QUERY_ALL_PACKAGES and the Play Console declaration

Checked against Google's policy pages on .

  • android.permission.QUERY_ALL_PACKAGES

What does it allow?

Since Android 11, an app that targets API level 30 or higher cannot see every other app installed on the device. The system filters what methods like getInstalledApplications() and queryIntentActivities() return, so the app only sees the apps it has a reason to.

QUERY_ALL_PACKAGES switches that filtering off: the app can list everything installed. Google treats the list of a person's apps as sensitive, which is why it is a restricted permission on Google Play.

Which apps does Google Play allow to use it?

Google's policy names the kinds of app where discovering installed apps is the core purpose: device search, antivirus apps, file managers and browsers.

It rules out uses "not directly related to the core purpose of the app", selling the data, and any case where the task "can be done with a less broad app-visibility method". That last clause is the one most apps fall under: if you can name the apps or intents you need, you do not qualify.

Why is it in my app?

Few apps add QUERY_ALL_PACKAGES on purpose. It usually arrives through the manifest merge, from a library that wants to know which other apps are installed.

Open the Merged Manifest tab in Android Studio, or paste your merged manifest into the permission checker, to see which library brought it in.

To see every permission in your build and which ones may need a declaration, paste your merged manifest into the Play Console permission declaration checker.

What can I use instead?

Declare the apps or intents you need with a <queries> element in your manifest. Android then makes exactly those visible, with no declaration: by package name (<package android:name="com.example.app" />) or by intent (an <intent> with the action and data you want to hand off, such as VIEW on https links).

Android's documentation says QUERY_ALL_PACKAGES is for "the rare cases where the <queries> element doesn't provide adequate package visibility", and that on Google Play its use "is subject to approval".

How do I remove it?

Add it to your own manifest with tools:node="remove". The manifest merge then leaves it out, whichever library declared it. In Flutter and React Native the file is android/app/src/main/AndroidManifest.xml.

<manifest xmlns:android="http://schemas.android.com/apk/res/android"
    xmlns:tools="http://schemas.android.com/tools">
    <uses-permission android:name="android.permission.QUERY_ALL_PACKAGES" tools:node="remove" />
</manifest>

In Expo, block it in your app config instead:

{
  "expo": {
    "android": {
      "blockedPermissions": [
        "android.permission.QUERY_ALL_PACKAGES"
      ]
    }
  }
}

Then test the feature the library provides: if it needed the permission, that feature may stop working.

How do I declare it if I keep it?

If your app is one of the kinds above, complete the Permissions Declaration Form in Play Console for QUERY_ALL_PACKAGES, and update it if your use changes. Google says apps that do not meet the policy or do not submit the form may be removed from Google Play.

Common questions

Do I need QUERY_ALL_PACKAGES to open another app?
No. A <queries> element naming the app or the intent you want to launch makes it visible to yours, with no declaration.
A library added QUERY_ALL_PACKAGES. Can I remove it?
Yes: declare it in your manifest with tools:node="remove", or list it under android.blockedPermissions in Expo. Then test the feature that library provides, and add the <queries> entries it actually needs.
Does this apply to apps targeting below Android 11?
Package visibility filtering applies to apps targeting API level 30 or higher. Google Play now requires new apps and updates to target a much newer level, so in practice it applies to every app you submit.

Sources

May we use analytics and ad measurement? Analytics (Vercel, and Ahrefs on our public pages) count page views without cookies. Ad measurement lets Google's tag on our public pages see which visits came from our Google ads, using a Google cookie. The site works the same either way. Cookie Policy · How Google uses data ·