# CalyxOS (Android ROM)

**URL:** https://discuss.privacyguides.net/t/calyxos-android-rom/11614
**Category:** Tool Suggestions
**Tags:** rejected
**Created:** 2023-01-25T15:59:18Z
**Posts:** 248

## Post 1 by @InternetGhost — 2023-01-25T15:59:18Z

I noticed that CalyxOS is no longer mentioned as a recommendation on the site and I was wondering why that’s the case. I mean it in a genuine way and not as in “why isn’t my favorite ROM not listed” kind of way.

In looking into it I did find the blog post discussing [why GrapheneOS is recommended over CalyxOS](https://blog.privacyguides.org/2022/04/21/grapheneos-or-calyxos/). I understand that as it lines up with the general consensus - it seems like Graphene has pulled ahead of the pack in terms of security, privacy, and user experience.

But then I see that DivestOS is listed as an [AOSP derivative to consider](https://www.privacyguides.org/android/). Not to take away from DivestOS at all (I want to learn more about it), but Calyx is based on LineageOS as well if I remember correctly. It seems like Divest leans on some Graphene technology where as Calyx continues to use microG, but otherwise they seem to be similar ROMs that satisfy similar requirements. Both are likely not as good as Graphene, but they are still good alternatives to know about.

So my question, is there something about Calyx that’s preventing it from being listed as a recommendation? Is it something about microG, the way the project is run, or just the perceived difference in quality from Graphene and Divest compared to Calyx? Is it that there are a lot of small things that aren’t great that, when put together, make it not a great option to recommend? Or is it about just not offering too many options that might overwhelm people looking for a privacy respecting Android ROM?

Last things:

1. I don’t even use Calyx, but I’ve heard about it a lot and was also curious about the general decline it seems to have had in the privacy world.
2. I am active in another privacy forum, plz I don’t mean this as a troll post, lol

---

## Post 2 by @NoOne — 2023-01-25T16:55:16Z

I agree with you, perhaps there could be created section/category on this website something like misfits, and provide report/explanation to why they are no longer recommended, along with articles/proves that back these claims.

UI suggestions:

- Green (Subjective, or questionable decisions of the project)
- Orange (Potentially compromising privacy/security in updated version of the project)
- Red (The project contains malware, or was breached, and taken over etc…)

---

## Post 3 by @InternetGhost — 2023-01-25T17:51:44Z

‘Misfits’ sounds a little too aggressive for me, lol. But if folks want to take the explanations provided and put that somewhere on the site, that could be a good idea. I also think it could be fine to just leave it to this thread to explain so that future people who are wondering can search for Calyx in the forum and find answers. I can see how the site maybe should try to stick to recommendations and not to explanations of everything they don’t recommend.

---

## Post 4 by @dngray — 2023-01-25T18:05:35Z

DivestOS is listed for harm reduction reasons basically.

At this time we don’t see any compelling reasons to list CalyxOS over using something like GrapheneOS anyway, that’s the main reason. It’s pretty much AOSP android, with a few bundled apps, We discussed it previously here [Remove CalyxOS by TommyTran732 · Pull Request #1518 · privacyguides/privacyguides.org · GitHub](https://github.com/privacyguides/privacyguides.org/pull/1518)

---

## Post 5 by @InternetGhost — 2023-01-25T18:50:18Z

Thanks for the insight! I guess it really has just fallen off the wagon while Graphene has caught up. I remember microG being the main selling point for Calyx as a way to get Google Play apps, but since GOS’s sandboxed Google Play services there isn’t anything else to compete on.

---

## Post 6 by @NoOne — 2023-01-25T20:29:08Z

Well, (I don’t mean to be mean, same thing could happen to me) but you’ve missed it, even if Daniel Gray pulled up discussion where it already was solved. So making a category of “misfits” (or other name) could be reconsidered, **IF** it would save moderators more time to make such articles, than reopening old discussions, over, and over again. Also it was made on GitHub, so you would have to jump over to different site, unless its copy request is present, on this forum?

Mods: It’s up to you, I’m just trying to share suggestions.

---

## Post 7 by @donotspamplz — 2023-02-13T17:48:50Z

Is there a way to downvote a suggestion on here? It doesn’t appear to have that function, so please accept this -1 from me

---

## Post 8 by @jonah — 2023-02-13T18:00:54Z

> [@NoOne](#):
>
> Well, (I don’t mean to be mean, same thing could happen to me) but you’ve missed it, even if Daniel Gray pulled up discussion where it already was solved. So making a category of “misfits” (or other name) could be reconsidered, **IF** it would save moderators more time to make such articles, than reopening old discussions, over, and over again.

_(Related discussion for the team: [https://github.com/privacyguides/team/discussions/18](https://github.com/privacyguides/team/discussions/18))_

I agree (though **not** strongly) that we should have anti-recommendations on the site for the reasons you specified, however @dngray disagrees and has some good reasons here:

> [@Privacy Guides should cover the reasoning behind why you should switch from X to Z](https://discuss.privacyguides.net/t/privacy-guides-should-cover-the-reasoning-behind-why-you-should-switch-from-x-to-z/10168/2):
>
> This discussion is usually in our discussion forum, or on Github. We don’t litter the site with every anti-recommendation, otherwise the whole site would become just that, and it would be painful to maintain as there are a lot of things, the team purposely does not use. The reason this was removed, is because it was not entirely accurate. That being said we are still looking at re-introducing a Windows section [https://github.com/privacyguides/privacyguides.org/pull/1659](https://github.com/privacyguides/privacyguides.org/pull/1659) though it does require…

We’re not sure it’s worth the time investment. If you wish to continue discussing anti-recommendations, you can do so in that thread instead of here.

