When Google introduced Android 10, it brought a fundamental shift in the way apps interact with the device’s file system. The change—known as Scoped Storage—replaces the long‑standing “global” storage model with a more restrictive, privacy‑focused approach. While the intent is to give users tighter control over their data, the transition has created a learning curve for both end‑users and developers.
Scoped Storage limits an app’s direct access to shared external storage (the "sdcard" directory). Instead of being able to read and write any file on the external volume, an app can only interact with:
/storage/emulated/0/Android/data/<package_name>).MediaStore API.In short, each app operates within a sandboxed “scope” that protects other apps’ files and the user’s personal data.
The primary motivations are:
MediaStore, making it easier for gallery, music, and file‑manager apps to present a consistent view.These goals align with Android’s broader push toward a more secure, privacy‑first ecosystem.
From a developer’s perspective, the model introduces three main pathways for file access:
getExternalFilesDir() or getExternalCacheDir() for files that do not need to be shared with other apps. The system cleans up these files when the app is uninstalled.MediaStore. The API abstracts the underlying file path, so the app never sees the raw file system location.Intent.ACTION_OPEN_DOCUMENT or Intent.ACTION_OPEN_DOCUMENT_TREE. The returned Uri grants the app permission to read/write that specific item.Direct file‑system paths (e.g., /sdcard/Download/file.pdf) are no longer writable unless the app holds the MANAGE_EXTERNAL_STORAGE permission, which is reserved for a narrow set of use cases and requires a special Play Store declaration.
For most users, Scoped Storage is invisible—they continue to save photos, download files, and share media as before. However, a few behavioural changes become noticeable:
MediaStore.Downloads or SAF, which can result in a brief system picker appearing the first time.Overall, the changes aim to protect users from hidden data collection and accidental data loss.
Developers need to adapt their codebases, especially if they previously relied on raw file paths. Key considerations include:
File‑based I/O with ContentResolver streams when working with MediaStore or SAF Uris.MANAGE_EXTERNAL_STORAGE permission responsibly—only request it if the app truly needs unrestricted file access (e.g., file‑manager, backup, or antivirus apps).Identify all places where your code reads or writes files using absolute paths. Convert them as follows:
// Old approach (pre‑Scoped Storage)
File file = new File(Environment.getExternalStorageDirectory(), "MyApp/data.txt");
FileOutputStream fos = new FileOutputStream(file);
// New approach – app‑specific directory
File dir = context.getExternalFilesDir(null); // null = root of app‑specific dir
File file = new File(dir, "data.txt");
FileOutputStream fos = new FileOutputStream(file);
For media files, use MediaStore insertion:
ContentValues values = new ContentValues();
values.put(MediaStore.Images.Media.DISPLAY_NAME, "photo.jpg");
values.put(MediaStore.Images.Media.MIME_TYPE, "image/jpeg");
Uri uri = getContentResolver().insert(MediaStore.Images.Media.EXTERNAL_CONTENT_URI, values);
OutputStream out = getContentResolver().openOutputStream(uri);
// write bitmap data to 'out'
When the user explicitly selects a document, request a Uri via the system picker:
Intent intent = new Intent(Intent.ACTION_OPEN_DOCUMENT);
intent.addCategory(Intent.CATEGORY_OPENABLE);
intent.setType("*/*"); // or "application/pdf" etc.
startActivityForResult(intent, REQUEST_CODE_OPEN_DOCUMENT);
// In onActivityResult:
Uri uri = data.getData();
InputStream in = getContentResolver().openInputStream(uri);
The returned Uri persists across reboots if you take a persistable permission grant:
final int takeFlags = data.getFlags() & (Intent.FLAG_GRANT_READ_URI_PERMISSION | Intent.FLAG_GRANT_WRITE_URI_PERMISSION);
getContentResolver().takePersistableUriPermission(uri, takeFlags);
If your app truly needs unrestricted access (e.g., a full‑featured file manager), add the permission to AndroidManifest.xml:
<uses-permission android:name="android.permission.MANAGE_EXTERNAL_STORAGE" />
Then, guide the user to the special permission screen via an intent:
Intent intent = new Intent(Settings.ACTION_MANAGE_APP_ALL_FILES_ACCESS_PERMISSION);
intent.setData(Uri.parse("package:" + getPackageName()));
startActivity(intent);
Remember that Google Play will review the justification, and misuse can lead to removal.
Android provides a clear UI for permission control:
MANAGE_EXTERNAL_STORAGE, you’ll see a separate toggle under All files access.
These controls let users audit which apps have broad file access and revoke it if needed.
While Scoped Storage is enforced on Android 10+ devices, older versions (Android 9 and below) still allow the legacy model. Developers targeting a wide audience should:
if (Build.VERSION.SDK_INT >= Build.VERSION_CODES.Q) guards to switch between APIs./sdcard/; always use Environment.getExternalStorageDirectory() or the appropriate scoped API.Note that some OEM‑specific file‑manager apps may expose additional shortcuts, but they cannot override the OS‑level restrictions.
Google has signaled that Scoped Storage will become the default for all apps on future Android releases, and the legacy mode will be removed entirely. This means:
Developers who adopt the model early will face fewer retro‑fit headaches and can benefit from the security reputation that comes with privacy‑first design.
Scoped Storage represents a decisive move toward a more secure Android ecosystem. By sandboxing file access, it protects user data while encouraging developers to use modern, content‑based APIs. The transition does require code changes, but the steps outlined above—migrating file I/O, leveraging MediaStore and SAF, and handling permissions responsibly—provide a clear roadmap.
For users, the change is largely transparent, with occasional prompts that give them finer control over which apps can touch their files. As the platform evolves, embracing Scoped Storage now positions both developers and users for a safer, more consistent Android experience.









