The device that undoes
everything else.
Every mitigation on this site is a browser mitigation. Your phone is not a browser. It carries an identifier handed to every app you install, runs a Google services layer you cannot uninstall, and reports position continuously, all underneath a layer no content blocker reaches. There is one real answer to that, and it costs a phone.
What your phone does that a browser cannot
The Honest Mitigation section on the home page is blunt about uBlock Origin: it stops "nothing at all inside a phone app." That single line is a hole under the whole page. Most people spend most of their screen time in apps, and almost every tool recommended for the desktop stops at the edge of the browser.
Four things happen on a phone that have no browser equivalent.
- A cross-app identifier. Google Play services issues an advertising ID and hands the same one to every app on the device. Two companies that have never met can compare notes and find the same person, because they were both given the same number.
- A privileged services layer. Google Play services is not an app you can uninstall. It is a system component with system-level access, and it sits underneath the apps, the permissions screen, and any tool you might install to watch it.
- Continuous position. Android keeps separate wifi and Bluetooth scanning switches, on by default, which allow scanning to improve location accuracy even when you have turned location off. Turning off the obvious switch does not turn off the others.
- Code you did not choose. An app is rarely one company's software. Analytics and advertising kits ship inside it and collect on their own vendors' behalf. Deleting an app you dislike does not remove that vendor from your phone, because the same kit is inside the other apps you kept.
None of this is a jailbreak or a hack. It is the operating system working exactly as designed, by a company whose revenue is advertising.
Why "I turned off ad tracking" fails
That toggle does more than most people assume, and much less than "not being tracked" implies. Both halves are true.
It genuinely works, as far as it goes. Since Android 12, deleting your advertising ID does not just flag you as opted out. Google's own developer documentation states that "any attempts to access the identifier will receive a string of zeros instead of the identifier." The number is gone, not merely disapproved of. That part is real and worth doing.
Then Google shipped a replacement. Alongside the change, Play introduced the App Set ID, described as a way to "correlate usage or actions across a set of apps owned by the same organization" for analytics and fraud prevention, specifically for the case where the advertising ID has been zeroed out. You removed one identifier and the platform handed you another, scoped more narrowly, for the uses it decided were legitimate.
And that toggle only ever touched the one number. Play services still runs privileged. The advertising kits inside your apps still generate their own identifiers. Location still works. The operating system still reports. You changed a setting inside the system that is doing the collecting, which is the entire reason the setting was available to you.
This is why the answer is not further down the settings screen. Everything reachable from a settings screen is a request. The thing you actually want is a different arrangement of the device.
What GrapheneOS actually removes
GrapheneOS is an open source Android built on the Android Open Source Project, the same public codebase every Android phone starts from. What it leaves out is the part that is not public. In the project's own words, it "doesn't include or use Google apps and services by default."
The important part is what happens when you want them anyway.
- Sandboxed Google Play. You can install the official Google Play releases, but they run in the ordinary app sandbox with, the project states, "absolutely no special access or privileges." Apps that need Play still work. Play is now a regular app you can confine, revoke, and put in a separate profile, rather than the floor the whole system stands on. This is the single most important difference, and it is the reason this is not an abstinence tool.
- A Network permission. Per app, on or off, blocking "both direct and indirect access to any of the available networks." A calculator that wants the internet can simply be told no, which is not a choice stock Android offers you.
- A Sensors permission. Android has no permission covering the accelerometer, gyroscope, compass, or barometer, so any app can read them. GrapheneOS adds a toggle and feeds refused apps "zeroed data" rather than breaking them.
- Storage Scopes and Contact Scopes. An app demands all your files or all your contacts. The system tells it yes, then shows it only the ones you picked. The app believes it was granted everything and stops nagging.
- A hardened memory allocator, which is a security improvement rather than a privacy one, aimed at the most common class of exploitable bug.
Every other item on this site reduces how much someone takes. This is the only one that removes a party from the arrangement.
What it costs you
The ledger, in the same form the home page uses for everything else, because this page is not going to grade itself on a different curve.
- Stops
- Google operating as a privileged party on your own device. The system-issued cross-app identifier. Network and sensor access by apps that never needed it.
- Doesn't stop
- Your carrier, which still records which tower your phone is talking to and when. Anything you hand over by signing in, because a Google account on GrapheneOS is still a Google account. Anything already collected about you. Any app you install and feed.
- Time
- An hour or two for the install, most of it waiting. Plus the price of a supported phone, which is the real cost.
- One-time?
- Setup is. Living with it is not. You will meet an app that refuses to run, and you will have to decide what to do about it.
The things that break
You need a Pixel, currently the 6th generation and newer. That is a hardware requirement, not brand preference: GrapheneOS needs a device that allows an alternate operating system without giving up its hardware security, ships complete monthly security patches without long delays, and provides hardware memory tagging. Almost no other manufacturer permits all three. Check the official list rather than trusting this sentence, because it changes.
The bootloader has to be locked again afterwards. The project treats an unlocked bootloader as an incomplete installation and does not support it. This happens during setup and wipes the device, which is fine on a phone you are setting up anyway.
