Android FLAG_SECURE: what it blocks and what it can't stop
FLAG_SECURE keeps app screens out of screenshots and recordings, but not away from a second phone, rooted devices, emulators or audio capture.
On this page 8 sections
FLAG_SECURE is an Android setting that lets an app ask the system to keep its screens out of screenshots and screen recordings, which then show black. It's one of the stronger protections a course app can have, because Android itself enforces it, but it has hard limits: it can't see a second phone filming the screen, it can be undermined on rooted phones, emulators and modified copies of an app, and it covers the picture, not the sound. Those gaps are where Android leaks happen, and they're what to test and ask your app developer about.
What FLAG_SECURE does
Android's reference describes FLAG_SECURE as treating a window's content as secure, "preventing it from appearing in screenshots or from being viewed on non-secure displays". See the FLAG_SECURE reference. For a student, that looks like this:
- a screenshot comes out black, or the phone says the app doesn't allow screenshots;
- a screen recording or screen share shows black where the app should be;
- the app's preview in the recent-apps screen is blank;
- mirroring to a screen that Android doesn't treat as secure shows black.
What makes it strong is who enforces it: the operating system, not the app, decides what goes into a recording. That is far more than any website can do, as our guide to screen recording on websites explains. But strong isn't the same as complete.
What FLAG_SECURE can't stop
| Leak route | Does FLAG_SECURE stop it? | Why |
|---|---|---|
| A second phone filming the screen | No | The picture leaves the screen as light; no app setting can reach another device's camera |
| Rooted phones | Not reliably | Rooting gives other software control over how the system treats apps |
| Emulators on a computer | No | The computer can record the emulator's window like any other window |
| Modified copies of the app | Not reliably | A repackaged app can have its protections stripped out |
| Audio | No | It covers the picture only; Android lets other apps capture an app's sound by default unless the app opts out |
| Screens that were never protected | No | Protection is applied screen by screen, so one missed viewer or pop-up leaks |
| A phone's video output to a TV or capture device | Not always | Protected screens can still appear on displays Android treats as secure, so the connection's own safeguards, such as HDCP, matter |
The camera row matters most for coaching content. A lecture needs a readable board and a clear voice, not cinema quality, and a phone on a stand delivers both. Our guide to camcording covers that leak route, and our explainer on HDCP and HDMI capture covers video outputs.
Stripping protection from an app to copy lectures can also be an offence. Under Section 65A of the Copyright Act, 1957, circumventing an effective technological measure that protects copyright, with the intention of infringing it, is punishable with up to two years in prison and a fine.
Why newer Android alerts don't close the gap
Recent Android versions add signals on top of blocking. Android 14 can tell an app that a screenshot was taken, and Android 15 can tell an app when it is being recorded. Useful, but limited:
- The screenshot alert comes afterwards. Android's screenshot detection guide also notes that it covers screenshots taken with the phone's button combination, not every method.
- Older phones get nothing. Many students keep phones for years, so a large share of your batch may be on versions without these alerts.
- Alerts can't see cameras. A second phone triggers nothing.
- Alerts live inside the app. A modified copy of the app can ignore them.
iPhones work differently again: they offer detection but no blocking, as our guide to iOS screen recording detection explains.
Where course apps commonly leave gaps
- Screens other than the player: PDF viewers, notes, test papers, solutions and lists of lecture thumbnails.
- Pop-ups: dialogs, bottom sheets and menus that show content but were left unprotected.
- Web pages inside the app, such as a notes page loaded from your website.
- Old app versions still installed on students' phones, from before protection was added.
- Cross-platform apps. Apps built with tools such as Flutter or React Native can use the same Android setting, but only if their Android side applies it. Ask.
- Rooted phones and emulators that the app doesn't notice. These checks belong to a wider approach known as root and emulator detection, part of runtime application self-protection (RASP).
How to check an app's claims
| Try this | What you should see |
|---|---|
| A screenshot on the player, notes, tests and downloads screens | Blocked or black on every one |
| The phone's built-in screen recorder during a lecture | Black where the app is, and check whether the audio was recorded |
| Every pop-up and menu, opened while recording | Black, not the content |
| The recent-apps screen | A blank preview |
| Mirroring the phone to a TV | Black, or a clear message |
| An older Android phone and a newer one, from different brands | The same results |
Questions to ask your app developer or vendor
- Which screens are protected: player, notes, tests, downloads and pop-ups?
- What happens to the audio during a screen recording?
- On Android 14 and 15, what happens when a student takes a screenshot or starts recording?
- What happens on rooted phones and emulators, and how is a modified copy of the app handled?
- Are students forced to update when an old app version lacks protection?
- Which Android versions and phone brands have you tested on?
- Since no setting stops a camera, how can a leaked copy be traced back to an account?
Key takeaways
- FLAG_SECURE lets an Android app ask the system to keep its screens out of screenshots, recordings and untrusted displays.
- It can't stop a second phone's camera, and rooted phones, emulators and modified apps can undermine it.
- It covers the picture, not the sound.
- Screenshot and recording alerts on Android 14 and 15 help, but older phones don't get them.
- Leaks often come through screens and pop-ups that were never protected, so test every one.
This is general information, not legal advice. For your situation, speak to a lawyer.
VidSafe, the video protection built by Upclass, combines screen- and camera-recording detection, RASP, dynamic watermarking and VidSafe proprietary encryption. VidSafe adds visible and invisible watermarks that are extremely hard to remove, even after heavy re-encoding, so a leaked copy can be traced back to the account it came from. See Upclass pricing.
Frequently asked questions
How to detect screen recording in Android?
Android 15 and later can tell an app when it is being recorded, and Android 14 added a similar alert for screenshots. Older versions offer no official signal. Detection has limits too: it can't see a second phone filming the screen, and a modified copy of the app can ignore it. That's why detection is a signal to act on, not a guarantee against leaks.
Can apps detect screen recording?
On Android 15 and later, yes: an app can be told when it appears in a recording. iPhone apps can also detect when the screen is being recorded or mirrored. On older Android versions apps generally can't detect recording, though they can ask the system to blank their screens with FLAG_SECURE. No app can detect a separate camera filming the screen.
How do apps know you're screen recording?
They're told by the operating system. Android 15 notifies apps when they appear in a recording, and iOS tells apps when the screen is being recorded, mirrored or sent over AirPlay. Banking and streaming apps often don't need to know at all, because protected screens and protected video record as black anyway, though a camera pointed at the screen still captures everything.