Alternative App Stores: Where They Actually Work
Alternative app stores work everywhere on Android but exist on iOS only where regulators forced Apple's hand, mainly the EU and Japan. This guide compares the real options, verified fees and dates, for users and developers alike.
Quick answer
Alternative app stores are app marketplaces other than Google Play or Apple’s App Store. On Android they work everywhere: Samsung Galaxy Store, F-Droid, Aptoide and the OEM stores all install directly. On iOS they exist only where a regulator forced the door open, mainly the EU and Japan, through Apple-notarised marketplace apps. Everywhere else, the App Store is still the only route.
Search for alternative app stores and you get two kinds of page. An Android listicle naming twelve stores with a paragraph each, and an iPhone listicle that either says you cannot do it or points at a jailbreak from 2019. Both miss the thing that actually changed. This stopped being a software question. It is now a question about which country your phone thinks it is in.
The EU’s Digital Markets Act made Apple open iOS to third-party marketplaces in the European Union, and Apple rebuilt those rules again in August 2026 with new fees that take effect on 1 October 2026. Japan’s Mobile Software Competition Act opened a second jurisdiction. Android has allowed other stores since day one, but Google is now tightening who is allowed to publish an installable app at all, starting with four countries at the end of September 2026.
So this covers both platforms and both sides of the transaction: what you can install and where, and whether shipping your own app outside the default store is worth the work. TopTut is a publication and sells none of these stores.
What counts as an alternative app store
An alternative app store is a catalogue that hosts apps, handles discovery and payment, and pushes updates to installed apps, run by someone other than the platform owner. That last part is what separates a store from a download site. F-Droid is a store. APKMirror is a file host with a nice index.
The distinction matters because updates are where sideloading quietly goes wrong. A real store keeps a client on the device, checks for new versions and re-verifies the signature before replacing the app. A download site hands you one APK and forgets you exist. Six months later you are running a build with a patched vulnerability in it and nothing has told you.
Android also allows a third category that iOS does not: a developer distributing straight from their own site with no store in between, which is exactly how Fortnite and several open-source projects reach Android users. On iOS the equivalent exists in the EU, but it is a formal Apple programme called Web Distribution with an approval process attached.
Why the answer depends on where you live
Because the only reason alternative marketplaces exist on iOS at all is regulation, and regulation has borders. The Digital Markets Act designates certain very large platforms as gatekeepers and imposes obligations on them, including a requirement that a gatekeeper allow the installation and effective use of third-party software applications and app stores on its operating system. Apple’s iOS and App Store fall inside that designation. Its obligations became applicable in March 2024.
Apple’s response was to build a permitted path rather than a free-for-all. Marketplace apps, notarisation for every binary, an eligibility bar for operators, and a fee schedule. That path is scoped to the European Union. A reader in the United States, the United Kingdom, Canada, Australia or India has materially fewer options on iOS today: no third-party marketplace, no web distribution, no sideloading a signed IPA outside developer and enterprise programmes. That is not a settings toggle you have missed. It does not exist there.
Japan is the second jurisdiction to move. Its Mobile Software Competition Act obliges similar opening, and at least one marketplace, Onside, now lists both the EU and Japan as live territories. Expect more countries to follow, and expect each one to have slightly different fee tables, because each regulator negotiates its own outcome.
Google’s position under the DMA is different in shape. Android already permitted third-party stores and direct installation, so the pressure landed mostly on Play’s billing and steering rules rather than on distribution itself. Google’s own fee documentation now carries a separate schedule for the EEA, the UK and the US that includes reduced rates for external web links, which tells you where the regulatory attention has been. There is active litigation and ongoing supervision on both platforms in several countries. None of that is settled, and it would be wrong to write about it as though it were.
Watch out
EU access on iOS is tied to your Apple Account country and where the device is, not to a VPN. Changing your billing country to install a marketplace is a good way to lose access to purchases, subscriptions and regional services you actually rely on. Do not do it as an experiment.
