Pollis for Android
A direct download for people who do not use Google Play. Same app, signed with our own key.
Android 7.0 or later. Loading the current version…
This is the right file for almost every phone (arm64-v8a). Older 32-bit phones:
armeabi-v7a.
Chromebooks and emulators:
x86_64.
If Android says the app is not compatible with your device, you have the wrong one.
Check it before you install it
Two values identify what we published. The signing certificate matters most: it is the key Android checks every future update against, and it is the same for every release.
Signing certificate SHA-256
a991cf8d0d3c4fd9280b8537f7089f621ec6cc09742a45ff568d06141cf524eb
Certificate CN=Pollis Android Sideload, OU=Pollis, O=Pollis, RSA-4096. Also committed in the
source repository as
mobile/store/android-sideload-cert.sha256,
and the release pipeline refuses to publish an APK signed by anything else.
Check it with apksigner, which ships in the Android SDK build-tools
($ANDROID_HOME/build-tools/<version>/apksigner):
apksigner verify --print-certs pollis-vX.Y.Z-android-arm64-v8a.apk
The line Signer #1 certificate SHA-256 digest: must show exactly the value above. If it
shows anything else, or the command reports the signature does not verify, do not install the file.
File SHA-256
Loading…
sha256sum pollis-vX.Y.Z-android-arm64-v8a.apk # macOS: shasum -a 256
This hash is served by the same CDN as the file, so it catches a corrupted download, not a tampered
one. The certificate check above is the one that tells you who made it. Every release, its hash and
its certificate fingerprint are also attached to its
GitHub release.
Android will only install an update over Pollis if it is signed by the same certificate as the copy you already have. Once a correctly signed Pollis is on your phone, a substitute signed by anyone else is refused as an update. So checking the certificate once, before the first install, covers every update after it.
Installing
- Download the APK on your phone, or copy it over from your computer.
- Open it. Android asks you to allow the app you opened it with (your browser or file manager) to install apps. Allow it for this install; you can turn the permission off again afterwards.
- Sign in, or enroll this phone as a new device from one you already use.
Skipping the Play Store does not skip Google's push service. Notifications while Pollis is closed are relayed through Expo's push service to Firebase Cloud Messaging, so they need Google Play services on the phone. The notification is a fixed "New message" with no sender and no content. Without Play services, messages still arrive, but only when you open the app.
Google Play and this APK do not mix
Google Play re-signs every app it delivers with a key Google holds. This APK is signed with ours. Android treats the two as different publishers of the same app, so neither can update the other: installing this APK over a Play install (or the reverse) fails with a signature conflict.
To switch from one to the other:
- Uninstall the copy you have, then install the other one.
- Your message history on that phone does not carry over. The new install is a new device, and a new device starts empty: there is no key backup and no server-side copy of your history, by design. Messages are still on your other devices, and everything sent from now on arrives normally.
- The uninstalled copy stays listed among your devices. Remove it from another device under Security → Devices (see lost or stolen device for what that does).
Updates are manual
This build does not update itself and does not check for updates. To update, come back to this page, download the new APK, check it the same way, and open it. It installs over the existing copy and keeps your data, because it is signed with the same certificate.
New versions are listed on our
GitHub releases page as mobile-v…, and the current one
is always at
releases/android/latest.json.