Coming Soon
GrapheneOS playbook · Fundamentals

First day with GrapheneOS: set it up right

Why this matters: Privacy isn't about hiding

What you’ll be able to do afterward

Do the previous playbook first if you haven’t — this one assumes the answer was yes and there’s a supported Pixel on the desk.

The plays

  1. Install with the official web installer Where: the install guide at grapheneos.org, from a computer with a good cable — follow it exactly, including the final "lock the bootloader" step

    What this just did: put a verified operating system on the phone with verified boot re-enabled. The web installer checks what it flashes; locking the bootloader at the end is what makes the verification mean something.

  2. Set a strong unlock Settings → Security → Screen lock — a 6+ digit PIN (or passphrase), then fingerprint on top

    What this just did: the passcode play, same as any phone — except here it also protects the encryption GrapheneOS leans on harder than stock Android does.

  3. Decide about sandboxed Google Play Where: the pre-installed Apps app → Google Play services — install only if your must-have apps need it

    What this just did: made Google an unprivileged guest, if you invited it at all. Sandboxed Play runs as a normal app with no special system access — most Play-dependent apps work, and Google sees what any ordinary app sees, which is dramatically less than on stock.

  4. Get your apps from the right doors Where: the GrapheneOS Apps app first; then your chosen store (sandboxed Play, or an alternative like Accrescent) for the rest

    What this just did: established the trust order — system apps from GrapheneOS itself, everything else from a store you chose deliberately rather than the one that came with the landlord.

  5. Use scopes instead of broad access When: an app demands all your photos or contacts — grant Storage Scopes / Contact Scopes in the permission prompt instead

    What this just did: taught you GrapheneOS's best trick. Scopes let an app believe it has full access while it actually sees only the folders or contacts you picked — the app works, the dragnet doesn't.

  6. Turn on auto-reboot and USB protection Settings → Security → Auto reboot (pick an interval like 18 hours); and USB-C port → "Charging only when locked"

    What this just did: made a seized or stolen phone go cold on its own. Auto-reboot returns the phone to its strongest encryption state; the USB setting refuses data handshakes while locked — together they're most of what "advanced forensics" runs into.

  7. Consider a second profile for the risky stuff Settings → System → Users → Add user — e.g. one profile for daily life, one for apps you don't fully trust

    What this just did: gave untrusted apps a separate, disposable apartment. Profiles are fully isolated — what installs and runs in one can't see the other. Optional on day one, worth knowing exists.

  8. Confirm updates are automatic Settings → System → System update — leave automatic updates on

    What this just did: kept the whole point intact. GrapheneOS ships security updates fast and installs them in the background; your job is only to not turn that off.

You’re now covered against…

Forty-five minutes for the phone; the habits from the earlier playbooks still apply on top. Welcome to the ceiling.

Progress is saved only on this device. It never leaves your phone.