Android: the alternative app stores worth knowing
On Android the genuinely useful list is short, and one long-standing name has left it entirely. Amazon discontinued the Amazon Appstore on Android phones on 20 August 2025. It still runs on Fire tablets and Fire TV as the native store for Fire OS, but if a page tells you to install it on a Pixel or a Galaxy in 2026, that page is out of date.
Samsung Galaxy Store
Preinstalled on Galaxy phones and watches, worldwide, and the only sensible route to Galaxy Watch faces, Good Lock modules and Samsung Themes. Trust model: Samsung reviews submissions and signs the client itself. It is the lowest-risk alternative store on Android for the simple reason that it ships with the device. The catalogue outside Samsung’s own ecosystem is thin.
F-Droid
A catalogue of free and open-source Android software where the project builds most apps itself from published source. That build model is the point: F-Droid compiles from source rather than accepting a binary someone uploaded, and flags anti-features such as tracking or non-free dependencies on the listing. It suits anyone who wants auditable software and no advertising SDKs. The catalogue is small, updates can lag the developer’s own releases, and you will not find commercial apps there.
Aptoide
The largest independent Android store, built on user and developer-uploaded APKs across many community stores, and now also an iOS marketplace in the EU. Useful for games and for regions where Play coverage is patchy. The trust model is the weak point: the safety of any given listing depends on who uploaded it and whether the signature matches the official one, so it demands more care from you than a first-party store does.
OEM stores: Huawei AppGallery, Xiaomi GetApps, OPPO and vivo
Each Chinese manufacturer ships its own store, and on Huawei devices without Google Mobile Services, AppGallery is the store. These matter mainly if you are trying to reach those users as a developer, or if you own the hardware. Apps that depend on Google Play Services frequently do not work on Huawei devices at all, which is a distribution problem, not a store problem.
APKMirror and APKPure are not stores
They are sideload sources, and treating them as stores is the most common mistake in this whole category. APKMirror in particular is useful for one narrow job: getting a specific older version of an app, or an update that is stuck behind a staged rollout. It publishes the signing certificate hash for uploads so you can check that a file was signed by the same key as the Play release. That verification step is the entire value. Skip it and you are just downloading executables from the internet.
iOS: marketplace apps, notarisation and web distribution
In the EU an alternative marketplace is itself an app, installed from the marketplace operator’s own website, that then installs other apps onto your device. Apple’s EU documentation sets out the mechanics: the marketplace app is distributed from the operator’s domain, it carries a security token from Apple, and it is managed through App Store Connect like any other app.
Every app distributed outside the App Store must still be notarised by Apple. Notarisation is not App Review, but it is not a rubber stamp either. Apple checks that the app accurately represents its developer, capabilities and costs, that the binary is reviewable and free of serious bugs, that it does not promote physical harm, that it does not ship malware, download unsigned executable code or read other apps’ containers without permission, and that it does not collect private data without the user’s knowledge. Installed apps are also checked for tampering afterwards.
Running a marketplace is not open to anyone. From 1 October 2026 an operator has to satisfy at least one of a set of criteria: a moderate Dun and Bradstreet financial stability score, being publicly traded or owned by a public company, venture funding from an established firm, an audit by a licensed accountant, government, educational or nonprofit status, a stand-by letter of credit of USD 1,000,000, or one million first annual installs worldwide, all set out in Apple’s eligibility criteria. Apple dropped the earlier requirement for an EU legal entity. The same bar applies to Web Distribution.
Web Distribution is the other route: a developer ships the app straight from a domain registered in App Store Connect, on iOS 17.5 and later, with the user approving that developer in Settings before anything installs. It is the closest iOS gets to a normal Android sideload, and it is still gated on Apple authorisation. If you go this way, your own site becomes the storefront, which means it needs to behave like one. The same discipline that goes into building a real ecommerce site on WordPress applies here, because there is no App Store product page doing the selling for you.
