My name is QnA. I am a Bitcoiner and I like to help other Bitcoiners. I spend my days building Bitcoin-centric sovereignty tools at Foundation. This site is a collection of my contributions that I can point people towards to help them along their journey. If you find it valuable, please share it with your peers and consider contributing or sending a tip.
GrapheneOS is a nonprofit open-source mobile operating system designed to provide a high level of privacy and security while remaining fully compatible with Android applications.
Sommaire:
- Intro
- Preparation
- Install
- App Alternatives
- Downsides
- Useful Info
Why use GrapheneOS?
- Attack surface reduction - Remove unnecessary code (or bloatware).
- Vulnerability exposure prevention - Allow the user enough granularity to choose the compromises they're comfortable with.
- Sandbox containment - GrapheneOS fortifies existing Android sandboxes, further locking down each app's ability to communicate with the rest of your phone.
Easing the Transition
Getting Started
Choosing a device
Installing GrapheneOS
- The Pixel
- A USB cable to go from the phone to your computer
- A computer to run a web browser (any Chromium-based browser: Chrome, Edge, Brave, etc.)
- The first step is to go to Settings > About phone and repeatedly tap the build number until you see 'Developer Mode' is activated.
- Next head to Settings > System > Developer Options and enable 'OEM Unlocking'.
- Now reboot the device and hold the volume down button whilst the phone is turning back on.
- Connect the phone to your laptop and if prompted for authorization, allow the connection.
- On the web installer page, click on 'Unlock the bootloader'.
- You'll then see the phone options change. Use the volume button to change the selection to
unlockand use the power button to accept. - Next click download release on the web installer page.
- Once fully downloaded, move on to the next step and click 'Flash release'. This will take a minute or two and you do not need to touch the phone at all.
- Finally, move to the next step of the web installer and click Lock Bootloader. You'll need to change the selection and confirm with the power button in the same way you did earlier in the process.
- When you see the word
Start, confirm this with the power button and the device will boot into your new Google-free operating system.
Pre Installed Apps
- The Auditor app uses hardware-based security features to validate the identity of a device along with authenticity and integrity of the operating system. It will verify that the device is running the stock operating system with the bootloader locked and that no tampering with the operating system has occurred.
- Vanadium is a privacy and security hardened variant of Chromium web browser.
Customization
Setting a wallpaper and updating the theme
- Update the home and lock screen backgrounds for images downloaded from the web.
- Choosing the accent colors used throughout the UI.
- Enable Dark theme.
Show battery percentage
Import contacts
Alternative Apps
F-Droid
.apk file. You'll then be asked if you'd like to install the app.Aurora Store
play.google.com. Now, whenever navigate to a product or service's website that has the 'Download via Play Store' link, tapping on it will open that app within Aurora for you to download.APK Download
.apk file. This is a great alternative that requires zero third party app stores, simply download the file directly from the project or services' website or GitHub repository.Web Apps
Web Browsers
.onion sites, you can download the Tor Browser APK directly from their website or via F-Droid.VPNs
Messaging
- Signal is one of the more popular end-to-end encrypted (E2EE) messengers that has a strong track record and rich feature set. Signal requires a phone number for sign up, so if you plan on chatting with people that you'd rather did not know your phone number, perhaps look into some of the alternatives or hide your number in your profile settings. Signal must be downloaded via the Aurora Store.
- Simplex is a fairly new E2EE messenger. It has no user ID, requires no phone number or personal information. People find you by scanning your personal QR code or by visitng your unique link. Simplex also allows advanced users to run their own server to further reduce reliance on any centralized entity. Simplex does not have a desktop client, so may not be suitable if multi-device is on your priority list. Simplex for Android is available via F-Droid.
- Threema offers a similar experience to Simplex, but has been around for longer and as a result, feels a little more polished. Threema is not free, a lifetime license costs $4.99 and can be bought with Bitcoin. Threema offers a web client and native desktop applications. The Android application is available via F-Droid.
- Mercurygram is an unofficial FOSS fork of the official Telegram app for Android. Telegram has E2EE 'secret chats', but the default option is not private. Mercurygram can be downloaded from F-Droid.
Media
- Spotube is a cross-platform Spotify client that doesn't require a Premium account. Spotube is available via F-Droid.
- Newpipe offers a YouTube experience without the annoying adverts and questionable permissions. With NewPipe you can subscribe to channels, listen in the background and even download for offline viewing. NewPipe is accessible via F-Droid.
- AntennaPod is a podcast player that allows you to subscribe and manage all of your favorite shows. AntennaPod is available via F-Droid.
Maps
- Magic Earth is a maps alternative that supports turn-by-turn navigation, 3D and offline maps. Magic Earth can be downloaded from the Aurora Store.
- Organic Maps is maps alternative for travelers, tourists, hikers, and cyclists based on top of crowd-sourced OpenStreetMap data. It is a privacy-focused, open-source fork of Maps.me app (previously known as MapsWithMe). It supports 100% of features without an active Internet connection and can be downloaded from F-Droid.
- OsmAnd is another great maps alternative that supports all of the features mentioned above.
- Proton Mail offers a free private email service that supports audited E2EE. Proton also offers a paid version that supports custom domains and aliasing. Proton Mail can be downloaded as a direct APK or via Aurora.
- Tutanota offers the same features as Proton Mail, including optional paid services and can be downloaded as a direct APK or via F-Droid.
- K-9 Mail is an open source email client that works with basically every email provider. It supports multiple accounts, a unified inbox and the OpenPGP encryption standard.
