The thing about Google App Signing is that the keystore certificate is stored on google servers and you do not have direct access to them.
For example, every time you need to update the application in the play store, the application must be signed with the same certificate, so if you select it, you will not be able to refuse, since the certificate remains with Google and there is no option to download at this time
source
share