What this protects, and what it doesn't
Protects
- Against many app and exploit attacks: apps run in a stronger sandbox, and supported devices were chosen for hardware security features such as memory tagging and a secure element.
- Against apps quietly using the network or motion sensors: you can revoke the Network and Sensors permissions per app.
- Against a phone that is seized while locked: the USB-C port refuses new data connections when locked, and auto reboot returns an idle phone to its fully encrypted state.
- Against Google services having privileged access: Google Play is optional and, if you install it, runs as an ordinary sandboxed app.
Does not protect
- The people you talk to. If their phone or account is compromised, your messages to them are too.
- Cloud accounts you sign into. Whatever you sync to a provider is governed by that provider, not by your phone.
- Physical coercion. Someone who forces you to unlock the phone gets what is on it; a duress PIN only helps if wiping is the outcome you want.
- Carrier metadata. The mobile network still sees your phone's location and connections whenever the radio is on; GrapheneOS says airplane mode is the only way to avoid cellular tracking.
Prerequisites
- A Pixel on the official supported-devices list, preferably bought unlocked rather than from a carrier (carrier variants can block bootloader unlocking).
- A computer you trust with at least 2 GB of free memory and 32 GB of free storage, a supported browser (for example Chromium or Google Chrome) and a good USB cable plugged directly into the computer.
- A backup of everything on the phone: unlocking and locking the bootloader both wipe it.
Step by step
-
Check that your Pixel is supported
GrapheneOS only supports specific Google Pixel models, chosen for hardware security features (memory tagging, a secure element, full security updates). The list changes as new Pixels launch and older ones reach end of life, so check the official supported devices list on the day you buy or install. The project recommends Pixel 8 and later, which get seven years of support from launch.
Avoid carrier-branded phones: their carrier can disable bootloader unlocking, and then you cannot install GrapheneOS at all.
-
Install with the official web installer
Use the web installer on grapheneos.org and follow it in order. In short: turn on developer options (tap Build number repeatedly under About phone), enable OEM unlocking in Developer options, boot into Fastboot Mode by holding volume down while the phone starts, connect it, then use the installer's buttons to unlock the bootloader, download the release and flash it.
Do not touch the phone while it flashes. Avoid USB hubs, virtual machines and private-browsing windows, which are common causes of failed installs.
-
Lock the bootloader and turn off OEM unlocking
When flashing finishes, use the installer's Lock bootloader button and confirm on the phone. This step matters: a locked bootloader is what lets verified boot detect tampering with the operating system. Locking wipes the phone again, which is expected.
At the end of first setup, keep the option to disable OEM unlocking switched on, so the bootloader cannot be unlocked again without first unlocking the phone.
-
Verify the install
At boot, a yellow notice shows an identifier for the verified boot key. On supported devices it is the full SHA-256 hash; compare it with the hash GrapheneOS publishes for your model on the install page.
For a stronger check, use the Auditor app with a second Android phone: one phone runs it as the auditor, the GrapheneOS phone as the auditee, and they exchange QR codes. Auditor uses hardware-based attestation to check the hardware, firmware and operating system, and remembers the pairing so later checks detect changes. See the Auditor tutorial.
-
Separate your apps into profiles
Put apps you do not trust, or that need Google services, in a separate user profile. Each profile has its own encryption keys and apps. Ending a profile session logs it out, so its apps cannot run and its keys are removed from memory.
A simple pattern: keep the Owner profile minimal, and use a second profile for social media, shopping or work apps.
-
Add Google Play only if you need it
GrapheneOS ships without Google services. If an app you need requires them, install Google Play services from the GrapheneOS App Store, ideally in a separate profile. It then runs as an ordinary sandboxed app with no special privileges, and only in the profile where you installed it. By default, location requests are handled by GrapheneOS rather than Google's network location service.
-
Revoke Network and Sensors per app
GrapheneOS adds two permissions stock Android does not let you control:
- Network: you can switch it off when installing an app, or later in the app's permissions. The app then sees no network at all, as if the phone were offline.
- Sensors: blocks the accelerometer, gyroscope, barometer and other sensors not covered by other permissions. Blocked apps receive no sensor data. You can make it off by default for new apps in Settings > Security & privacy > More security & privacy.
Storage Scopes and Contact Scopes let an app work while seeing only the files or contacts you choose.
-
Set auto reboot, USB-C and duress options
- Auto reboot restarts the phone after it has been locked for a set time (18 hours by default; you can pick from 10 minutes to 72 hours). After a reboot, your data is at rest and encrypted until you unlock again. A shorter timer helps if the phone could be seized.
- USB-C port (in Exploit protection in the security settings): the default Charging-only when locked blocks new USB data connections while the phone is locked. Charging-only or Off is stricter.
- Duress PIN and password (Settings > Security & privacy > Device unlock > Duress Password, in the Owner profile): entering it at any unlock prompt wipes the phone and its eSIMs immediately and irreversibly. You must set both a duress PIN and a duress password. Only set one if wiping is the outcome you want under pressure, and think about the legal situation where you live.
-
Keep it updated
Updates download automatically in the background and apply when you reboot; if the new version fails to start, the phone rolls back. Stay on the default Stable release channel and reboot when an update is ready. Security fixes only protect you once the reboot happens.
Your ticks are saved in this browser only (see or delete local data).
Common mistakes
- Skipping the bootloader lock at the end of the install. Without it, verified boot cannot protect you.
- Buying a carrier-locked Pixel that cannot unlock its bootloader.
- Installing Google Play and every usual app in the Owner profile, which recreates the phone you were trying to leave.
- Treating GrapheneOS as anonymity. Your carrier, your accounts and the people you contact still see what they saw before.
- Setting a duress PIN that is easy to type by accident.
Going further
Combine the phone with a threat model, hardened messaging, and passkeys or a hardware key for your accounts. GrapheneOS also documents an LTE-only mode to reduce cellular radio attack surface, PIN scrambling, and two-factor fingerprint unlock (fingerprint plus a PIN). Read the features page for the full list.