---

## Post 9 by @jonah — 2023-03-12T16:57:40Z

A post was split to a new topic: [Forum Voting System Improvements](/t/forum-voting-system-improvements/12053)

---

## Post 10 by @jonah — 2023-04-12T22:31:54Z

Do we have a revised opinion on CalyxOS now that they have streamlined security updates via their Security Express channel?

> **[April Security update - Security Express](https://calyxos.org/news/2023/04/12/april-update-security-express/)**
>
> April Security update - Security Express

We can give it a few months to see how it actually pans out, but in theory they would meet our current criteria: [Android - Privacy Guides](https://www.privacyguides.org/en/android/#operating-systems)

---

## Post 11 by @anon63378630 — 2023-04-12T22:44:34Z

They still regularly take two to five days to get the latest WebView/browser into their testing F-Droid repo: [https://divestos.org/misc/ch-dates.txt](https://divestos.org/misc/ch-dates.txt)  
Something I’ve done within a day for a year now.

---

## Post 12 by @jonah — 2023-04-12T22:49:38Z

~~So they have a better track record than Google does at updating my Chromebook /s~~

Thanks for keeping track of that stuff, yeah that’s something to consider. I should circle back to whether they ever allowed other WebView implementations to be installed, I had asked them to whitelist more WebView apps a while ago.

---

## Post 13 by @anon63378630 — 2023-04-13T00:06:57Z

Another thing to take into account:  
They are currently selling the Pixel 4a 5g for $550 despite only having 6 months left of support from Google.

And are also selling the Pixel 6a for $700 despite being available at Amazon and Best Buy for $250-300.

Absurd markup aside or deranged notation that it is a “donation”: I think it is asinine they are selling a near EOL phone without ANY such note of it being so.

To go even further, their starting Internet “membership” is $500 for the first year and $400 upfront for every year after OR $600 a year if paid quarterly.

Despite it being a rebranded service from Mobile Citizen who only actually charges $180 for every year at $15 a month: [https://connectall.org/icmc-bundle-p2-1.html](https://connectall.org/icmc-bundle-p2-1.html)

---

## Post 14 by @dumpster — 2023-04-13T00:54:56Z

While those margins remain breathtaking, I just want to note that the membership includes a mobile hotspot router unit (Franklin T10) available from T-Mobile for $90. So I suppose that accounts for the $100 higher price on the first year.  
But yeah nevertheless this really doesn’t reflect well on Calyx.

---

## Post 15 by @anon63378630 — 2023-04-13T01:00:22Z

> [@dumpster](#):
>
> so I suppose that accounts for the $100 higher price on the first year.

the ConnectAll option is $105 for the same Franklin T10 and first month of service, so yes if you fully account that way it is $270 for the first year and $180 every year after.

---

## Post 16 by @Niek-de-Wilde — 2023-04-13T05:25:45Z

Then again, even if they become faster at update, I wouldn’t know what calyx would bring to the table over Graphene OS atm.

---

## Post 17 by @ph00lt0 — 2023-04-13T09:27:34Z

Exactly CalyxOS doesn’t provide anything that GrapheneOS does not. GrapheneOS simply is a better alternative so this should be the recommendation. If people chose not to follow that, that’s fine, but why recommend things that are not simply the best. Don’t make it more complex to the vistor just focus on good and easy solutions.

I am not even recommending CalyxOS for Fairphone. MicroG is a hit or miss and will mostly just limit your experience in a bad way.

DivestOS is there only because it has support for other devices as well and provides some hardening. I happily use this on a secondary device, but given there is no play services it for most people won’t be so useful.

---

## Post 18 by @Regime6045 — 2023-04-13T11:26:38Z

Mainly support for one single non-Google phone (the Fairphone). Not sure if it’s worth mentioning that anywhere.

---

## Post 19 by @jonah — 2023-04-13T12:55:53Z

Also the SHIFT6mq.

@Niek-de-Wilde my perspective is that if it isn’t _worse_ than GrapheneOS then it should be added to provide user choice.

Either that, _ **OR** _ we need to add the ways in which GrapheneOS is better to the Android OS criteria. We can look at [Should You Use GrapheneOS or CalyxOS? - Privacy Guides](https://blog.privacyguides.org/2022/04/21/grapheneos-or-calyxos/#update-frequency) but the updates were our main complaint, so if they are fixed it’s difficult to say why exactly CalyxOS shouldn’t be recommended. We shouldn’t be rejecting projects based on… gut feeling? I suppose we should do an updated in-depth look since that article is a year old.

---

## Post 20 by @anon63378630 — 2023-04-13T15:37:20Z

The two extra supported devices by Calyx don’t even handle verified boot correctly, FP4 trusts test-keys and axolotl has Qualcomm secure boot disabled.

[https://divestos.org/pages/faq#deviceBootloader](https://divestos.org/pages/faq#deviceBootloader)

---

## Post 21 by @ph00lt0 — 2023-04-13T15:46:54Z

> [@jonah](#):
>
> Either that, _ **OR** _ we need to add the ways in which GrapheneOS is better to the Android OS criteria. We can look at [Should You Use GrapheneOS or CalyxOS? - Privacy Guides](https://blog.privacyguides.org/2022/04/21/grapheneos-or-calyxos/#update-frequency) but the updates were our main complaint, so if they are fixed it’s difficult to say why exactly CalyxOS shouldn’t be recommended. We shouldn’t be rejecting projects based on… gut feeling? I suppose we should do an updated in-depth look since that article is a year old.