The live marketplaces are fewer than the coverage suggests. AltStore PAL, which hosts things Apple will not, such as UTM and emulators. Epic Games Store, live since August 2024, essentially for Epic titles. Aptoide, focused on games. Skich, a game discovery store launched in March 2025. Onside, live in the EU and Japan since February 2026. Mobivention, which is a business-to-business product for companies distributing internal apps. Setapp Mobile, MacPaw’s subscription bundle, shut down on 16 February 2026, and the company pointed at the business terms as the reason. That is the clearest signal available about how hard the economics are.
Alternative app stores compared
Here is the whole field on one screen, with the catch stated rather than buried. Region is the column most listicles omit and the one that decides whether any of this is available to you.
| Store | Platform | Where it works | Good for | The catch |
|---|---|---|---|---|
| Samsung Galaxy Store | Android | Worldwide, preinstalled on Galaxy | Watch faces, Good Lock, Themes, Samsung exclusives | Thin catalogue outside Samsung’s own ecosystem |
| F-Droid | Android | Worldwide | Open-source apps built from source, no trackers | Small catalogue, updates can lag upstream, no paid apps |
| Aptoide | Android, iOS | Android worldwide; iOS marketplace in the EU | Games, older versions, regions with poor Play coverage | Community uploads on Android; verify the signer |
| Amazon Appstore | Fire OS | Fire tablets and Fire TV only | Amazon devices, Amazon Coins | Discontinued on Android phones on 20 August 2025 |
| Huawei AppGallery | Android, HarmonyOS | Worldwide, default on Huawei | Reaching Huawei users without Google services | Apps needing Google Play Services often will not run |
| Xiaomi GetApps, OPPO, vivo stores | Android | Preinstalled on those brands | Reaching those users in their home markets | Regional catalogues, uneven English documentation |
| APKMirror, APKPure | Android | Worldwide | Specific versions, staged rollouts, rollbacks | Not stores. No automatic updates. Verify signatures yourself |
| AltStore PAL | iOS | EU only | Emulators, UTM, apps Apple will not host | Installs from the developer’s own site; EU account required |
| Epic Games Store | iOS, Android | iOS: EU. Android: worldwide | Fortnite and Epic-published titles | Narrow catalogue by design |
| Skich | iOS | EU only | Game discovery with a social layer | New and small; 15 percent commission on purchases |
| Onside | iOS | EU and Japan | General catalogue, card and Apple Pay checkout | Launched February 2026; short track record |
| Mobivention | iOS | EU | Corporate internal and white-label distribution | Business to business only, not a consumer store |
| Apple Web Distribution | iOS | EU only | Shipping direct from your own domain | Apple authorisation plus the eligibility bar |
The security trade-off nobody puts in the listicle
Installing outside a first-party store removes a review layer, and the attackers know exactly which apps you are most likely to go looking for. The realistic threat is not an exotic exploit. It is a repackaged version of an app you already wanted.
The mechanism is simple. Someone takes a legitimate APK, decompiles it, injects a payload, re-signs it with their own key, and puts it on a site that ranks for the app’s name plus a word like free, mod or premium. It installs. It looks right. It asks for accessibility services or notification access during setup, which is the part people click through, and those two permissions are enough to read your screen and intercept one-time codes. Banking trojans have used precisely this route for years.
Modded and premium-unlocked builds are the worst case and deserve naming directly. There is no honest business model behind a stranger giving away a paid app with the licence check removed, so the build has to earn its keep some other way. That other way is you. Beyond the security problem, distributing or installing a cracked paid app is copyright infringement, and it takes money out of the pocket of the developer whose work you wanted enough to go looking for. Buy it or use a free alternative.
Practical safety rules
- Check the package name, not the app name. A fake will use something like com.whatsapp.pro or com.wnatsapp. The real one is exact, and it is visible in Settings under the app’s details.
