Conversation

APKs can be end-to-end signed with keys under developer control. You can move between app stores or no store (data is preserved on update with same key). And Google can't fuck with it. (Well, they can fuck with the entirety of the rest of the phone, so that point's kinda moot.)
1
4
Replying to
Developers should release their apps outside the Play Store too rather than only on Play Store. The OS package manager pins the key after the initial install but you still always trusted the Play Store for the initial install and they had Play Store App Signing before bundles.
1
2
Replying to and
On devices integrating Play services / Play Store as part of the partnership program they can do an unattended app install / uninstall and they can also obtain app data for most apps due to being one of the hard-wired allowed backup services. They provide core OS components too.
1
1