Simply for the reason that GrapheneOS offers further security options in comparison to CalyxOS and has sandboxed play services. An example of a security feature is the firewall that GrapheneOS has (and divestOS has this too!) CalyxOS does have a Firewall but is not build as robust as done in GrapheneOS and DivestOS I have been thought. I also do not believe CalyxOS offers the in the blog listed Additional Hardening ([Should You Use GrapheneOS or CalyxOS? - Privacy Guides](https://blog.privacyguides.org/2022/04/21/grapheneos-or-calyxos/#additional-hardening))

---

## Post 22 by @jonah — 2023-04-13T16:27:39Z

> [@anon63378630](#):
>
> axolotl has Qualcomm secure boot disabled.

Unless I misunderstand what you’re saying, how could this be true? Android has required verified boot from OEMs since like… Android 8? I think?

---

## Post 23 by @anon63378630 — 2023-04-13T16:29:18Z

Oh verified boot is still there, you can just replace the bootloader entirely.

Most vendors do not implement it correctly at all, but it was actually a deliberate choice for axolotl because they wanted it for Linux phone/postmarketOS-eqsue development.

---

## Post 24 by @jonah — 2023-04-13T16:48:29Z

I guess I don’t understand what the implication of what you’re saying about axolotl actually is.

> [@anon63378630](#):
>
> FP4 trusts test-keys

I’m also trying to figure out what makes this problematic. CalyxOS tells me that because their factory images and OTA updates are signed with their private keys this is a non-issue, because OTA updates are checked against their [release key](https://source.android.com/docs/core/ota/sign_builds) and factory images can’t be installed without unlocking the bootloader again. What is the risk to the end-user? If anything, in theory we _should_ be recommending CalyxOS to Fairphone users because this seems like a potential improvement over their stock ROM.

> [@ph00lt0](#):
>
> I also do not believe CalyxOS offers the in the blog listed Additional Hardening ([Should You Use GrapheneOS or CalyxOS? - Privacy Guides](https://blog.privacyguides.org/2022/04/21/grapheneos-or-calyxos/#additional-hardening))

Honestly it has not really been demonstrated why this is relevant to most people. It’s nice to have, but if CalyxOS isn’t _worse_ than AOSP in general, while providing better privacy protections than AOSP, it’s unclear to me why we wouldn’t want to present it as an option.

---

## Post 25 by @ph00lt0 — 2023-04-13T17:27:47Z

> Honestly it has not really been demonstrated why this is relevant to most people. It’s nice to have, but if CalyxOS isn’t worse than AOSP in general, while providing better privacy protections than AOSP, it’s unclear to me why we wouldn’t want to present it as an option.

well it really is, MicroG is adding more parties to trust, but not only that also doesn’t offer you the same features as GMS does and is not as stable. It’s just a worse experience I don’t see why we would recommend that especially given the security is lower.

On the test key story:

> **[Bootloader // AVB keys used in ROMs for Fairphone 3+4](https://forum.fairphone.com/t/bootloader-avb-keys-used-in-roms-for-fairphone-3-4/83448/4)**
>
> @FairphoneHulk I have just downloaded the latest iodeOS for FP3 (iode-2.4-20220401-FP3.zip) and verified that while it uses release keys for the system, it uses the insecure public test keys for verified boot: python verify_signature.py --file...

---

## Post 26 by @anon63378630 — 2023-04-13T17:34:51Z

re: microG

Per my [https://divestos.org/misc/mg.txt](https://divestos.org/misc/mg.txt)

> - Has unclear potential to leak location to apps without location permission
> - “Fused Locations: Does not honor AppOps!”
> - [Implementation status · microg/GmsCore Wiki · GitHub](https://github.com/microg/GmsCore/wiki/Implementation-Status)

re: secure boot  
secure boot is what underpins verified boot, you can effectively bypass it if you can replace the bootloader

re: test-keys for verified-boot  
it may be possible for both a proximate and remote attacker to write valid data and signed metadata even when an alternate key is in use, it is unclear and no one has yet tested/researched it yet  
but it is definitely known worse if you’re running the stock OS which is test-key signed.

and yes there is a distinction between signing keys for system/otas and the verified boot metadata  
edl access or an exploit would be necessary to gain write access

---

## Post 27 by @jonah — 2023-04-13T17:52:01Z

microG is not mandatory in CalyxOS, is it? My recollection is that it asks during install.

> [@ph00lt0](#):
>
> On the test key story:
> 
> [Bootloader // AVB keys used in ROMs for Fairphone 3+4 - #4 by SkewedZeppelin - The Products - Fairphone Community Forum](https://forum.fairphone.com/t/bootloader-avb-keys-used-in-roms-for-fairphone-3-4/83448/4)

I read that already, it doesn’t answer the question I asked.

---

## Post 28 by @anon63378630 — 2023-04-13T17:53:12Z

> microG is not mandatory in CalyxOS, is it? My recollection is that it asks during install.

This just goes full circle then, use GrapheneOS if you have a Pixel or DivestOS if you have a FP2/FP3/FP4.

That only leaves axolotl that they support, which I probably will too eventually.  
Mind you SHIFT6mq is a _still available for sale_ 600eur phone with a 5 year old end-of-life [SoC](https://en.wikichip.org/wiki/qualcomm/snapdragon_800/845). Meanwhile the Pixel 6a is half the price and supported until July 2027 and doesn’t have a broken bootloader.

---

## Post 29 by @jonah — 2023-04-13T18:08:53Z

I guess what is still unclear to me is why DivestOS should be listed and CalyxOS should not. My preference would probably be to list Graphene, Divest, and Calyx as they all provide advantages over stock. It’s not a competition.

