalogue app. The operator may choose not to publish the app on the Play Store. The operator may choose to publish the app on the Play Store with a different package. The catalogue site does not have the authority to confirm the operator's Play Store status.

What the sideloaded APK discloses

A sideloaded APK discloses the package name, the version, the certificate, the file size, the permissions, the install path, and the update cadence. The sideloaded APK does not disclose the publisher name, the rating, the download count, the developer name, the developer address, the developer email, the developer website, the screenshots, the description, or the reviews. The sideloaded APK does not run Google Play Protect. The sideloaded APK does not push updates automatically.

The sideloaded APK disclosures are limited. The disclosures are not always available for a real-money catalogue app. The catalogue site does not publish the APK file. The catalogue site does not republish the package version, the file size, the certificate, the developer name, the update date, the malware scan, the rating or the download count.

What the operator-mediated access route discloses

The operator-mediated access route discloses the operator's identity, the operator's terms, the operator's privacy policy, the operator's bonus rules, the operator's responsible play policy, the operator's eligibility checks, the operator's KYC requirements, the operator's withdrawal conditions, the operator's dispute resolution, the operator's licence number, the operator's regulatory approval, the operator's legal name, the operator's registered address, the operator's founders, the operator's employees, and the operator's financial condition. The route also publishes the package name, the version, the file size, the certificate, the developer name, the update date, the malware scan, the rating, and the download count.

The route disclosures are the most complete. The route is the only authoritative source for the operator's identity. The route is the only authoritative source for the package. The route is the only source the catalogue site recommends.

What the catalogue site publishes

The catalogue site publishes the source ID, the provider, the RTP, the currency, the category, the install path, the verified support channel, the editorial principles, and the operator-mediated access route. The catalogue site does not publish the package version, the file size, the certificate, the developer name, the update date, the malware scan, the rating or the download count.

The catalogue site uses the verified first-party access route as the only source for the package. The catalogue site uses the verified support channel as the only source for the support desk. The catalogue site uses the responsible play route as the only source for the responsible play context.

How the visitor verifies the route

The visitor verifies the route by tapping the Download App action on the catalogue site. The visitor verifies the route by checking the URL in the new tab. The visitor verifies the route by completing the eligibility check on the operator endpoint. The visitor verifies the route by allowing the install source when Android prompts. The visitor verifies the route by reading the package certificate during install.

The visitor does not verify the route by reading the catalogue site. The catalogue site does not embed the operator endpoint URL. The catalogue site does not republish the package certificate. The catalogue site does not have the authority to confirm the operator's identity. The visitor must verify the route on the operator endpoint.

Frequently asked questions

Is the my11 app on the Play Store?

No. The my11 app is delivered through the verified first-party access route, not through the Play Store. The route is the only source the catalogue site recommends.

Why does the catalogue site not embed the operator endpoint URL?

The catalogue site does not embed the operator endpoint URL because the URL may change. The catalogue site points to the verified first-party access route, and the route opens the operator endpoint in a new tab.

How does the visitor verify the route?

The visitor verifies the route by tapping the Download App action, checking the URL in the new tab, completing the eligibility check on the operator endpoint, allowing the install source, and reading the package certificate during install.

Does the catalogue site publish the package certificate?

No. The catalogue site does not republish the package certificate. The certificate is published on the operator endpoint. The catalogue site does not have the authority to bypass the operator endpoint.

Where can I get support?

Open the live support tab at /contact/. The support team replies inside the browser tab.

Verify the access route

The verified first-party access route is the only source the catalogue site recommends.

Open Access Route
Download App