Project showcase

Privacy-hardened mobile with GrapheneOS.

Most smartphones — even well-intentioned ones — are designed to leak. Contacts, location, app usage, and browsing history flow constantly to advertisers, platform operators, and aggregators. The problem isn't the hardware; it's the software stack.

GrapheneOS is an open-source, security-hardened Android derivative built for Google Pixel hardware. It replaces the Google-controlled firmware with a minimal, privacy-respecting alternative — verified boot, hardened memory allocator, and per-app network and sensor controls baked in. This is the mobile setup I recommend to clients who need genuine privacy, not just privacy theater.

Workflow

How it's built, step by step.

01

Device selection & GrapheneOS installation

Start with a supported Google Pixel. GrapheneOS is flashed via the official web installer — verified builds, reproducible from source. After installation, the bootloader is relocked, giving you a verified-boot chain that catches any subsequent tampering.
02

User-profile compartmentalization

Android's multi-user system, which GrapheneOS exposes fully, gives each profile its own isolated app space, contacts, and network state. One profile for work, one for personal use, one for anything you want fully air-gapped from the others. Apps in one profile have no visibility into another.
03

Sandboxed Google Play (optional)

GrapheneOS provides a sandboxed Google Play compatibility layer — installed inside a dedicated profile with no special OS privileges. Apps that require Play Services work normally; the sandbox prevents them from accessing anything outside that profile. You keep access to the Play ecosystem without granting it root-level trust.
04

Network & identity separation

Each profile can use a different network identity: separate VPN tunnel, different DNS-over-HTTPS resolver, or no internet at all for fully offline profiles. Combined with the Vanadium browser (GrapheneOS's hardened Chromium fork), web fingerprinting surface is minimized.
05

App sourcing & vetting

Prefer F-Droid open-source apps for the privacy-sensitive profile. Vet closed-source apps before installation: check permissions requested, network behavior, and whether the app can be isolated to a low-trust profile. Document your approved app list so future installs don't undo the work.
06

Backup & recovery posture

Encrypted local backups via USB to a dedicated machine, not cloud. Recovery keys stored offline with a documented restore procedure. GrapheneOS's per-profile encryption means even a partial restore lands in the right compartment without cross-contamination.

Outcomes

What you gain from this setup.

The result is a phone where each aspect of your digital life is genuinely isolated — not just hidden behind a folder. A compromise of your work profile doesn't expose your personal data. A leaky app installed in a sandboxed context can't reach your contacts or location. You can run apps that require Google Play without those apps having privileged access to your device.

Crucially, you understand the setup. Every decision is documented. If something needs to change — a new app, a new profile, a different network config — you know how to do it.

0 cross-profile data leakage
0 Play Store root-level privileges
100% verified-boot chain post-install

Want this set up?

I'll build it with you, not just for you.

We'll configure your device together, document every decision, and you'll walk away knowing how to maintain it.

Get in touch