---

## Post 30 by @anon63378630 — 2023-04-13T18:11:37Z

My qualm here is the numerous issues that they do not document and users end up thinking they have a secure device.

To recap:

- [Selling](https://calyxinstitute.org/membership/calyxos) near [end of life Pixel 4a 5G](https://endoflife.date/pixel) without any such note (at an egregious price too)
- Supporting the FP4 as secure despite:
  - [trusting](https://forum.fairphone.com/t/bootloader-avb-keys-used-in-roms-for-fairphone-3-4/83448/11) test-keys for verified boot
  - having both Qualcomm ([2020-11](https://wikimovel.com/index.php/Qualcomm_Snapdragon_750G)+3=2023-11) and Linux 4.19 ([2024-12](https://kernel.org/category/releases.html)) support end before Fairphone’s claimed support date of [2026](https://support.fairphone.com/hc/en-us/articles/4404656100753-Fairphone-4-FAQ)

- Supporting axolotl as secure despite already being an end-of-life ([2018](https://en.wikichip.org/wiki/qualcomm/snapdragon_800/845)+3=2021) insecure device and [not](https://forum.shiftphones.com/threads/vollstaendiges-backup-ueber-qualcomm-edl-mode.4777/#post-44656) having Qualcomm secure boot.
- Potential [issues](https://github.com/microg/GmsCore/wiki/Implementation-Status) with microG leaking location
- Taking up to a [week](https://divestos.org/misc/ch-dates.txt) for WebView/browser updates

they can handle this, they can document this, they can do better: they [received](https://www.youtube.com/watch?v=2aRBLx6h1Ms) between $4-6 [million](https://startsmall.llc/) dollars last year.

---

## Post 32 by @jonah — 2023-04-13T18:37:12Z

The risk with the SHIFT6mq disabling Qualcomm secure boot seems to be the same risk as Fairphone allowing test keys: Minimal, because as far as I can tell the bootloader still can’t be just completely replaced without unlocking the bootloader first?

---

## Post 33 by @anon63378630 — 2023-04-13T18:38:06Z

> because as far as I can tell the bootloader still can’t be just completely replaced without unlocking the bootloader first?

This is wrong.

With secure boot disabled the generic/unsigned Qualcomm firehose files will allow flashing regardless.

EDL access allows flashing and dumping disk+RAM.

They even say so right here: [SHIFT6mq - vollständiges Backup über Qualcomm EDL Mode | SHIFTPHONES](https://forum.shiftphones.com/threads/vollstaendiges-backup-ueber-qualcomm-edl-mode.4777/#post-44656)

> SHIFT STAFF  
> But the 6mq is SB-Off, so a generic Firehose loader can be used.  
> If you use EDL from bkerler, then it works.  
> Memory dumps are also possible with it

---

## Post 34 by @jonah — 2023-04-13T18:45:45Z

> [@anon63378630](#):
>
> EDL access allows flashing

What’s the actual risk here for CalyxOS users, can the bootloader be replaced with one which doesn’t verify boot while keeping user data intact? I don’t think dumping disk is a concern with encryption.

---

## Post 35 by @anon63378630 — 2023-04-13T19:06:37Z

nickcalyx:

> where I come from, if someone makes a claim without evidence, it’s pretty normal and uncontroversial to say oh cool, do you have evidence for that claim ?

I really appreciate you thinking I’m spreading nonsense even when I clearly link sources.

---

## Post 36 by @ph00lt0 — 2023-04-13T19:18:11Z

If you can change the OS you can also make it upload the data after the user unlocked it. It doesn’t need to happen at the same time.

---

## Post 37 by @jonah — 2023-04-13T19:22:15Z

> [@ph00lt0](#):
>
> If you can change the OS you can also make it upload the data after the user unlocked it.

I’m not debating that, I’m asking whether the “change the OS” part is possible in the first place.

---

## Post 38 by @ph00lt0 — 2023-04-13T19:23:25Z

When the bootloader is unlocked anyone with physical access to the device could alter the OS. And without it being unlocked you could still flash updates, if they are signed with the same key it should be accepted and if you use test keys, well anyone can.

---

## Post 39 by @jonah — 2023-04-13T19:28:24Z

> [@ph00lt0](#):
>
> When the bootloader is unlocked

The bootloader isn’t unlocked, so that is irrelevant.

> [@ph00lt0](#):
>
> and if you use test keys, well anyone can.

Test keys aren’t used for updates, which we just covered here earlier.

---

## Post 40 by @ph00lt0 — 2023-04-13T19:29:58Z

In that case I probably do not understand your question.

---

## Post 41 by @anon63378630 — 2023-04-13T19:34:13Z

> Test keys aren’t used for updates, which we just covered here earlier.

OTA update signatures or Bootloader lock state isn’t what is being talked about here.

As I mentioned, it is unclear but possible that a remote attacker can gain privs via exploit and then write data and valid signatures to verified boot protected partitions as the bootloader may still accept test-keys on boot even with a user secondary key installed.

And regardless with physical access and EDL access via available signed firehose or unsigned firehose via disabled secure boot any partition can be flashed or RAM dumped while running.

These are three distinct issues.

These issues are not the fault of Calyx, I just want to see them document them.

---

## Post 42 by @jonah — 2023-04-13T20:38:40Z

**Update** : They said they would test this.

(After discussing in their Matrix room) Calyx doesn’t seem to want to look into this, so I think I’ll just give up on this thread unless they respond. It’s clear that I’m the only one on the team advocating for them anyways, so I guess I’ll leave it up to public opinion and mark this thread as rejected for now.

* * *

I agree that their marketing that CalyxOS “cannot be tampered without your knowledge” creates a false sense of security for users, **if** the reality is that any partition could be overwritten with EDL mode and a special cable, regardless of whether they consider that a “realistic” threat or not.

