Step 3 ยท Separating identities

Profiles: lock Google in a box

GrapheneOS's strongest everyday feature: real user profiles. You can banish Google and its apps entirely into a profile of their own โ€“ your main profile stays clean and private.

The basic idea

GrapheneOS lets you run multiple separate user profiles. Each one has its own encryption, its own apps and its own data โ€“ they can't read one another.

๐Ÿ”’

Main profile โ€“ completely Google-free

This is where your digital everyday life lives: messaging, photos, navigation, banking โ€“ all from privacy-friendly sources. No Google Play Services, no Google account.

๐Ÿ“ฆ

Second profile โ€“ "Google in a Box"

This is the only place you install Sandboxed Google Play and the few apps that absolutely require it. Google only sees what happens inside this box โ€“ not your main profile.

Important to understand: on GrapheneOS, Google Play does not run with system privileges, but as an ordinary app in the sandbox โ€“ with the same permissions as any other app. Tucked into its own profile, it's hemmed in as tightly as possible.

Why not just put everything in the main profile?

Clean separation

Google apps in the second profile can't learn anything about your other apps, contacts or locations.

Deliberate use

You actively switch into the Google profile when you need it. That creates distance instead of constant dependence.

Cuttable at any time

You can delete the whole profile with a single tap โ€“ and with it, remove all Google data on the device without a trace.

How to set it up

A) Install Sandboxed Google Play in the second profile

Create a second profile

Settings โ†’ System โ†’ Multiple users โ†’ add user. Name it e.g. "Google" or "Out & About". Switch into it.

Install Sandboxed Google Play

In the new profile, open the pre-installed GrapheneOS App Store and install "Sandboxed Google Play" (Play Store, Play Services, Services Framework).

Optional: sign in to a Google account

Only if needed. Many apps work without signing in too. Grant Google Play as few permissions as possible.

Install only the necessary apps here

Anything that strictly requires Google (e.g. certain banking or company apps) goes into this profile โ€“ nothing else.

B) Keep the main profile clean

Quick profile switching: from the quick settings (swipe down from the top) you can tap the user icon and jump between your main and Google profile in an instant.

Even finer: Private Space & per-app separation

Multiple profiles are the most powerful tool. But there are lighter options for less effort.

Private Space

A hidden, separately encrypted area within a profile โ€“ ideal for sensitive apps that become invisible at the press of a button.

Permission toggles

Revoke network, sensor and location access from each app individually. That keeps even a Google app in the second profile tame.

Contact scopes

Apps only see the contacts/files you specifically share โ€“ instead of your entire address book.