- Check the signing certificate. Android will refuse to install an update signed with a different key than the installed app, which is a genuine safety net, but only if you installed the real one first. Sources that publish the certificate hash let you compare before installing.
- Prefer stores that build from source. F-Droid’s model removes the question of whether the binary matches the published code, because the project compiled it.
- Leave Google Play Protect on. It scans sideloaded apps too. Turning it off to silence a warning about an app you already decided to trust is a bad trade.
- Refuse accessibility services and notification access unless the app’s entire purpose requires them. A game does not need to read your screen.
- Never install a paid app you did not pay for.
One structural change is coming that will reshape this. Google’s developer verification programme requires developers to verify their identity for apps installed on certified Android devices, whether or not the app comes from Play. Enforcement starts on 30 September 2026 in Brazil, Indonesia, Singapore and Thailand across Google Play, Galaxy Store, HONOR App Market, OPPO App Market, Palm Store, V-Appstore and GetApps, on certified devices running Android 7 and later, and expands globally in 2027. There is a documented advanced flow for power users who want to install from unverified developers anyway, and free limited distribution accounts for students, teachers and hobbyists sharing an app with up to twenty devices.
How to allow installs from another source on Android
Android grants install permission per app, not system-wide, and you turn it on for the specific app you are installing from. The path on current Android versions is:
Settings
> Apps
> Special app access
> Install unknown apps
> [the browser or file manager you are using]
> Allow from this source
Samsung nests it slightly differently, under Settings, Apps, the three-dot menu, Special access. The permission belongs to the installer, so granting it to Chrome does not grant it to your file manager, and vice versa.
What the warning is actually telling you: the app you are about to grant this to can put software on your device that has not been reviewed by Google and whose developer identity has not been checked. Malware routinely arrives by persuading someone to grant this permission to a messaging app or a browser and then serving the file through it.
Reversing it takes the same path and the toggle off. Do that immediately after the install finishes rather than leaving it on permanently. Revoking the permission does not uninstall anything you already installed, so if you want the app gone as well, uninstall it separately.
Pro tip
Grant install permission to a file manager rather than your browser, and download the file first. It forces a deliberate second step, it stops a drive-by download from installing anything, and it leaves the file on disk so you can check its size and signature before you commit.
The developer side: what alternative distribution costs
There are three real reasons to distribute outside the default store: commission, policy, and reach. Commission is the obvious one. Policy matters when your app is legal but not permitted, which covers emulators, certain adult content, some crypto and finance products, and anything that competes too directly with the platform owner. Reach matters if your users are on Huawei devices, or in a market where the default store has poor coverage.
Apple’s August 2026 announcement replaced the per-install Core Technology Fee with a flat 5 percent Core Technology Commission on digital transactions in apps distributed outside the App Store, effective 1 October 2026, and scrapped the Initial Acquisition Fee. That is a meaningful simplification. A per-install fee punished free apps with large install bases; a percentage of transactions does not.
