A Fake Copy of Your App Is on the Store: Use the Legal Form, Not the Report Button

Three users sued Apple on 27 July over a counterfeit Sparrow Wallet that took $1.8 million. For anyone with a named product, the useful question is which form actually removes a clone, and what it demands before you file.

If a counterfeit version of your app appears on the App Store or Google Play, the consumer "Report a Problem" flow is the wrong door. Both stores route rights-holder complaints through a separate legal channel: Apple's App Store dispute form and Google's legal removal troubleshooter. Both require you to describe the infringement and assert, under penalty of perjury, that you are or represent the authorised rights holder. That single requirement is why the preparation matters more than the report, and why most developers lose a week discovering it.

The reason this is in the news: on Friday 27 July 2026, three plaintiffs filed suit against Apple in the Northern District of California over a fake "Sparrow Wallet" app impersonating the legitimate Sparrow Bitcoin wallet. James Ramirez lost roughly $875,000, Christopher Ellis roughly $840,000, and Jalen Delgado roughly $120,000, for a combined $1.8 million, per TechCrunch's report (opened 27 July 2026). The complaint cites public criticism from Sparrow's creator, Craig Raw, that Apple allowed fake Sparrow apps to persist. Apple's position is that impersonating apps violate its guidelines and it removes them swiftly. Whether Apple is liable is for the court. What is settled today is that the store will not find your clone for you.

Stage 1: build the evidence pack before you open a form

Both forms want a description that a non-technical reviewer can act on in one pass. Assemble this first, in a single folder:

  • The store URL and the numeric app identifier of the clone, plus the exact developer name shown on the listing.
  • Full-page screenshots of the clone's listing: icon, title, subtitle, screenshots, description, developer name. Capture them today, because a scammer's listing metadata changes.
  • The same set for your genuine listing, side by side.
  • Your rights basis. A trademark registration number is the strongest; an application number, a first-use date with evidence, or a copyright registration for the icon artwork are weaker but usable. Write one sentence naming which right the clone infringes and how.
  • Any user reports, with dates. Evidence of actual confusion is what separates "similar app" from "impersonation" in a reviewer's mind.

Stage 2: cite the rule the reviewer enforces

Generic complaints get generic handling. Apple's App Store Review Guidelines (opened 27 July 2026) contain the specific provisions, and quoting the right one changes what the reviewer is being asked to do.

What the clone is doingRule to citeConsequence the rule carries
Presenting itself as your app or serviceApple 4.1(b)Named as a Developer Code of Conduct violation, which "may result in removal from the Apple Developer Program", not just the app
Using your icon, brand or product name in its own icon or nameApple 4.1(c)Prohibited without your approval, which you can state you have not given
Copying your app with cosmetic changes to name or interfaceApple 4.1(a)Copycat listing
Misleading or copycat names and metadata in the bundle or developer nameApple 5.2.1Intellectual property violation; also covers the developer name field
Indistinguishable from an existing widely available appApple 4.3(b)Spam
Implying a relationship with or authorisation by youGoogle Play Impersonation policy"We don't allow apps that mislead users by impersonating someone else (for example, another developer, company, entity) or another app"

The Google language comes from the Play Impersonation policy (opened 27 July 2026), which also prohibits icons and titles suggesting official affiliation, copying the logos or designs of established products, and using titles like "Official" without permission.

Stage 3: file with Apple

The guidelines themselves point rights holders to a web form, and it is not the same form for every Apple service. The dispute forms index (opened 27 July 2026) lists seven, one each for the App Store, iTunes and Apple Music, Apple News, Apple TV, Apple Books, iCloud and Podcasts. Use the App Store one. Apple asks for contact details, an identification and description of the alleged infringement, and a representation under penalty of perjury that you are or represent the authorised rights holder. You then receive a reference number, and the rest of the exchange happens over email with Apple Legal.

Two practical notes. Send from an email address on the domain that matches your published developer contact, because the reviewer's first job is establishing that you are who you say you are. And keep the description factual: the elements copied, the confusion caused, the rule breached. Arguments about how much revenue you have lost belong in a lawsuit, not a takedown request.

Stage 4: file with Google

Google's Play impersonation policy page has no rights-holder form on it; it points to Play Console help. The route that works is Google's legal removal troubleshooter (opened 27 July 2026), which covers Google Play apps among more than thirty services and has separate paths for copyright, trademark, counterfeit, malware and phishing. Choose the branch that matches your strongest right. If the clone is harvesting credentials or seed phrases, file the malware or phishing branch in parallel with the trademark branch: they are handled by different teams on different timescales, and the abuse path is usually faster.

If you also publish on Android, report from your Play Console account rather than an anonymous one. The association between your verified developer identity and the complaint is worth more than the extra field costs you.

Stage 5: warn your own users while you wait

Removal is not instant and you do not control the clock. In the meantime, the cheapest protective step is a pinned notice on the page users actually land on: your own site's download page, stating the exact developer name shown on your genuine listings and linking directly to both store URLs. Financial and wallet products should say plainly that the app will never ask for a recovery phrase. If you have an email list, one short message with the store links is worth more than any store-side action you can take that week, which is the argument we made in the email list is the only audience you own.

The ten minutes a month that prevent all of this

Search both stores for your product name, your name with common suffixes ("pro", "official", "wallet", "app"), and your name with one character transposed. Do it from a logged-out device, because personalised results hide competitors. Set a Google Alert on your product name plus "app store". Claim your name in the store metadata that supports it, and keep your developer display name stable so users have one consistent string to check against. If you are on Android, this fits alongside the registration work required by the verification deadline we covered in register your apps now.

The uncomfortable part of the Sparrow case is that the impersonated product was open-source software with no company behind it and no obvious rights-enforcement budget. A clone of a well-funded app gets removed because the trademark file is ready and the legal team files within hours. A clone of a solo developer's app stays up because nobody has assembled Stage 1. That gap is not about how good the store's review is; it is about who is prepared to file. If you have a named product and no registered mark, the takedown path exists but you will be arguing your rights and the infringement at the same time. Registering first is what makes the form a formality. And if a single store deciding your fate feels like a familiar exposure, run our platform dependency audit next, then read the four levers Apple gives you for the day the rejection is aimed at you instead.

Discussion

Sign in with Google or just a name. No email link, no password to remember.