GrapheneOS's strongest everyday feature: real user profiles. You can banish Google and its apps entirely into a profile of their own โ your main profile stays clean and private.
GrapheneOS lets you run multiple separate user profiles. Each one has its own encryption, its own apps and its own data โ they can't read one another.
This is where your digital everyday life lives: messaging, photos, navigation, banking โ all from privacy-friendly sources. No Google Play Services, no Google account.
This is the only place you install Sandboxed Google Play and the few apps that absolutely require it. Google only sees what happens inside this box โ not your main profile.
Google apps in the second profile can't learn anything about your other apps, contacts or locations.
You actively switch into the Google profile when you need it. That creates distance instead of constant dependence.
You can delete the whole profile with a single tap โ and with it, remove all Google data on the device without a trace.
Settings โ System โ Multiple users โ add user. Name it e.g. "Google" or "Out & About". Switch into it.
In the new profile, open the pre-installed GrapheneOS App Store and install "Sandboxed Google Play" (Play Store, Play Services, Services Framework).
Only if needed. Many apps work without signing in too. Grant Google Play as few permissions as possible.
Anything that strictly requires Google (e.g. certain banking or company apps) goes into this profile โ nothing else.
Multiple profiles are the most powerful tool. But there are lighter options for less effort.
A hidden, separately encrypted area within a profile โ ideal for sensitive apps that become invisible at the press of a button.
Revoke network, sensor and location access from each app individually. That keeps even a Google app in the second profile tame.
Apps only see the contacts/files you specifically share โ instead of your entire address book.