---

## Post 43 by @anon63378630 — 2023-04-13T21:18:22Z

> [@jonah](#):
>
> special cable

EDL doesn’t need a special cable at all. It can be accessed via:

- volume buttons from poweroff (depending on device)
- fastboot menu (depending on device)
- when the device crashes/panics (depending on device)
- shorting pins on the MMC (always available).

An open-source reimplentation tool is here: [GitHub - bkerler/edl: Inofficial Qualcomm Firehose / Sahara / Streaming / Diag Tools :)](https://github.com/bkerler/edl)  
and firehose (n-stage bootloaders) are here: [GitHub - bkerler/Loaders: EDL Loaders](https://github.com/bkerler/loaders)

---

## Post 44 by @dngray — 2023-04-14T12:53:03Z

> [@anon63378630](#):
>
> They are currently selling the Pixel 4a 5g for $550 despite only having 6 months left of support from Google.

That’s something I noticed a while ago, and it really annoyed me when I first saw it

> [@anon63378630](#):
>
> Absurd markup aside or deranged notation that it is a “donation”: I think it is asinine they are selling a near EOL phone without ANY such note of it being so.

I also think it’s dishonest to call something a donation when it’s not. Donation has a very specific meaning in a legal/financial sense and is often tax deductible.

> [@jonah](#):
>
> Also the SHIFT6mq.

I get massive marketing vibes with the whole [“German Made” thing](https://wunderkey.de/en/blogs/magazin/because-quality-is-key-wie-viel-ist-das-label-made-in-germany-heute-noch-wert).

> **Which products are allowed to carry the" Made in Germany "label?**
> 
> When exporting Products from one country to another they often have to be labeled with the country of origin label. Nowadays, many products are the result of a large number of parts that come from many different countries and are ultimately assembled in a third country. In these cases it is not so easy to name the country of origin and there are different rules for determining the “right” country of origin. In general, articles only change their country of origin if the addition of a new material or work step represents a significant change (for example the processing from a wheel to a car). Nowadays most machines and products with the designation “Made in Germany” already have 40 to 50 percent foreign parts. In some industrial plants and systems, it is even 80 percent. Therefore, an increasing number of products are losing the right to officially carry the “Made in Germany” label. Many German companies are now demanding that the requirements for the “Made in Germany” label are lowered in order to be able to use the positive image of the label abroad. Only a few products continue to be 100% “Made in Germany”.

The other thing is the device has a fairly old [Snapdragon 845](https://en.wikichip.org/wiki/qualcomm/snapdragon_800/845) from 2018 and less security than a pixel, for example Secure Elements, Titan etc.

I can see what Fairphone/SHIFT6mq are trying to do, but it’s simply not possible to provide long term support to a phone beyond what the SoC will grant during their support period. These phones are not cheap either. The shiftmq starts at €577.00.

I think the best bet for sustainability is to just buy a pixel, and if you break it take it to a repair shop (or repair it yourself if you have the tools, want to take the risk). There are plenty of spare parts and documents around.

Best bet though is to buy a durable case though that will likely prevent any accidental damage.

---

## Post 45 by @jonah — 2023-04-14T13:21:36Z

> [@dngray](#):
>
> Donation has a very specific meaning in a legal/financial sense and is often tax deductible.

The membership cost minus the fair market value of the products is tax deductible, and Calyx Institute is a 501(c)(3) non-profit, I don’t think we have to straight up misrepresent Calyx here to argue against them.

The Google Pixel 7 is available in a mere [17 countries total](https://en.wikipedia.org/wiki/Pixel_7), so I do see the value in additional OS options for people.

---

## Post 46 by @ph00lt0 — 2023-04-14T15:17:17Z

I do not think the fairphone and SHIFT are available in more countries tho.

For other phones mode widely available we have DivestOS or iPhone. If none available I am not sure what is worse. I mean if you are in china is LinageOS worse than any backdoored OS?

---

## Post 47 by @jonah — 2023-04-14T15:40:01Z

> [@ph00lt0](#):
>
> I do not think the fairphone and SHIFT are available in more countries tho.

Guessing isn’t really constructive here either. I am extremely tired of people in general saying random things on this forum without bothering to look anything up, just because they don’t like something.

Fairphone 4 is available in 34 countries (most of the EU), Shift ships to 26.

I’m aware we have DivestOS on the site:

> [@jonah](#):
>
> I guess what is still unclear to me is why DivestOS should be listed and CalyxOS should not.

---

## Post 48 by @ph00lt0 — 2023-04-14T16:01:42Z

The page that you linked earlier. was outdated.

The pixel f.x. is also available in Poland, see [https://allegro.pl/listing?string=google%20pixel%207](https://allegro.pl/listing?string=google%20pixel%207)  
or denmark: [Google Pixel 7 smartphone 8/128 GB (Obsidian) | Elgiganten | Elgiganten](https://www.elgiganten.dk/product/mobil-tablet-smartwatch/mobiltelefon/google-pixel-7-smartphone-8128-gb-obsidian/525086)

Pretty sure you can get it in most EU countries as well. It’s a bit strange that you call me out for this while you didn’t even link something up to date yourself in the first place. I happy that you updated it., but I still doubt it is complete, many people I know all acros the EU have Pixels. This issue I am not familar with.

---

## Post 49 by @jonah — 2023-04-14T16:38:21Z

My point is that we get messages all the time from people saying “I live in _x_ and can’t get a Pixel” and I’m frustrated that the only solution we offer is a $300-$800 phone which has barely any worldwide availability.

