F-Droid
Germany · f-droid.org · 17 vendors
F-Droid is a free and open-source app store and software repository for Android devices. It provides a curated collection of applications that adhere to open-source principles, focusing on user privacy and freedom. Operating as a non-profit volunteer project, it offers an alternative to traditional app stores by hosting only free and open-source software.
Resilience scores
- Digital Sovereignty: 35
- Digital Resilience: 5
- Financial Resilience: 5
Technology vendors
- Civilized Discourse Construction Kit, Inc. — Technology — United States
- Mozilla Open Source Support — Technology — United States
- Stripe, Inc. — Financial Services — United States
- and 17 more
Services catalogue
1 service in catalogue across 1 category; runs on 17 sub-vendors.
- Application distribution
Insights
Last updated 2026-07-29 · revision 6
17 direct vendors, 104 subvendors
Direct vendors by controlling owner country (sample)
- Czech Republic: 1
- Germany: 3
- United States: 10
Subvendors by controlling owner country (sample)
- Denmark: 4
- Japan: 3
- France: 2
Migration Readiness: 6/10
Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.
F-Droid exhibits moderate migration readiness. A strong technical foundation is a key advantage, with a modern, heavily FOSS-based tech stack (Debian, Python, Git, Ansible, QEMU/KVM) that is highly portable and reduces proprietary software lock-in. The use of virtualization (Vagrant, QEMU/KVM) and automation (Ansible, GitLab CI/CD) further enhances its technical flexibility. The 'Total Vendors: 0' (if interpreted as minimal formal contractual vendors) also reduces contractual lock-in, which is beneficial for migration. However, significant challenges arise from the regulatory environment and data residency requirements. GDPR and NIS2 compliance are 'Assessment Required' with high/medium risk, necessitating meticulous planning for data processing, security, and cross-border transfers during any migration. Data residency requirements for EU residents' personal data will restrict choices for migration targets, particularly cloud providers. Financial stability is an unknown, as no revenue or growth data is provided, making the funding of a potentially large-scale migration uncertain for a non-profit organization. While the core tech stack is portable, migrating 37 distinct services, even if FOSS, still represents a considerable operational effort.
Compliance
4 in-scope frameworks identified; showing 3.
GDPR (source) — Assessment Required
F-Droid is a volunteer-run, open-source, non-commercial project legally represented by the Commons Conservancy (a Dutch foundation), with stated HQ in Germany. It explicitly markets itself as privacy-friendly and does not require user accounts or track installations. This privacy-by-design approach significantly reduces GDPR risk. However, the project does operate a global-facing website (f-droid.org), a community forum, mailing lists, and accepts donations — all of which may involve some processing of personal data (e.g., IP addresses in server logs, contributor names, donor information via OpenCollective/Liberapay). No formal GDPR compliance documentation, privacy policy, or DPO appointment has been publicly disclosed on the website, which elevates risk. The risk is Medium rather than High because the organization is small, non-commercial, processes minimal personal data by design, and enforcement against small volunteer-run FOSS projects is historically rare. However, the absence of a visible privacy policy or GDPR compliance statement is a notable gap.
Evidence: https://f-droid.org/en/about/, https://f-droid.org/en/docs/Government_Requests, https://commonsconservancy.org/programmes/#F-Droid, https://dracc.commonsconservancy.org/0039/, https://f-droid.org
EU Digital Services Act — Assessment Required
The DSA (Regulation (EU) 2022/2065) applies to intermediary services including online platforms. F-Droid operates an app repository that could be classified as an online platform. However, DSA obligations scale with size: micro and small enterprises (fewer than 50 employees and less than €10M annual turnover) are exempt from most obligations. F-Droid almost certainly qualifies as a micro-enterprise given its volunteer-run, donation-funded nature. Risk is Low because size-based exemptions likely apply, and F-Droid's privacy-by-design approach already aligns with DSA's user protection goals.
Evidence: https://f-droid.org/en/docs/Take-Down_Requests, https://f-droid.org/en/docs/Inclusion_Policy, https://f-droid.org/en/about/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2065
Cyber Resilience Act (source) — Assessment Required
The EU Cyber Resilience Act (Regulation (EU) 2024/2847), which entered into force in December 2024 with phased application through 2027, introduces cybersecurity requirements for products with digital elements placed on the EU market. F-Droid distributes Android apps (products with digital elements) to EU users. The CRA includes specific provisions for open-source software stewards — entities that provide non-commercial open-source software — which may apply to F-Droid. The risk is Medium because: (1) the CRA's open-source steward provisions are specifically designed for organizations like F-Droid, (2) the obligations are lighter than for commercial manufacturers but still include security policies and vulnerability disclosure requirements, (3) the CRA is newly in force and compliance timelines are still being established, and (4) F-Droid's role as a trusted app distributor makes CRA compliance particularly relevant.
Evidence: https://f-droid.org/en/about/, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202402847, https://commonsconservancy.org/programmes/#F-Droid
Financials
Three-year financials
- 2025: revenue EUR 15.16K, equity EUR 24.10K
- 2024:
- 2023:
Financial Resilience Score: 5/10
F-Droid is not a company but a volunteer-run FOSS project legally represented by the Commons Conservancy Programme (a Dutch stichting). It has no revenue, no EBIT, no equity, and no audited accounts in the corporate sense. Its financial activity is limited to donation flows through Open Collective (EUR and USD), Liberapay, and GitHub Sponsors. The Euro collective shows a balance of €24,098.42, total raised of €38,182.99 all-time, and an estimated annual budget of €15,160.34. In 2025 it received a one-time $50,000 FLOSS/Fund grant, materially boosting inflows. Resilience is underpinned by full financial transparency, a highly diversified donor base (1,203+ contributors on the € collective), near-zero fixed costs (all volunteer, no salaried staff), and legal continuity via the Commons Conservancy umbrella. Institutional validation from the FLOSS/Fund grant and recurring foundation donors (Digitalcourage e.V., sysmocom GmbH, Disroot.org) strengthens sustainability. However, the scale of funding (~€15k/year on the Euro side) is very small relative to the technical and security-review workload for thousands of Android apps, making the project heavily dependent on unpaid volunteer labor. The most acute risk is not financial but regulatory/platform: Google's 2025-2026 Android Developer Verification and sideloading restrictions pose an existential threat to F-Droid's distribution model.
Key strengths: Fully transparent finances via Open Collective public ledger, Highly diversified donor base with 1,203+ contributors on the Euro collective, Zero salaried permanent staff; variable, low-cost structure, Legal umbrella via Commons Conservancy (NL) ensures IP and governance continuity, One-time $50,000 FLOSS/Fund grant received in 2025, Recurring institutional donors (Digitalcourage e.V., sysmocom GmbH, Disroot.org), 15-year track record as the default FOSS alternative Android app store
Risk factors: Google's Android Developer Verification / sideloading restrictions pose existential platform risk, Very small annual budget (~€15k EUR side) vs. large technical workload, Heavy dependence on unpaid volunteer labor, Key-person risk: only three named admins on the Euro collective, FLOSS/Fund $50k grant is one-off; long-term sustainability relies on many small donors, No audited financials and no publicly stated reserves policy, Legacy F-Droid Limited (UK) dormant but still on Companies House
Revenue by geography
- Eurozone (esp. Germany): 55%
- United States: 25%
- Rest of world: 10%
- India (FLOSS/Fund): 10%
Revenue by product/service
- One-time individual donations: 40%
- Grants (FLOSS/Fund): 25%
- Recurring individual donations: 25%
- Institutional/organizational sponsorships: 10%
Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.