| Channel | Standard rate | Reduced rate | Notes |
|---|---|---|---|
| Apple App Store, EU, Apple in-app purchase | 26% | 15% | Reduced applies to Small Business Program, Mini Apps and Video Partner Program members, and subscriptions after year one |
| Apple App Store, EU, alternative payment inside the app | 20% | 10% | Same reduced-rate qualifications |
| Apple App Store, EU, link out to the web | 15% | 10% | Store Services commission, applies to sales within seven days of the link tap |
| iOS alternative marketplace or Web Distribution, EU | 5% Core Technology Commission | Waiver available | Waiver for marketplace operators under EUR 10m global revenue in twelve months and under EUR 1m lifetime marketplace fees |
| Google Play, EEA, UK and US, subscriptions | 10% + 5% billing fee | Same | Schedule effective 30 June 2026 |
| Google Play, EEA, UK and US, new installs | 20% + 5% billing fee | 15% + 5% | Reduced with Play Games Level Up or Apps Experience enrolment |
| Google Play, EEA, UK and US, existing installs | 25% + 5% billing fee | 20% + 5% | Same programmes |
| Google Play, all other markets | 30% above USD 1m per year | 15% on the first USD 1m; 15% on subscriptions | Subscription rate applies regardless of revenue tier |
| Google Play alternative billing, South Korea and India | Standard rate minus 4 points | Same | You still pay your own processor on top |
| Third-party Android stores | Not uniformly published | Varies | Rates are often negotiated per publisher; treat any single quoted figure with care |
Now the effort, because the rate table is the easy half. A second channel means a second build target and signing key, a second billing integration and its tax handling, a second review or notarisation queue with its own turnaround, a second set of store assets, and a support inbox where users cannot tell you which version they installed. Update logistics are the part people underestimate: every channel needs a release, and a security fix that lands on Play three days before it lands elsewhere is a real exposure window.
Then there is discovery, which is the reason Setapp Mobile’s closure is instructive. Nobody browses an alternative marketplace the way they browse the App Store. If you distribute outside the default store, you are buying the traffic yourself, and your acquisition costs move onto your own P&L. That is a marketing problem before it is an engineering one, and it needs the same treatment as any other owned-channel play: search, content, email, the tools in a working content marketing stack, and the fundamentals covered in our guide to internet marketing strategies. If you are choosing where to sell more broadly, the same logic that drives a look at Shopify alternatives applies: lower fees are only a saving if you can replace the traffic they bought you.
Worked example, stated assumptions. Take an EU app doing EUR 200,000 a year in digital sales, qualifying for Apple’s reduced rate. On the App Store with Apple in-app purchase at 15 percent, Apple takes EUR 30,000. Moving the same revenue to an alternative marketplace costs 5 percent to Apple as Core Technology Commission, EUR 10,000, plus the marketplace’s own cut and your payment processing. At a marketplace commission of 15 percent that is EUR 30,000 more, so EUR 40,000 total and you are worse off. At a marketplace commission of 5 percent you pay EUR 20,000, saving EUR 10,000 before you spend anything on acquiring the traffic yourself. The arithmetic only works if the second channel’s cut is genuinely small and you can fill it.
Mistakes that cost people
Four failure modes account for almost all of the damage in this category, and none of them is exotic.
- Downloading an APK from whatever ranked first. The sites competing for app name plus APK are competing precisely because that query has commercial value to malware distributors. Rank is not a trust signal here. It is the opposite.
- Ignoring a package name mismatch. If the installed app’s package differs by one character from the official one, you have a different piece of software wearing the same icon. Two seconds in the app details screen catches it.
- Assuming an alternative store reviews apps the way Play or the App Store does. Some do a lot, some do almost nothing, and on iOS notarisation is a security and accuracy check, not a content review. Read the store’s actual policy instead of assuming there is one.
- Losing the update path. An app installed from a one-off file has no updater. Months later it is running unpatched. If you sideload something, either install its store client too or diary a manual check.
The developer-side equivalent of that last one is shipping to a second channel and then quietly stopping. Users on the abandoned channel keep running an old build, they keep filing bugs you fixed a year ago, and they blame your brand rather than your release process. Either commit to a channel properly or do not open it.
Verdict
For users: on Android, install F-Droid and use it as your default for anything open source, keep the Galaxy Store if you own a Galaxy, and treat APKMirror as a versioning tool rather than a store. Leave Play Protect on. Avoid Aptoide unless you check signatures, and avoid anything marketed as mod or premium unlocked without exception. On iOS outside the EU and Japan there is nothing to do, and any page telling you otherwise is selling you something or is out of date. Inside the EU, AltStore PAL is the one worth having, because it hosts categories Apple will not, which is the only reason to leave a store that works.
