First day with GrapheneOS: set it up right
Why this matters: Privacy isn't about hiding
What you’ll be able to do afterward
- A verified GrapheneOS install, set up in the order that avoids re-doing things.
- Google exactly where you want it: absent, or sandboxed with no special powers.
- The hardening features that make GrapheneOS worth it actually turned on.
Do the previous playbook first if you haven’t — this one assumes the answer was yes and there’s a supported Pixel on the desk.
The plays
-
Install with the official web installer
Where: the install guide at grapheneos.org, from a computer with a good cable — follow it exactly, including the final "lock the bootloader" step
What this just did: put a verified operating system on the phone with verified boot re-enabled. The web installer checks what it flashes; locking the bootloader at the end is what makes the verification mean something.
-
Set a strong unlock
Settings → Security → Screen lock — a 6+ digit PIN (or passphrase), then fingerprint on top
What this just did: the passcode play, same as any phone — except here it also protects the encryption GrapheneOS leans on harder than stock Android does.
-
Decide about sandboxed Google Play
Where: the pre-installed Apps app → Google Play services — install only if your must-have apps need it
What this just did: made Google an unprivileged guest, if you invited it at all. Sandboxed Play runs as a normal app with no special system access — most Play-dependent apps work, and Google sees what any ordinary app sees, which is dramatically less than on stock.
-
Get your apps from the right doors
Where: the GrapheneOS Apps app first; then your chosen store (sandboxed Play, or an alternative like Accrescent) for the rest
What this just did: established the trust order — system apps from GrapheneOS itself, everything else from a store you chose deliberately rather than the one that came with the landlord.
-
Use scopes instead of broad access
When: an app demands all your photos or contacts — grant Storage Scopes / Contact Scopes in the permission prompt instead
What this just did: taught you GrapheneOS's best trick. Scopes let an app believe it has full access while it actually sees only the folders or contacts you picked — the app works, the dragnet doesn't.
-
Turn on auto-reboot and USB protection
Settings → Security → Auto reboot (pick an interval like 18 hours); and USB-C port → "Charging only when locked"
What this just did: made a seized or stolen phone go cold on its own. Auto-reboot returns the phone to its strongest encryption state; the USB setting refuses data handshakes while locked — together they're most of what "advanced forensics" runs into.
-
Consider a second profile for the risky stuff
Settings → System → Users → Add user — e.g. one profile for daily life, one for apps you don't fully trust
What this just did: gave untrusted apps a separate, disposable apartment. Profiles are fully isolated — what installs and runs in one can't see the other. Optional on day one, worth knowing exists.
-
Confirm updates are automatic
Settings → System → System update — leave automatic updates on
What this just did: kept the whole point intact. GrapheneOS ships security updates fast and installs them in the background; your job is only to not turn that off.
You’re now covered against…
- The stock-Android default — Google is sandboxed or absent, chosen per profile, with no privileged access either way.
- Data-hungry apps — scopes feed them a partial view they can’t tell from the real thing.
- Physical seizure scenarios — verified boot, auto-reboot, and a locked USB port raise the cost of every offline attack.
Forty-five minutes for the phone; the habits from the earlier playbooks still apply on top. Welcome to the ceiling.
Progress is saved only on this device. It never leaves your phone.