Texas’s App Store Accountability Act, Senate Bill 2420 (SB 2420), which took effect on January 1, 2026, requires app store owners to verify users’ age categories and generally obtain parental consent before minors download or purchase applications or make in-app purchases. Developers that make applications available through an app store have separate duties to assign age ratings, notify stores before certain changes to an application’s terms of service or privacy policy, verify age and consent information received from stores, and limit and delete personal data received from stores. The US Court of Appeals for the Fifth Circuit stayed two preliminary injunctions that had blocked enforcement, and the US Supreme Court denied emergency applications seeking to vacate that stay. The act therefore remains enforceable while the appeals continue.
Does the Law Pertain to Websites?
The act defines an “app store” as a publicly available internet website, software application, or other electronic service that “distributes software applications” from an application’s owner or developer to a mobile device user. It does not define “distributes” or “software application.”
Many websites have widgets, such as a mortgage calculator, currency converter, fitness tracker, or language translator. Even more websites have webpages that incorporate or otherwise operate based on specific software, such as e-commerce webpages, career webpages, and privacy setting webpages. Do website owners fall within the scope of the act simply because cellphone owners can use these widgets and webpages? The central issue is what constitutes the distribution of software to a mobile device user.
The act’s structure provides notable guidance, repeatedly referring to app store accounts, individual downloads and purchases, applications available for “download and purchase,” and information exchanged between app stores and developers. Those provisions suggest that distribution involves a user obtaining a distinct mobile application. They do not suggest that every website offering software, games, or interactive features is an app store. In deciding whether to stay preliminary injunctions entered in First Amendment challenges to the act, the Fifth Circuit explained that app store users can browse a catalog, obtain information, and “download or purchase” an application. The court did not interpret “distributes” or decide whether any particular website is covered.
In arguments to the US Supreme Court in support of the act, Texas compared the act with a separate Texas law governing material published on websites and described the act as applying to “software applications on mobile devices, not Internet websites.” However, because the act expressly includes websites, that statement does not mean that all websites are exempt. The more natural interpretation is that a website is not covered merely because users visit it but may be covered when it serves as the channel through which users obtain software applications.
How users obtain the software application will likely matter. A game or software service used only through a browser has a stronger argument for being considered outside of the scope of the act. The same is likely true of a website that redirects users to Apple’s App Store, Google Play, or another app marketplace because the outside marketplace enables the download. By contrast, a website that hosts a mobile installation file and provides it directly to users presents a greater risk of being subject to the act. Google’s Android guidance describes hosting an APK file on a website and providing a download link as “distributing through a website.” A website offering several mobile applications for direct download presents an even stronger case of being subject to the act.
In summary, the act does not clearly resolve whether it applies to web-based software applications or to a website that offers only its own software application, and no court has decided those questions.
What Businesses Should Do Now
Companies offering software, games, or mobile applications to Texas users should identify how users obtain their products and whether the companies may be acting as an app store owner, a developer, or both. The review should distinguish browser access from outside marketplace links, direct downloads, and installable web products. Companies that may fall within the act should also review their age verification, parental consent, age rating, notice, and data handling procedures. Outside age assurance and parental consent vendors may assist, but retaining a vendor does not itself establish compliance.
The pending appeals may clarify the act’s reach. Until then, companies distributing software through their own websites should not assume that avoiding a traditional app store places them outside of the act.
If you have any questions regarding the content of this alert, please contact Renato Smith-Bornfreedom, Data Security & Technology Practice Area co-chair, at rsmithbornfreedom@barclaydamon.com, or another member of the Data Security & Technology Practice Area.
Patrick Crowley, summer associate (not admitted to the practice of law), contributed significantly to the preparation of this alert.