Productivity
- Syncthing Fork is a fork of the file synchronization program. It synchronizes files between two or more devices in real time, safely protected from prying eyes. Your data is your data alone and you deserve to choose where it is stored, whether it is shared with some third party, and how it's transmitted over the internet. Syncthing Fork is available via F-Droid.
- KDE Connect all of your devices to easily talk to one another when connected to your home network. Easily send files, photos, clipboard data across all of your devices (even on iOS!). KDE connect can be downloaded from F-Droid.
- Notesnook is an E2EE notes application for syncing your thoughts and to-do lists across all of your devices. Their free plan should cover most personal use cases. Notesnook is available on F-Droid.
- Standard Notes is very similar to Notesnook, but requires a paid plan to match the feature set. Standard Notes is available through F-Droid.
- Anysoft Keyboard is a keyboard app that allows you to customize pretty much anything you can think of when it comes to your phone typing experience. It can be downloaded via F-Droid.
- GBoard is the default Google keyboard app. In my experience it offers by far the best type and swipe experience. If you download this app, ensure you completely disable all network related permissions. It can be downloaded via Aurora.
Lifestyle
- Breezy Weather is a feature-rich open source weather app with Material 3 Expressive interface; it offers well-thought-out visualizations, forecasts, real-time conditions, air quality, pollen, weather alerts from over 50 sources.
- Translate You is an Open Source and privacy preserving translation app that supports more than 200 languages. Translate You is available via F-Droid.
- Proton Calendar is a simple to use E2EE that interacts seamlessly with your Proton email accounts. Proton Calendar can be downloaded as an APK or via the Aurora store.
- PassAndroid is an app for displaying and storing boarding passes, coupons, movie tickets and membership cards etc. Simply download the relevant
pkpassorespassfile and open with the app. PassAndroid is available via F-Droid.
Security/Privacy
- Bitwarden offers a free and E2EE cross platform password manager solution for all of your devices. Their paid service allows you to integrate 2FA codes into the app. The server side of Bitwarden can be self hosted and the Android app is available via F-Droid.
- Proton Pass offers a similar free service to Bitwarden, but Proton Unlimited customers are able to access additional advanced features. Proton Pass is available via APK or Aurora.
- FreeOTP is a two-factor authentication application for systems utilizing one-time password protocols. Tokens can be added easily by scanning a QR code. FreeOTP is available via F-Droid.
- Aegis is a free, secure and Open Source app for Android to manage your 2-step verification tokens for your online services. Aegis is available via F-Droid.
- Cryptomator is a free cross-platform service (paid only via Google Play on Android) that encrypts your data locally so you can safely upload it to your favourite cloud service. Cryptomator can be downloaded via F-Droid.
Cloud Solutions
- Proton Drive is a paid E2EE cloud solution for backing up and storing all of your files. At the time of writing, they have just announced a Windows desktop client, but Mac and Linux users must continue to use the web version to sync from their computers (for now). The Android client is available as an APK or via Aurora.
- Skiff also offers paid E2EE cloud storage and file collaboration tools. They offer a Mac and Windows desktop client (as well as a web app) and their Android clients must be downloaded from Aurora.
- Nextcloud offers a fully featured cloud based solution for collaboration, cross device sync and file storage. More advanced users can choose to self-host their Free and Open Source software on any hardware they like. The Android clients can be downloaded via F-Droid.
- Cryptpad offers a free, web based, E2EE alternative to Google Docs.
The Downsides
- Apple CarPlay/Android Auto - You're going to need to stick to good old fashioned Bluetooth, USB or Aux.
- Apple/Google Pay - Pretty much everyone carries their wallet with them anyway!
- Banking apps - It's not that these don't work at all. Some do, perfectly in fact. Others work only with Google Play Services enabled (read more on that below) and others just don't work at all. Read the report on your bank here to see the current state of play. Fear not if yours is on the list that does not work, remember you can just save the URL as a web app on your home screen.
- Push Notifications - Most applications that send you updates when not using a specific app will do so through Google Play Services. These are not installed by default with GrapheneOS, so if you find yourself not being notified immediately when your friend sends you an email, this is likely why. The good news is that some of the apps mentioned above have implemented their own background connection to periodically check for updates and then give you a notification where required
Sandboxed Google Play
Profiles
e-Sims
Backups
- Go to Settings > System > Backup, then write down your 12-word recovery code. This code is required to decrypt the backup file at a later date. Lose the code, lose access to your phone backup.
- Next choose your storage location. I'd recommend an external USB drive or industrial grade microSD card.
- Choose the data to be backed up. If you have the space on your specified storage medium, I'd advise selecting everything.
- Tap the three dots n the top right, and choose Backup now.
Conclusion
Learn more
- GrapheneOS Official Usage Guide - Official Website
- GrapheneOS Forum - Official Website
- GrapheneOS Settings Masterclass - Video by 'The Privacy Wayfinder'
- GrapheneOS General Podcast - Podcast by 'Watchman Privacy'
Author
This tutorial has been written by Bitcoin Q&A
You can say thanks by tipping the professor.
Credits
This tutorial has not been proofread yet
The original content has been translated by AI, but human review is necessary to ensure its accuracy.
7 525 sats3 763 sats1 882 satsEvery content on the platform is the result of a collaborative effort: each lesson, translation, and revision is made possible by the work of contributors. For this reason, we are always looking for proofreaders who can review our content in many languages. If you want to participate in the proofreading process, please reach out in our Telegram group and read our tutorial. We remind you that this content is open-source - licensed under CC BY-SA - so it can be freely shared and used, as long as the original source is credited.














