The App Store Heist Isn't Another App Store
Google Play began distributing rival app stores on July 22, 2026. Everyone will look at the storefront. The money is one layer underneath, in the software required to run one.
On August 10, 2026, a U.S. Android user could open Google Play, find a competing app store, and install it from inside Google's own product. Aptoide Games, the gaming marketplace run by Portuguese distributor Aptoide with roughly 25 million monthly active users and more than 40,000 titles, became the first alternative Android app store distributed inside Google Play in over a decade.
Three days later, James Donato, the federal judge overseeing remedies in Epic v. Google, held a compliance hearing in San Francisco, watched Epic demonstrate what the install experience actually looked like, and told Google it wasn't acceptable. Searching "store for apps" in Google Play returned Walmart. Aptoide's listing showed a "View" button where every other app shows "Install." An extra interstitial asked users whether they were sure they wanted to proceed. Donato gave Google until August 20, 2026 to fix all three.

The naive read of that news is that Google Play has cracked open, so somebody should rush in and build the better app store: indie games only, apps for parents, privacy-first apps, AI apps, whatever. There's a version of that business worth building, and we'll get to it. But the more interesting heist sits one layer below the storefront. Here's the opportunity:
The money: Ten operators at $2,000 a month is $20K MRR; twenty-five is $50K. Every one of them already pays Google $20,000 a year.
Inside:
• Full MVP scope for the StoreOps control plane
• Three-tier pricing from $1,000 to $12,000/mo
• A 90-day plan to three paying operators
• Three moats, starting with operational history
Google has created a new class of company: the licensed Android marketplace operator. Those operators now have to ingest a catalog, track developer authorizations, keep listings synchronized, submit APKs for review, maintain policy declarations, monitor opt-outs, handle version updates, preserve compliance evidence, run support and takedown processes, and wire into Google's install infrastructure. All of it under audit, with published thresholds they can be removed for missing. None of that operational work existed in July.
What the two programs actually require
Google split the opening into two programs, and the difference between them is where the business hides.
The Third-party App Store on Play Program lets an approved marketplace be distributed through Google Play to U.S. users. It costs $15,000 a year. Five thousand of that is credited against manual review costs, and security and content reviews generate variable charges on top, which Google invoices whenever they reach $10,000 or monthly, whichever comes first. The operator has to be a registered organization, target U.S. users, run an open marketplace with non-discriminatory policies, hold written authorization from every developer it distributes, and submit both its own store updates and every catalog app version for review before shipping them.

The Play Catalog Access Program is the other half. It lets an approved store surface apps from Google's own Play catalog, for $5,000 upfront and $5,000 annually after. Downloads still route through Google Play. Google's service fee still applies. And Google explicitly forbids charging users extra to download or install anything sourced from the Play catalog, or monetizing those installs in any other way. The program is U.S.-only, and stores can't use it to reach anyone outside the country.
Run both and the published fixed fees come to $20,000 a year before a single variable review charge.
The last of those rules kills the most tempting business model on the table. You can't clone Google's catalog, undercut its take rate, and pocket the spread. Google stays in the fulfillment chain, keeps its fee, and forbids you from adding one of your own. Whatever value a rival storefront creates has to come from discovery, curation, and trust instead.
It can also come from operations, and that's where a solo builder should be looking.
Google accidentally wrote the spec for a vertical SaaS company
Read the implementation docs closely and they stop reading like a launch announcement and start reading like a requirements document somebody left on a table.
An operator with catalog access receives a private export dropped into its own Google Cloud Storage bucket, regenerated at least daily, each version stamped with its own identifier. The payload is not small: package names, developer details and contact information, category and subcategory, in-app purchase and advertising flags, U.S. pricing, device requirements, SDK versions, excluded devices, full localized store listings with icons and screenshots and video, permissions, privacy policy URLs, IARC certificates, release dates, publication timestamps. Each record also carries a delivery token that invokes Google's inline install flow. Those tokens are unique to the app-and-store pair and expire after seven days.

Between daily exports, Google exposes a change API. It emits two event types: modifications, when an app is edited, first published, starts targeting the U.S., or newly opts into catalog inclusion; and deletions, when an app is unpublished, suspended, blocked, stops targeting the U.S., or opts out of your particular store. Google recommends polling it every minute. The event window is 36 hours. Miss that window and your only recovery path is reconciling against the next full snapshot.
A marketplace operator therefore carries a 36-hour blast radius on every change it fails to catch, and a seven-day clock on every install link it's serving.
The publishing side is heavier still. Google's App Store Review API expects operators to submit metadata, listings, APK binaries, and policy compliance declarations, assembled as an atomic snapshot: upload each asset, cache the returned identifiers, then commit the whole package in one call. The declarations cover privacy policies, advertising IDs, target audience and content ratings, ads, health functionality, financial functionality, and testing credentials, with conditional requirements layered on for government apps, news and magazine apps, and social and dating apps that trigger additional safety and moderation requirements. Rate limit: 300 requests per minute per store.
Underneath all of it sits the compliance floor. Malware install attempts have to stay below 1% over a rolling 30-day window, measured globally across all devices. Audited catalogs can't exceed 2% content policy violations. Trust and safety policies have to be published, parental controls provided, IP dispute processes staffed, customer support reachable.
The startup here is a control plane for running an Android marketplace, not another dashboard estimating download counts. Call the category StoreOps.
An operator connects its Google credentials and its existing catalog. The system ingests the daily export, polls the change feed, reconciles developers and applications, flags missing declarations, stores evidence, assembles submission packages, tracks review state, alerts when an app opts out from underneath you, records every catalog decision, and maintains an audit trail of what was published, when, and on whose authority. Think Vanta crossed with a lightweight CMS, except the thing being governed is a marketplace.
Appfigures, AppTweak, and Sensor Tower are a different animal. Those are substantial businesses built around app store analytics, ASO, and mobile growth intelligence, and they exist to help developers and marketers perform better inside app stores. StoreOps helps the app stores themselves stay alive.
There's already a proof point that cross-store workflow carries value. Aptoide Connect sells developers a single integration that reaches every Aptoide-operated store plus a network of partner stores including Huawei, OPPO, and Xiaomi, with a console for managing apps, versions, and distribution, and most teams integrated inside half an hour. Aptoide is a marketplace network selling access to itself, though, which puts a neutral tool serving independent operators in a completely different position on the board.
The opportunity is to become the system of record between a marketplace, Google, and every developer that marketplace distributes.
The MVP is smaller than it looks
Don't start by building a consumer marketplace, and don't build billing or an ASO platform on the way there. Skip the grand Shopify-for-apps abstraction spanning twelve theoretical stores that don't exist yet.
Build one painful workflow exceptionally well, then the next one.
Unlock the Vault.
Join founders who spot opportunities ahead of the crowd. Actionable insights. Zero fluff.
“Intelligent, bold, minus the pretense.”
“Like discovering the cheat codes of the startup world.”
“SH is off-Broadway for founders — weird, sharp, and ahead of the curve.”