F-Droid is an alternative Android app store: a catalogue and client for installing mostly free and open-source apps without Google Play. In late September 2026 the project shipped client F-Droid 2.0 — by the team’s account, the biggest app update in a decade: new UI, smarter search, smoother installs and updates, same free-software philosophy without tracking you.
Below: what F-Droid is if you only know the name; what changed in 2.0; how this app store’s trust model differs from Play; and where the limits and risks are. At the end — how it ties to OpenPGP and apps like PGPony.
What is F-Droid — an Android app store without Google Play
F-Droid is an Android catalog and client focused on free and open-source apps (FOSS). Important detail: for many packages F-Droid builds the APK itself from the developer’s public repository, instead of only redistributing a random binary.
Why ordinary people use it:
- install a messenger, VPN client, gallery, keyboard or password manager without a Google account;
- see when an app has controversial traits (ads, proprietary deps, tracking) — often labelled as anti-features;
- update software centrally, like a store, but from a community repository;
- on some custom ROMs (CalyxOS, iodéOS, …) F-Droid already ships as a default app source.
It is not a full Play clone with every bank and AAA game. The catalogue is different: fewer commercial titles, more utilities and privacy tools. The rules are clearer, and the client is not built to profile you for ads.
F-Droid 2.0: what is new in the app store client
Official post: F-Droid 2.0: A New Chapter for Android Freedom (24 Sep 2026). The practical bits:
- New UI in Kotlin + Jetpack Compose, closer to modern Android / Material Design. Navigation: Discover, Search, My Apps.
- Search that understands intent: names, descriptions, categories and translations — useful when you remember what an app does, not what it is called.
- Discover and categories: easier to find new and popular apps; categories expanded (games genres instead of one dump).
- Filters: device compatibility and anti-feature exclusions.
- Store-like installs: on supported devices you can approve before the APK download (pre-approval). Updates check and install in the background by default (you can tighten settings).
- Parallel downloads, alerts for problems (e.g. signing-key change).
- Optional Material You theming; better CJK search.
Rollout is staged after many test builds. If 2.0 has not arrived yet, grab a current build from f-droid.org. Very old Android 6 devices stay on older clients.
How safe is F-Droid as an app store
“Safer than Play” is too blunt. More precisely: F-Droid uses a different trust model that fits privacy-minded users better.
- Built from source. For a large share of packages the path “public repo → binary in the index” is more inspectable than “APK uploaded by an unknown store account”.
- Signed repository metadata. The client verifies the index and packages; a signing-key change is something you are warned about.
- No ad-profile client. Discovery is designed without tracking you to maximise engagement.
- Anti-features. Non-free services, trackers and similar traits are often labelled and filterable.
- Client audit. The team reports an independent security review of 2.0 (OTF Security Lab / Convocation); a full report is expected later.
- Network control. Data and proxy/Tor-oriented settings still matter for high-risk users.
Bottom line: F-Droid reduces “black-box store APK” and client-side tracking risk — it does not remove the need to think before granting SMS, camera or storage access.
Risks and limits — honestly
- Smaller catalogue. Banks, ride-hailing and hit games often live only on Play. F-Droid is a complement or a FOSS base, not always the only store on the phone.
- Update lag. Build pipelines can trail upstream GitHub releases. Bad for critical security fixes; fine for quiet utilities.
- Not every listing is “pure FOSS bliss”. Read anti-features: “on F-Droid” ≠ “perfect privacy by default”.
- Maintainer and metadata trust. A bad recipe, a compromised repo key or malicious upstream are rare but possible. Signatures help you notice anomalies; they are not magic immunity.
- Sideloading and Google policy. You must allow installs from the F-Droid source. The wider backdrop is tighter developer verification and restrictions on third-party installs toward 2026–2027 — a reason independent catalogues matter, not a promise they stay untouched forever.
- 2.0 behaviour changes. Privileged Extension is unused by 2.0 (session installer instead). Some panic/wipe flows changed or are temporarily gone — read the announcement if you depend on them.
How this ties to PGP
OpenPGP is software where “store icon trust” is not enough — you want auditable crypto. On Android, such clients belong naturally on F-Droid: public builds plus the habit of reading anti-feature labels.
We covered mobile OpenPGP with PGPony: why PGP still helps in daily life, how beginners start, and why the F-Droid package is the preferred Android path. After installing F-Droid 2.0, try the new Search for OpenPGP, PGP, or the app name — descriptions are indexed too.
How to install F-Droid and get started
- Download the official client from f-droid.org (not a random Telegram mirror).
- Allow installs from that source, install the client, open it.
- Wait for the repository index, then use Discover or Search.
- Before installing, read the description, anti-features and permissions.
- Choose background auto-updates or stricter manual control.
- A practical split: banks in Play if you must; everyday FOSS tools from F-Droid.
Links
F-Droid FAQ
Is F-Droid an app store? Yes. It is an alternative Android app store (catalogue + client) for installing mostly free and open-source apps without requiring Google Play.
Can I use F-Droid together with Google Play? Yes. A common setup is banks and proprietary apps from Play, FOSS tools from F-Droid.
Is F-Droid safer than Play? It uses a different trust model: many packages are built from source, the repository is signed, anti-features are labelled, and the client is not an ad profiler. That is not a promise that every app is harmless — still read permissions.
What is F-Droid 2.0? A major official client update (September 2026): new UI, description search, smoother installs and background updates.
Where should I download F-Droid? Only from f-droid.org — avoid random messenger “mirrors”.
Related reading
- PGPony and OpenPGP on your phone: why PGP and F-Droid
- Sync phone contacts with Yandex instead of Google or iCloud
- DAVx⁵: sync without Google services
In short: F-Droid 2.0 makes the open store feel much closer to a “normal” app shop in UX, without giving up transparency. For beginners it is a friendly way to install FOSS without a Google account; for careful users it is still “read the label” — open source is not a free pass.
No email, no trackers — just the update feed.