For developers: for most small publishers, alternative distribution is not yet worth it on iOS. The 5 percent Core Technology Commission is fair, but it stacks on top of a marketplace cut and your own processing, and the marketplaces cannot yet send you meaningful volume. Web Distribution is the more interesting EU option if you already have an audience you can address directly, because it removes the middle cut entirely and your existing traffic does the work. On Android, a second channel makes sense in exactly two cases: your app is not permitted on Play, or your users are on devices without Google services. Otherwise put the engineering hours into your Play listing and your own site, and make sure the pages carrying that traffic are actually built to convert, which is where a proper ecommerce SEO checklist earns its keep.
Whichever side you are on, check the date on anything you read about this. The terms changed in August 2026, they changed in 2024 before that, and the enforcement picture in Brazil, Indonesia, Singapore and Thailand changes again at the end of September. Anything written before that is describing a system that no longer exists.
Frequently asked questions
Can I use a VPN to install an EU-only app marketplace from outside Europe?
No. Access to EU marketplace apps on iOS is tied to your Apple Account country and the device’s actual location, not to a VPN. Changing your billing country to install a marketplace risks losing access to purchases, subscriptions and regional services you already rely on, so the article specifically warns against treating this as something to experiment with.
Is the Amazon Appstore still an option for installing apps on an Android phone?
No, not anymore. Amazon discontinued the Amazon Appstore on Android phones on 20 August 2025. It still runs on Fire tablets and Fire TV as the native store for Fire OS, but any guide telling you to install it on a Pixel or a Galaxy in 2026 is describing a store that no longer exists on that kind of device.
What actually separates a real app store from a site like APKMirror?
Updates. A real store keeps a client on the device, checks for new versions and re-verifies the signature before replacing an app. A download site like APKMirror hands you one file and does not follow up, so six months later you can be running a build with a patched vulnerability and nothing has told you. APKMirror does publish signing certificate hashes, which lets you verify a file yourself.
Do alternative iOS marketplaces put apps through the same review as the App Store?
No, not exactly. Apps distributed outside the App Store still go through Apple notarisation, but notarisation is not App Review. Apple checks that the app represents its developer, capabilities and costs accurately, that the binary is reviewable and free of serious bugs, that it avoids malware and unauthorised code, and that it does not collect private data without your knowledge, then checks installed apps for tampering afterward.
Will opening my own alternative marketplace on iOS actually save me money on Apple’s cut?
It depends on the marketplace’s own commission. In the article’s worked example, an EU app doing 200,000 euros a year saves 10,000 euros moving to an alternative marketplace when that marketplace charges 5 percent, because Apple’s 5 percent Core Technology Commission still applies. At a 15 percent marketplace commission, the total cost is higher than staying on the App Store, so the second channel’s cut has to be genuinely small to pay off.
What is Google’s developer verification program going to change for sideloaded Android apps?
It requires developers to verify their identity for apps installed on certified Android devices, whether or not the app came from Play. Enforcement begins on 30 September 2026 in Brazil, Indonesia, Singapore and Thailand, covering several stores including Play, Galaxy Store and GetApps, and expands globally in 2027. There is a documented advanced flow for power users who still want to install from unverified developers.
Is it ever safe to install a modded or premium-unlocked version of a paid app?
No. There is no honest business model behind a stranger giving away a paid app with its licence check removed, so the build earns its keep some other way, usually by reading your screen or intercepting codes through permissions you granted during setup. It is also copyright infringement that takes money from the developer whose work you wanted. Buy the app or use a free alternative instead.
Which Android alternative store should most people actually use day to day?
F-Droid as the default for open-source apps, since it builds from source and flags trackers rather than accepting an unknown binary. Keep the Galaxy Store if you own a Galaxy device for watch faces and Samsung exclusives. Treat APKMirror as a tool for grabbing a specific version rather than a store, and avoid Aptoide unless you are prepared to verify signatures yourself before installing.