Trust
Is it safe? Check it yourself.
You install NewTube from outside Google Play, so you should be able to verify what you install. Each claim on this page points to something you can check.
Who makes it
NewTube is one person's project: @aleixrodriala maintains it and uses it every day. It is built on SmartTube by @yuliskov and its contributors. It is independent and unofficial: not affiliated with Google, YouTube or SmartTube's developer.
Made with AI. Most of NewTube's own code (the phone interface, the player and the network work) was written with AI coding assistants, Claude and Codex, and the commit trailers say so. The maintainer directs and reviews that work. Each release record lists what was checked on a real phone, what was checked only with automated tests, and what is still open.
How it's built and signed
Since 1.10.3, the release workflow builds and signs every APK on GitHub's servers from the tagged source. It deletes the key from the build machine afterwards, refuses any APK signed with another certificate, and attaches the files to a draft release that the maintainer publishes by hand. Up to 1.10.2, the APKs were built on the maintainer's computer. The builds aren't reproducible yet.
Every APK is signed with the same key (CN=NewTube, OU=NewTube, O=aleixrodriala). Its certificate's SHA-256:
2e:f9:9d:76:ed:fa:d9:88:ad:17:cd:ee:8b:a1:8c:63:4e:23:0f:e1:e3:cb:1f:dc:6c:db:02:49:37:0a:36:c9
- The signature
apksigner verify --print-certs <file>.apk- Where it was built
gh attestation verify <file>.apk -R aleixrodriala/newtube- The file itself
- Compare its SHA-256 with
SHA256SUMSon the release page.
VirusTotal
When a release is published, a workflow uploads each APK to VirusTotal and adds the results, with a link to each report, to the release notes. For 1.14.0 (1 October 2026), none of the 64 to 67 engines flagged any of the four APKs.
A clean scan means no antivirus engine recognised the file as malware. It is not a security audit.
What the app sends, and where
| Service | What it gets | When |
|---|---|---|
| YouTube and Google | Your requests for videos, search and your account | Always; your account only if you sign in |
| SponsorBlock | The ID of the video you open | On by default; you can switch it off |
| DeArrow | Video IDs, to fetch clearer titles and thumbnails | Only if you switch it on |
| Return YouTube Dislike | The ID of the video you open | Only if you switch on dislike counts |
| GitHub | A check for a newer version | Update checks |
Nothing goes to the developer. The app has no analytics, no crash reporting and no ad SDKs: its dependencies include none, and the APK's code contains no Firebase, Crashlytics, Sentry, ACRA, Google Play Services or ad-network classes. Details are in the privacy policy.
If you sign in, the login token is stored on your phone and never sent to the developer; backups you turn on (Android's own, or the app's Backup & restore) can include it. You can revoke it at any time at myaccount.google.com/security, under Your connections to third-party apps & services.
How the updater checks an update
It reads the update manifest from NewTube's GitHub releases over HTTPS and downloads the APK from the same release. Before offering it, it checks that the file is a complete Android package for NewTube at the announced version. Then it hands the file to Android's own installer, which refuses an update that isn't signed with the same key as the installed app.
The source
NewTube's code is public under the MIT license, the same as SmartTube: the app and its forks of SmartTube's MediaServiceCore and SharedModules. The libraries it uses keep their own licenses, listed in THIRD_PARTY_NOTICES.md. Every release is tagged, so you can read the exact source it was built from.
How fast, measured
Medians from a Pixel 9, timed on 25 and 26 September 2026 with release builds of the code that became 1.10.1, 2 to 8 runs per cell: small samples, one phone, one carrier, and the mobile-data runs were on different days. Later versions haven't been re-timed this way, and 1.12.0 changed how the app opens (Home shows loading placeholders first). The method and the full table are in STATUS.md.
| Action | Wi-Fi | Mobile data |
|---|---|---|
| Open the app → first screen | 0.24 s | 0.24 s |
| Open the app → Home fully painted | 1.35 s | 1.56 s |
| Tap a related video → first frame | 0.50 s | 0.53 s |
| Tap a related video → picture visible | 0.66 s | 0.73 s |
| Reopen a half-watched video → picture | 0.37 s | – |
| Tap a shared link → first frame | 0.66 s | 0.84 s |