LEGIT A L0 · trustless
GrapheneOS
GrapheneOS

De-Googled hardened Android OS · no account, no telemetry

GrapheneOS runs a phone with no account, no email and no ID — and told the incoming age-verification laws that this will not change.

*A hardened Android fork for Pixel hardware that treats identity as an attack surface — and the statute book as a compatibility problem.*

Jurisdiction Toronto, Canada
Operating since 2014
Category Field Tools
Rubric v2.7

How it works

GrapheneOS is a hardened fork of the Android Open Source Project that installs on Google Pixel hardware from a browser tab over WebUSB — no vendor account, no proprietary flashing tool. The installer then relocks the bootloader against GrapheneOS's own signing keys, so verified boot stays intact end to end and the phone attests to its own firmware rather than to Google's.

What lands on the device is Android with the Google layer excised: no Play Services, no Play Store, no account prompt at setup. Apps that genuinely need Google can run through sandboxed Google Play, a compatibility layer that installs the official Google binaries as ordinary, unprivileged apps confined to a single profile. They hold no system privileges, they see only what that profile grants, and signing into a Google account stays optional.

The hardening underneath is the actual product: a hardened memory allocator, hardware memory tagging on recent Pixels, up to 32 secondary profiles, Storage and Contact Scopes, and Network and Sensors permissions that stock Android does not offer. LTE-only mode strips the 2G, 3G and 5G baseband code paths. The device auto-reboots into its pre-unlock state after 18 hours idle, and a duress PIN wipes it — eSIMs included — irreversibly.

KYC & privacy

There is no signup, no email, no phone number, no account. The project's own wording is blunt: "there aren't any analytics/telemetry in GrapheneOS", and the only thing its servers learn is the generic device model and OS version needed to serve an update. Connectivity checks, network time, GNSS almanac fetches and attestation key provisioning route through GrapheneOS-operated endpoints instead of Google's. Server-side logs are purged after four to ten days — short, but not zero.

The software is free. The GrapheneOS Foundation, a Canadian federal non-profit incorporated in Toronto in March 2023, funds development through donations in Bitcoin, Monero, Ethereum, Litecoin and Zcash, or through PayPal, Wise and GitHub Sponsors. None of it is required to run the OS.

In March 2026 the project said it will not implement the operating-system age-assurance mandates now arriving. California's AB-1043 takes effect on 1 January 2027 and obliges OS vendors to collect a date of birth at setup and expose it to app stores through an API. GrapheneOS said it will "remain usable by anyone around the world without requiring personal information, identification or an account", and that "if GrapheneOS devices can't be sold in a region due to their regulations, so be it."

Strengths and limits

The guarantees are structural rather than promissory. Verified boot under user-controlled keys, hardware-backed attestation through the Auditor app, and an OS with nothing to log are not policies a change of management can quietly revoke. The hardening is not theatre either: memory tagging surfaced a Bluetooth LE flaw, CVE-2024-23694, before anyone was looking for it. And in July 2026 the duress PIN was tested in the least comfortable way available — a US federal prosecution followed a traveller's phone wiping itself during a border search in Atlanta. The feature did what the documentation says it does.

The limits are hardware-shaped and honest. GrapheneOS runs on Pixels and nothing else, because little else ships the attestation and long-term update guarantees its threat model assumes; a Motorola partnership announced in March 2026 should widen that in 2027, not today. There is no published third-party audit of the OS as a whole — the code is open, but no independent firm has signed a report on it, and that gap is what separates this grade from Tails. Governance has been turbulent, too: the 2018 split from the former sponsor and the founder's 2023 departure under harassment were loud, even if neither ever cost a user anything.

Verdict

GrapheneOS is the device layer the rest of this index quietly assumes and rarely gets — a handset that runs Monero wallets, SimpleX and Tor with no Google account underneath them. Take it if you can live on a Pixel; skip it if you need another device today, or if you want an audit report to point at.

verdict.grapheneos.diff +5 pros −4 cons
what works
+ 01 No account, no email, no telemetry — servers see only device model and OS version for updates
+ 02 Verified boot survives install: the bootloader relocks against GrapheneOS's own signing keys
+ 03 Duress PIN, 18-hour auto-reboot, plus Network and Sensors permissions stock Android lacks
+ 04 Sandboxed Google Play runs the official Google binaries unprivileged, inside one profile only
+ 05 Free and permissively licensed, funded by a Canadian non-profit on BTC, XMR, ETH and fiat
what to know
01 Pixel-only hardware support; the Motorola partnership ships no device before 2027
02 No published third-party audit of the OS as a whole — the code is open, the report is missing
03 Governance turbulence: 2018 sponsor split, founder stepped down in 2023 under harassment
04 Update and network-service logs are retained four to ten days rather than not written at all

GrapheneOS is the strongest privacy posture available on mainstream handset hardware, and the only one here whose refusal to identify users is about to be tested by statute rather than by policy. Take it if you can live on a Pixel and want an OS with nothing to hand over; skip it if you need another device today or want an audit report to point at. Grade: A (9.3/10). Trust: LEGIT.