A hardened, de-Googled Android for Google Pixel phones. Not a "ROM for geeks" — it's the best-documented, most secure mobile OS for people who want real control over their privacy.
GrapheneOS is an open-source OS based on Android (AOSP), with strong security hardening and no Google services in the system. It runs only on Pixel phones — for a specific reason (see §7). It keeps Android fully usable, but takes away Google's role as the "owner" of your phone.
Sandboxed Google Play — if you need apps that require Google services, you install them as a regular app with no system privileges, confined in a sandbox. You get compatibility, but Google gets no privileged access to the system. You can also skip Play entirely.
User profiles (each separately encrypted): e.g. everyday, banking, work, anonymous (Tor-only, no Google). One profile's apps and data are invisible to the others. Plus a guest profile and app-to-app isolation. Practical compartmentalization of your life's spheres.
It's not a whim. Pixels have the Titan M2 secure element, full verified boot with the ability to re-lock the bootloader on your own key (other phones don't allow this), hardware attestation and the longest support (7 years of updates). That's why GrapheneOS supports Pixels only — it's the only place the full security model is achievable.
| Control | Trust in | |
|---|---|---|
| Stock Android | low | Google + manufacturer |
| iPhone | low (closed), but secure | Apple |
| GrapheneOS | high | small surface — you + an open-source project |
BASIC
Install via the official web installer on a Pixel, re-lock the bootloader. Sandboxed Play only where needed. Deny the Network permission to apps you don't trust. Result: a de-Googled, updated phone right away.
ADVANCED
Multi-profile (banking / everyday / work), Storage & Contact Scopes, always-on VPN with kill-switch, a private communication stack (Signal / Molly / SimpleX). Separate accounts and apps per profile.
EXPERT
A Tor-only, no-Google profile, Duress PIN, short auto-reboot, own-key attestation (Auditor), a minimal app set, separate identities per profile, no mixing of spheres. The phone as an OPSEC tool.
We'll prepare a Pixel with GrapheneOS in a multi-profile architecture matched to your threat model: re-lock, Sandboxed Play where needed, Scopes, always-on VPN, private messaging, Duress. You get a ready, hardened phone.
Related articles
PivLab informational material. The right configuration depends on your threat model — if in doubt, get it reviewed individually.