If functionality exists in the client app, there's nothing to be done to stop someone from bypassing checks.
Looking into it further this looks like it's an API between the backend of a service and Google though. That would be difficult to defeat, but you could probably spoof the identity of the requesting device with enough effort
I am a bit out of the loop in terms of RDBMS history, what do you mean by MySQL refugees?