> **[Learn about devices & services available in your region - Google Store Help](https://support.google.com/store/answer/2462844?hl=en)**
>
> Here's where you can find devices available for purchase on the Google Store. To buy a device from the Google Store, your shipping address must be in the same region as the Google Store site you want

---

## Post 50 by @anon43879818 — 2023-04-14T16:56:26Z

> [@jonah](#):
>
> I’m frustrated that the only solution we offer is a $300-$800 phone which has barely any worldwide availability.

Maybe we need to remark more in the recommended section that you could buy/use a phone that is supported by DivestOS in their golden devices section. Just to improve that situation a little bit

Edit: in the android devices section specifically [Android - Privacy Guides](https://www.privacyguides.org/en/android/#android-devices)

---

## Post 51 by @ph00lt0 — 2023-04-14T18:04:55Z

I think this suggestion of @anon43879818 is a good idea.

And i get your frustation with that @jonah it makes sense. I just don’t think these phones w/ calyxOS are the solution. They are not available either in countries in Asia f.x. where I think this problem is more significant.

---

## Post 52 by @dngray — 2023-04-14T19:16:41Z

> [@jonah](#):
>
> I’m frustrated that the only solution we offer is a $300-$800 phone which has barely any worldwide availability.

The Fairphone and the shift are not innexpensive phones either.

---

## Post 53 by @InternetGhost — 2023-04-15T22:52:29Z

For what’s it worth, I would like to see CalyxOS listed if it qualifies. @jonah’s point about referencing a qualifying OS as long as it’s not worse than the AOSP is a good rule of thumb. By not recommending an option, especially when so few options exist, the implication is that the one that’s mentioned is not private enough to be trusted. Instead of interpreting Privacy Guides as being the best options that exist, it can be interpreted as being the only options that one should consider.

To the argument of not wanting to bog down users with too many choices, that doesn’t seem to be bogging down other pages that may list several options to consider. Also, I don’t think increasing the number of options from two to three is going to add too much analysis paralysis.

But also it seems to hinge on whether the the security updates keeping coming at a good rate.

---

## Post 54 by @gregfaefgear — 2023-04-16T01:56:07Z

Would it help at all if there was a reseller that shipped to countries google doesn’t sell in with a minimal markup? That way we don’t have to compromise on what OSs we reccomend, and more people get to use Graphene OS.

---

## Post 55 by @jonah — 2023-12-05T06:09:53Z

4 posts were split to a new topic: [NitroPhone](/t/nitrophone/15398)

---

## Post 59 by @anon63378630 — 2023-04-16T18:28:32Z

Since this thread is still going, I’d like to point out that Chromium 112.0.5615.101 was released two days ago with a [zero day fix](https://chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop_14.html) and CalyxOS [still](https://review.calyxos.org/q/project:CalyxOS/platform_prebuilts_calyx_chromium_arm64) hasn’t updated to it despite being a simple version bump.

---

## Post 64 by @pganonymous — 2023-09-30T04:15:07Z

The Privacy Guides website is well developed but I feel its current treatment of Calyxos is unfair.  
It contributes towards pitting Open Source projects that respect and promote the privacy of the end user against each other and spreads information that is false about the operating system. I will be making a 3 pronged criticism of the [Privacyguides.net](http://Privacyguides.net) stance on Calyxos.

First, the signature spoofing on Calyxos is more secure than any other implementation across all roms since it only works when using microg. No other android package other than microg and fakestore can enable signature spoofing making this feature safe and secure for the end user. This change is open sourced and can be verified on the Calyxos Gitlab.

Second, Calyxos has more user friendly privacy features than any other rom. During install the user is prompted to install a free VPN provided by Calyx, Tor and several other open source apps that add privacy to the operating system. Also, Calyxos is patched to allow the Hotspot to use the system VPN so connected devices can be secure. And lastly, Calyxos has a firewall app built in that links the system firewall settings into an easy to use application.

Third, unlike its other open source compatriots Calyxos only uses open source projects to provide its software support. Microg, Seedvault, even the browser are all open source unlike some of the compatibility features of other open source projects that offer the option to install closed sourced play services.

I hope Calyxos can be reconsidered as a suggested operating system for Privacyguides. While its not hardened like its compatriots it is more private in many ways and enables user privacy by not using Play services. It also, maintains the security model of android and is consistent with its monthly updates.

---

## Post 65 by @pinkandwhite — 2023-09-30T04:38:22Z

I guess the biggest issue that’s been mentioned on the forums before is microG - [here’s](https://discuss.privacyguides.net/t/divestos-unprivileged-microg-implementation/13287) a discussion from the DivestOS dev on why there’s issues to consider with microG vs GOS’ sandboxed google play.

Also I’m not entirely sure if they still use it ([the calyx website says they do at least](https://calyxos.org/features/) but if they no longer do this point is moot) but the Bromite browser hasn’t had an update since December last year (as per the bromite github repo) which is Not Good At All considering it’s what’d be used for the webview. Having an outdated browser is _really bad_ and I hope that the site is just outdated and they’ve actually moved to e.g., Cromite.

Providing the provisions to “easily” install private applications is kinda moot when there are issues with that - I don’t have a source for this beyond remembering a discussion from the GOS matrix rooms, but if I’m remembering that discussion correctly, the included apps with Calyx are sometimes outdated. If you have to update the apps basically immediately after installing, then you might as well go to the up to date source anyway?

---

## Post 66 by @dngray — 2023-09-30T04:51:55Z

> [@pganonymous](#):
>
> Second, Calyxos has more user friendly privacy features than any other rom. During install the user is prompted to install a free VPN provided by Calyx,

We’re not here to sell Calyx’s other products.

