Project showcase
Privacy-hardened mobile with GrapheneOS.
Most smartphones — even well-intentioned ones — are designed to leak. Contacts, location, app usage, and browsing history flow constantly to advertisers, platform operators, and aggregators. The problem isn't the hardware; it's the software stack.
GrapheneOS is an open-source, security-hardened Android derivative built for Google Pixel hardware. It replaces the Google-controlled firmware with a minimal, privacy-respecting alternative — verified boot, hardened memory allocator, and per-app network and sensor controls baked in. This is the mobile setup I recommend to clients who need genuine privacy, not just privacy theater.
Workflow
How it's built, step by step.
Device selection & GrapheneOS installation
User-profile compartmentalization
Sandboxed Google Play (optional)
Network & identity separation
App sourcing & vetting
Backup & recovery posture
Outcomes
What you gain from this setup.
The result is a phone where each aspect of your digital life is genuinely isolated — not just hidden behind a folder. A compromise of your work profile doesn't expose your personal data. A leaky app installed in a sandboxed context can't reach your contacts or location. You can run apps that require Google Play without those apps having privileged access to your device.
Crucially, you understand the setup. Every decision is documented. If something needs to change — a new app, a new profile, a different network config — you know how to do it.
Want this set up?
I'll build it with you, not just for you.
We'll configure your device together, document every decision, and you'll walk away knowing how to maintain it.
Get in touch