Installing an APK Safely: What Android 13/14 Actually Protects
Turning on install-from-unknown-sources doesn't turn off your phone's protections. Here is what still runs, and which permission prompts to say no to.
On this page
- "Install unknown apps" is scoped per app, not a global switch
- What Google Play Protect will and won't catch
- Permission requests worth refusing
- A slower install checklist
- If the app or its install flow asks for your OTP directly
- When deleting the APK is the right call
- Where the APK file itself sits on your phone
- Updates don't come from Play, so they need the same caution
- A note on app permissions you granted months ago
- Where this fits with the rest of our checks
None of the 115 apps in our review are on Google Play, which means the only way to try one is by downloading an APK file directly and installing it manually. That process is more exposed than a Play Store install, but modern Android still gives you real controls if you know where to look.
"Install unknown apps" is scoped per app, not a global switch
On Android 13 and 14, there is no single master switch labelled "allow all unknown installs" anymore. Instead, when you open a downloaded APK, Android asks whether the specific app you used to download it (your browser, a file manager, or a chat app) is allowed to install packages. Granting that permission applies only to that source app, not to your phone as a whole.
Once the earning-game APK is installed, we suggest going back into Settings and revoking that install permission from the browser or file manager again. It only takes a few seconds to re-enable if you need it later, and it closes the door in the meantime.
What Google Play Protect will and won't catch
Play Protect scans apps on your device even when they were installed outside the Play Store, checking against Google's known-malware database. That is a real, useful layer, and it runs automatically on most Android phones.
What it will not do is judge whether an app is a fair gambling product, whether its withdrawal promises are real, or whether its invitation-code system is worth your time. Play Protect looks for malicious code, not business honesty. An app can pass its scan cleanly and still be exactly the kind of site covered in our real-or-fake checklist.
Permission requests worth refusing
Earning-game and betting-style APKs commonly ask for a bundle of permissions during or right after install. A handful of these have no real function tied to playing a slot or colour-prediction game, and refusing them costs you nothing in the app itself.
| Permission asked | Why it's often requested | Our advice |
|---|---|---|
| SMS / read messages | To auto-read a one-time password during signup | Refuse; type the OTP yourself |
| Call log / phone state | Device fingerprinting for the operator's own tracking | Refuse |
| Accessibility service | Almost never needed for a slot or prediction game; can grant deep control | Refuse, always |
| Contacts | Usually tied to referral or invitation-code features | Refuse unless you specifically want to invite someone |
| Notifications | Bonus and "someone just won" push alerts | Optional; safe to deny without losing app function |
A slower install checklist
- Confirm the domain the APK came from using our how we check apps approach: look up its registration age first.
- Download only from the operator's own site, not a random forwarding link or forum post.
- Let Play Protect finish its scan before opening the app the first time.
- Go through the permission prompts one at a time and refuse anything from the table above.
- Re-lock the "install unknown apps" toggle for whatever app you used to download the file.
If the app or its install flow asks for your OTP directly
A one-time password sent to your phone by your bank or mobile wallet is meant to be typed by you, into that bank's or wallet's own screen, never into a slot or prediction app. If any part of the install or registration process asks you to paste or forward an OTP into the earning-game app itself, stop and close it. That single step is one of the more direct ways an account can be taken over.
When deleting the APK is the right call
If Play Protect flags the file, if the app demands the accessibility service to "work properly," or if it wants your SMS permission before you've even reached the home screen, uninstalling immediately is a reasonable response. None of the 115 apps we reviewed need that level of access just to run a game.
Where the APK file itself sits on your phone
A downloaded APK usually lands in your Downloads folder and stays there after installation, taking up storage and remaining available for anyone with access to your phone to reinstall or resend. Once you've installed the app and decided whether to keep it, delete the original APK file from Downloads. There is no reason to leave an installer file sitting on your device once its job is done.
Updates don't come from Play, so they need the same caution
An app installed outside Google Play also gets its updates outside Google Play, usually through an in-app prompt that downloads a new APK the same way the first one arrived. Treat every update prompt with the same checklist as the original install: confirm it's coming from the app's own domain, not a pushed link from an unfamiliar source, and watch the permission list again in case a new version asks for something the old one didn't.
A note on app permissions you granted months ago
Permissions granted at install time don't expire on their own. If you installed one of these apps some time ago and haven't opened it in a while, it's worth going into Android's Settings, Apps, and reviewing exactly what it can still access. Revoking anything from the refuse list above costs the app nothing if you've already stopped using it, and removes a standing permission you may have forgotten was ever granted.
Where this fits with the rest of our checks
Installing carefully doesn't answer the separate question of whether an app is worth installing at all. Pair this page with our real-or-fake checklist for the domain and homepage signals, and with our legal guide for why none of these apps carry a Pakistani licence in the first place.
Common questions
Does Android 13/14 still let me sideload apps at all?
Yes. You can still install APKs manually; Android just asks per-source-app permission each time rather than offering one global toggle, and Play Protect still scans the result.
Is it safe to grant accessibility service to a slot or colour-prediction app?
We'd say no. Accessibility service gives an app broad ability to read your screen and simulate taps across other apps, which has no real function in a slot game and is worth refusing.
Will Play Protect tell me if a withdrawal promise is fake?
No. It only scans for malicious code, not business practices. Use our real-or-fake checklist for that side of the question.
Should I give a betting app my contacts?
Only if you actually intend to send someone an invitation yourself. Otherwise refuse it; it isn't needed to play the games.