> [@pganonymous](#):
>
> Tor and several other open source apps that add privacy to the operating system.

Blindy suggesting Tor usage without proper thought is not a good idea.

> [@pganonymous](#):
>
> Also, Calyxos is patched to allow the Hotspot to use the system VPN so connected devices can be secure. And lastly, Calyxos has a firewall app built in that links the system firewall settings into an easy to use application.

So does regular android. We think the ‘INTERNET’ permission, is more intuitive, and has had less issues in the past with by-passes. The main thing is that Calyx doesn’t really run anywhere GrapheneOS doesn’t (except for a couple barely supported devices anyway).

And yes, @pinkandwhite does point out, that you might as well install the other apps from their source where they are up to date.

> [@pganonymous](#):
>
> Third, unlike its other open source compatriots Calyxos only uses open source projects to provide its software support. Microg, Seedvault, even the browser are all open source unlike some of the compatibility features of other open source projects that offer the option to install closed sourced play services.

Microg, is still google services, it’s just an open implementation that might be lacking at times it really has no bearing on privacy however. Also: [Privileged eSIM Activation Application](https://blog.privacyguides.org/2022/04/21/grapheneos-or-calyxos/#privileged-esim-activation-application), is another reason we prefer the sandboxed play services approach.

---

## Post 67 by @pganonymous — 2023-09-30T04:55:43Z

The microg vs sandboxed google play services debate is moot because both rely on google binaries and communicate with google. But I the user trust microg’s open source implementation of those binaries more than I trust google’s closed source implementation because I can control which apps use microg via an in app toggle. I can also control whether my device is registered with google via a toggle. Microg also, doesn’t send device identifies afaik whereas sandboxed google play does.

Calyxos uses their own chromium fork with the patches from Bromite, now chromite, added ontop which means the base browser/webview was always secure even if bromite was no longer being updated.

Your final point about preinstalled apps is moot when considering that even on stock preshipped apps are out of date and require an update. But usually nowadays they ship the most up to date apps.

---

## Post 68 by @dngray — 2023-09-30T04:57:29Z

Privacy Guides is also not about listing “everything” it’s about listing the most compelling options, otherwise we would potentially have a list with hundreds of items.

At this point in time, we don’t see a reason to use CalyxOS over GrapheneOS, when GrapheneOS has things Calyx does not, and largely Calyx just has some pre-installed apps.

---

## Post 69 by @pganonymous — 2023-09-30T05:18:17Z

I can list multiple features of Calyx that aren’t on Graphene. But my point is comparing the two does a disservice to what each has to offer. Calyxos is still better than stock for privacy. This website is called PRIVACYGUIDES not SECURITYGUIDES. Multiple options should be included to accomadate multiple use cases. Also, the apps at startup like tor browser, orbot, riseup vpn, calyx vpn are not preinstalled. Its all user choice.

Features Calyxos has:

1. VPN over Hotspot
2. Microg which doesn’t send identifiers to google. Hence no advertising ID or tracking unlike sandboxed google play services.
3. Datura Firewall. Literally a frontend for hidden system settings with more customizable network options like mobile network, wifi, background data and vpn access.
4. An android work profile that doesn’t rely on trusting another app to be a device administrator.

---

## Post 70 by @pganonymous — 2023-09-30T05:22:55Z

Honestly, I have spent time using both graphene and Calyxos. Both are very different projects and picking one over the other is honestly ridiculous. Also, how is divestos listed when half its builds are untested? Calyxos should be listed before divestos.

---

## Post 71 by @anon63378630 — 2023-09-30T05:47:24Z

Not going to say you should or shouldn’t use CalyxOS, but I have some corrections here:

> [@pganonymous](#):
>
> First, the signature spoofing on Calyxos is more secure than any other implementation across all roms since it only works when using microg.

- CalyxOS has a permission check only used by their GmsCore fork, a package ID check, and only allows spoofing the Google signature

- DivestOS is opt-in, checks microG package ID + targetSdk + versionCode + certificate hash, and only allows spoofing the Google signature

> [@pganonymous](#):
>
> Also, Calyxos is patched to allow the Hotspot to use the system VPN so connected devices can be secure.

This is a LineageOS feature. And has arguable downsides such as diminished state partitioning between devices.

> [@pganonymous](#):
>
> And lastly, Calyxos has a firewall app built in that links the system firewall settings into an easy to use application.

This is also just a centralized UI for the LineageOS data restrictions, you can see a very early version of it here: [https://review.lineageos.org/q/topic:"ten-firewall"](https://review.lineageos.org/q/topic:%22ten-firewall%22)  
Granted, it has obvious additions over the years, features like force deny cleartext is nice.  
But these restrictions have had numerous leaks over the years, see recently: [https://review.lineageos.org/q/topic:"13-firewall-bypassable-vpn-fix"](https://review.lineageos.org/q/topic:%2213-firewall-bypassable-vpn-fix%22)

> [@pganonymous](#):
>
> is prompted to install a free VPN provided by Calyx

People shouldn’t be encouraged to route all their traffic through a SPOF without good reason.

> [@pganonymous](#):
>
> Third, unlike its other open source compatriots Calyxos only uses open source projects to provide its software support.

Last I checked, my DivestOS is king as far as removing proprietary junk.  
CalyxOS has actually been adding it back:

- [https://review.calyxos.org/q/topic:gcam-ext](https://review.calyxos.org/q/topic:gcam-ext)
- [https://review.calyxos.org/q/topic:wifi-calling](https://review.calyxos.org/q/topic:wifi-calling)

It must also be noted that microG itself is open-source, but every app that talks to it does so using the proprietary Google Play Services library.

