How it works
GrapheneOS is a hardened fork of the Android Open Source Project that installs on Google Pixel hardware from a browser tab over WebUSB — no vendor account, no proprietary flashing tool. The installer then relocks the bootloader against GrapheneOS's own signing keys, so verified boot stays intact end to end and the phone attests to its own firmware rather than to Google's.
What lands on the device is Android with the Google layer excised: no Play Services, no Play Store, no account prompt at setup. Apps that genuinely need Google can run through sandboxed Google Play, a compatibility layer that installs the official Google binaries as ordinary, unprivileged apps confined to a single profile. They hold no system privileges, they see only what that profile grants, and signing into a Google account stays optional.
The hardening underneath is the actual product: a hardened memory allocator, hardware memory tagging on recent Pixels, up to 32 secondary profiles, Storage and Contact Scopes, and Network and Sensors permissions that stock Android does not offer. LTE-only mode strips the 2G, 3G and 5G baseband code paths. The device auto-reboots into its pre-unlock state after 18 hours idle, and a duress PIN wipes it — eSIMs included — irreversibly.
KYC & privacy
There is no signup, no email, no phone number, no account. The project's own wording is blunt: "there aren't any analytics/telemetry in GrapheneOS", and the only thing its servers learn is the generic device model and OS version needed to serve an update. Connectivity checks, network time, GNSS almanac fetches and attestation key provisioning route through GrapheneOS-operated endpoints instead of Google's. Server-side logs are purged after four to ten days — short, but not zero.
The software is free. The GrapheneOS Foundation, a Canadian federal non-profit incorporated in Toronto in March 2023, funds development through donations in Bitcoin, Monero, Ethereum, Litecoin and Zcash, or through PayPal, Wise and GitHub Sponsors. None of it is required to run the OS.
In March 2026 the project said it will not implement the operating-system age-assurance mandates now arriving. California's AB-1043 takes effect on 1 January 2027 and obliges OS vendors to collect a date of birth at setup and expose it to app stores through an API. GrapheneOS said it will "remain usable by anyone around the world without requiring personal information, identification or an account", and that "if GrapheneOS devices can't be sold in a region due to their regulations, so be it."
Strengths and limits
The guarantees are structural rather than promissory. Verified boot under user-controlled keys, hardware-backed attestation through the Auditor app, and an OS with nothing to log are not policies a change of management can quietly revoke. The hardening is not theatre either: memory tagging surfaced a Bluetooth LE flaw, CVE-2024-23694, before anyone was looking for it. And in July 2026 the duress PIN was tested in the least comfortable way available — a US federal prosecution followed a traveller's phone wiping itself during a border search in Atlanta. The feature did what the documentation says it does.
The limits are hardware-shaped and honest. GrapheneOS runs on Pixels and nothing else, because little else ships the attestation and long-term update guarantees its threat model assumes; a Motorola partnership announced in March 2026 should widen that in 2027, not today. There is no published third-party audit of the OS as a whole — the code is open, but no independent firm has signed a report on it, and that gap is what separates this grade from Tails. Governance has been turbulent, too: the 2018 split from the former sponsor and the founder's 2023 departure under harassment were loud, even if neither ever cost a user anything.
Verdict
GrapheneOS is the device layer the rest of this index quietly assumes and rarely gets — a handset that runs Monero wallets, SimpleX and Tor with no Google account underneath them. Take it if you can live on a Pixel; skip it if you need another device today, or if you want an audit report to point at.
GrapheneOS is the strongest privacy posture available on mainstream handset hardware, and the only one here whose refusal to identify users is about to be tested by statute rather than by policy. Take it if you can live on a Pixel and want an OS with nothing to hand over; skip it if you need another device today or want an audit report to point at. Grade: A (9.3/10). Trust: LEGIT.

