Harbor Dock
June 1, 2026

You self-hosted your files. Can you still install the app that opens them?

Self-hosting lets you own the server. It does not, on its own, let you own the client. As installing apps outside the Play Store gets harder, the way you reach your own files matters more than which box they sit on.

A household spends a weekend standing up Jellyfin, or Immich, or a plain file server on a small box in the closet. The reward, the thing that makes the weekend worth it, is the moment a phone in the kitchen opens the app and there are the photos, the movies, the documents, all of it coming off a drive they own. The server is theirs now. This year a quieter question has started showing up in the self-hosted forums: can they still install the app that opens it?

What is actually changing

Google has signaled that Android is moving toward requiring a verified developer identity behind the apps people install, including apps that come from outside the Play Store. The exact timeline, the regions involved, and the precise mechanics are still moving, and anyone who tells you they know the final shape is guessing. The direction is the part worth watching. For most of Android's life, sideloading, installing an app the system did not hand you from the official store, was something you could simply do. The trend is toward that act needing someone else's sign-off.

This is a different lever from the reCAPTCHA wall the de-Googled crowd has been trading screenshots about. That one is about the web declining to believe a phone is human. This one is about the phone itself becoming a place where installing the software you chose is no longer entirely your call.

Why this lands on self-hosting in particular

Self-hosting is two halves that usually get talked about as one. The first half is the server: the box, the drive, the service running on it. That half you can genuinely own. Nobody can reach into your closet and revoke the file server. The second half is the client: the app on the phone that talks to the server. That half lives on a device whose rules about what may be installed are set by the platform, not by you.

Plenty of self-hosted services lean on companion mobile apps, and a fair number are distributed outside the Play Store, or through alternative stores like F-Droid, precisely because their authors did not want to live inside Google's distribution. When installing from outside gets harder, those are the apps in the blast radius. You can own the Immich server outright and still find that getting the Immich app onto a family member's phone has turned into a small project.

This is the non-obvious part. Self-hosting solves ownership of the server. It does not, on its own, solve ownership of the client. The two are unrelated problems, and the second one has been getting quietly worse while everyone celebrated winning the first.

The part that survives the squeeze

There is one way to reach your own files that does not route through any app store: the browser, and the boring protocols underneath it. A file server you can open in a web browser needs no app to install and no developer to be verified. The same goes for standard file protocols, WebDAV, SMB, plain HTTPS, which a phone or laptop can speak without a bespoke application from a store.

This is why keeping your files on something reachable by ordinary means matters more, not less, as the app layer tightens. If reaching your photos depends on one specific vendor app from one specific store, you have a single point of failure with someone else's hand on the switch. If reaching them is just opening a page or mounting a share, the app-store question never comes up.

It is the lane Harbor Dock sits in. The dock is a small ARM board with a USB drive that you browse to over a Tailscale network, and there is nothing to install but Tailscale itself. Your files are reachable the way a website is reachable, not the way a locked-down app is. That does not make the broader sideloading story disappear. It means a meaningful chunk of what you care about, the photos and documents and backups, does not hinge on whether the next Android release lets you install what you want.

The honest tradeoffs

A browser is not as pleasant as a good native app. Native apps do background photo backup, offline caching, and push notifications that a web page handles poorly or not at all. If those features are the whole reason you self-hosted, a browser-first setup will feel like a step down, and that is a fair thing to weigh.

Tailscale is itself an app you install, and today it comes from the Play Store, which puts it on the verified-developer side of the line and out of the immediate squeeze. That is true for now. It is worth being honest that it is one more dependency, not zero.

And none of this is fixed by de-Googling the phone. That is a separate and harder decision, and it tends to trade the install problem for the reCAPTCHA one. Google has not banned sideloading, and requiring verification is not the same as prohibiting it. The point is not panic. The point is that the direction is set, and the cheap insurance is to avoid building access to your own files on top of the part that is closing.

The server side of ownership is more or less solved for anyone willing to spend a weekend on it. The client side is a second front, and it is the one tightening fastest. Keeping your files reachable by ordinary means, a browser, a mounted share, a private network nobody else is on, is how you keep that second front from mattering as much. The box in the closet is yours. The cheapest way to keep it that way is to make sure no app store ever sits between you and it.

Want a private cloud that does not phone home?

Reserve a Harbor Dock. No charge today, no spam, no surprises.

Reserve now