Some apps refuse to run. One mechanism explains all of them. GrapheneOS passes Google's basicIntegrity check but is not certified by Google, so it fails the ctsProfileMatch check. Apps that demand certification rather than actual integrity will reject it. Banking apps are the usual example, and contactless payment depends on the same certification. Which specific apps care changes constantly, so check a current compatibility list before you buy anything.
Android Auto works, with effort. It runs through sandboxed Google Play, installed from the GrapheneOS App Store, in a separate user or work profile, with permissions granted by hand. It is supported. It is not automatic.
You are trading convenience for a change in who your device answers to. That is a real trade with a real price, and the price is paid in small amounts, repeatedly, for as long as you own the phone.
If that sentence sounds fine to you, this is a good tool. If it sounds like a chore you will resent in three weeks, the three actions on the home page will do more for you than a phone you end up fighting.
If you are on an iPhone
GrapheneOS does not run on an iPhone and never will, because Apple does not permit alternate operating systems at all. So if you are holding one, everything above is advice you cannot take. Telling you to buy a different phone or stop reading would be exactly the abstinence-only move this site exists to avoid.
Where the iPhone beats stock Android: App Tracking Transparency requires apps to ask before tracking you across other companies' apps and sites, and the ask is a real prompt with a real refusal. More structurally, there is no privileged, un-uninstallable services layer belonging to an advertising company, because Apple's money comes from selling hardware. That shows up in the defaults, and defaults are most of what happens to most people.
Where it falls short of GrapheneOS: you cannot remove Apple. The system is closed, so you cannot audit the claim, only accept it. You cannot install anything else. And iCloud is on by default, so a copy of a great deal of your life sits on Apple's servers in a form Apple can read unless you change that yourself.
So change that yourself. Advanced Data Protection extends end-to-end encryption to most iCloud categories, including device backups and photos, which is the difference between Apple declining to hand your data over and Apple being unable to. Mail, Contacts, and Calendar stay outside it for interoperability reasons. Lockdown Mode is a different tool for a different problem: turn it on only if you have specific reason to think a well-resourced adversary is targeting you personally, because it breaks ordinary functionality on purpose.
Everything above is a settings change. Ten minutes, no hardware, nothing to install. That is what makes it cheap, and also what keeps it short of the real thing.
A setting is a request, and requests can be withdrawn. In February 2025 the UK government demanded access to encrypted user data. Rather than build a way in, Apple stopped offering Advanced Data Protection in the United Kingdom entirely. Existing users were told they would eventually have to turn it off. The feature protects users in most of the world and is simply unavailable to an entire country, because a government asked and the answer was not the user's to give.
Who should not do this
Most people reading this page. There is no false modesty in that. It is the same rule the rest of the site runs on: a tool adopted without a reason costs you every day and protects you against an adversary you do not have.
If your honest answer to "what am I defending against" is that you dislike being advertised at, this is far too much machine for the job. The three actions on the home page take about an hour in total and cover most of the damage that realistically happens to people. Do those. They are not a consolation prize.
Reasons that do justify it. Your work makes you a target: a journalist protecting a source, an organizer, a lawyer carrying client material. You need a device that a specific person has never had physical access to. Or you have thought about the arrangement, object to it, and are willing to pay for the objection. That last one is legitimate and does not require a threat model.
Reasons to wait. You are not comfortable being your own tech support. You depend on an app that might not run and cannot afford to find out. You are treating it as step one, before a password manager and a credit freeze, which is the wrong order by a wide margin.
And a hardened phone signed into the same Google account as everything else, running the same apps, is theater. The operating system changes who has privileged access. It does not change what you choose to hand over.
The project itself. The features page is the honest technical description, not marketing, and it is short enough to read before deciding.
The current device list and the reasoning behind it. Check this rather than any secondhand summary, including this page, because it changes as devices come and go.
The web installer runs in a browser and is the recommended route. Use the official instructions. Third party guides for this are frequently out of date in ways that matter.
This is triage too
Read the remedy back to yourself. To stop your phone reporting on you, buy a particular brand of phone, erase the operating system it came with, install a different one written by volunteers, lock the bootloader, and accept that some apps will refuse to work. That is a real option and it genuinely works. It is also not an option most people can take, and calling it a personal choice hides why it had to exist.
Ask why the list of supported devices is so short. The short list has nothing to do with GrapheneOS lacking ambition. Nearly every manufacturer refuses to let you install another operating system without surrendering the hardware security that made the phone worth trusting in the first place. The choice gets presented as safety or freedom, and it is presented that way because presenting it that way is profitable. There is no technical reason those have to be opposed.
You paid for the device. You own the device. The decision about what it reports, to whom, and how often was made before you took it out of the box, and the only way to reverse it is to become the kind of person who reflashes phones.
The Bigger Picture makes the argument that privacy is infrastructure rather than a personal habit. This page is what that argument looks like when it reaches your pocket. The closing section on Honest Mitigation names the organizations doing the legal work, and the same point applies here: a law can require that a device you own let you decide what it does. No amount of individual effort can.