---

## Post 72 by @anon63378630 — 2023-09-30T05:48:51Z

> [@pinkandwhite](#):
>
> Having an outdated browser is _really bad_ and I hope that the site is just outdated and they’ve actually moved to e.g., Cromite.

CalyxOS uses patches from Bromite and Cromite and Brave but is not outdated: [https://divestos.org/misc/ch-dates.txt](https://divestos.org/misc/ch-dates.txt)

> [@dngray](#):
>
> Also: [Privileged eSIM Activation Application](https://blog.privacyguides.org/2022/04/21/grapheneos-or-calyxos/#privileged-esim-activation-application), is another reason we prefer the sandboxed play services approach.

It should be noted that DivestOS has had Google-free eSIM activation for a few weeks thanks to OpenEUICC: [https://divestos.org/pages/news#2023-09](https://divestos.org/pages/news#2023-09)

---

## Post 73 by @anon63378630 — 2023-09-30T05:53:43Z

> [@pganonymous](#):
>
> Microg which doesn’t send identifiers to google.

It still maintains a longterm persistent identifier for push registration.

> [@pganonymous](#):
>
> Also, how is divestos listed when half its builds are untested?

lol, half of 170 is still 85:

- Tested Working: 19
- Reported Working: 49
- Very Likely Working: 42
- Likely Working: 24
- Mostly Working: 9
- Broken: 5
- Untested: 19
- Total: 167

---

## Post 74 by @jonah — 2023-12-05T06:06:55Z

8 posts were split to a new topic: [Privacy vs Security Recommendations](/t/privacy-vs-security-recommendations/15396)

---

## Post 75 by @anon62252234 — 2023-09-30T09:15:35Z

> [@dngray](#):
>
> Also: [Privileged eSIM Activation Application](https://blog.privacyguides.org/2022/04/21/grapheneos-or-calyxos/#privileged-esim-activation-application), is another reason we prefer the sandboxed play services approach.

I understand CalyxOS enabling the proprietary Google app by default is a problem, but how come GrapheneOS requires installing the full (albeit sandboxed,) Google Play Services just to add an eSIM? That is also very wrong in my opinion.

> [@anon63378630](#):
>
> It should be noted that DivestOS has had Google-free eSIM activation for a few weeks thanks to OpenEUICC: [News - DivestOS Mobile](https://divestos.org/pages/news#2023-09)

Now that is nice!

---

## Post 76 by @Sharply — 2023-09-30T11:19:30Z

Have you seen [this table](https://eylenburg.github.io/android_comparison.htm)? CalyxOS seems to fall behind compared to GrapheneOS and DivestOS in a ton of aspects. I definitely wouldn’t consider it on the same level, I agree with PG not recommending it. There’s really no reason to when GrapheneOS and DivestOS exist and are just simply better. You’d be much better off using those 2 any day IMO.

---

## Post 84 by @jonah — 2023-12-05T06:04:07Z

Posting a question asked of us on Matrix for further discussion:

Is CalyxOS worth revisiting now that they’ve [added support for the Motorola G32](https://calyxos.org/news/2023/11/20/motorola-g32-g42-g52/), G42, and G52?

The argument being that the Motorola G32 is a ~$150 option brand new, whereas Pixel devices are $350 at minimum from a trusted source (Google Store), $499 minimum for a current-gen product, and still ~$200 minimum even on the used marketplace.

* * *

The _real_ question is: All this being the case, do we prefer CalyxOS over DivestOS? Previously we did, which is why our ranking was GrapheneOS \> CalyxOS \> DivestOS, and we only removed CalyxOS once their device support was identical to GrapheneOS.

That being said, I’m not sure if this is actually wise in the present day, DivestOS might be preferable to CalyxOS in all aspects anyways, and then this doesn’t matter as much.

That seems to be the general agreement above, although not unanimously [[1](https://discuss.privacyguides.net/t/calyxos-android-rom/11614/53), [2](https://discuss.privacyguides.net/t/calyxos-android-rom/11614/64)]. In which case I’d ask, what phone would _you_ recommend someone with a $100-$300 budget buy? Maybe that can be a separate thread.

---

## Post 85 by @anon63378630 — 2023-12-05T06:24:23Z

I wrote some stuff but I’ll keep it short and (bitter)sweet to not repeat points already made:  
Ultimately I’d rather see people on GOS/DOS/COS over the other alternatives which quickly nosedive into lunacy.

---

## Post 86 by @anon46412288 — 2023-12-05T13:13:51Z

> **Old Post**
>
> There are reasons CalyxOS was removed from the recommended list but as of recent CalyxOS [gained support for three cheap Motorola phones - the Moto G32, Moto G42 and Moto G52.](https://calyxos.org/news/2023/11/20/motorola-g32-g42-g52/) Each of these are around 100-400$ (in terms of specs and combinations like 4GB+64GB, 8GB+128GB etc) but are nevertheless really cheap compared to the Google Pixel (and Fairphone, which Calyx also supports).
> 
> A bigger thing to note is that Motorola phones are available in more markets than the Google Pixel. Especially countries in South Asian regions.
> 
> CalyxOS is not the absolute best in terms of privacy gains and security hardening but is _fundamentally better_ than the stock OS that comes on these phones (with Privileged Google Play Services on the stock OS). Also to note is that DivestOS is not available for these phones yet.
> 
> Considering the above, please consider re-adding CalyxOS.

+1 for CalyxOS, because it supports a relocked bootloader (which DivestOS doesn’t offer on some devices) and also because no matter the technical details, it is penultimately a better option than using the stock OS which comes with Privileged Play Services.

---

## Post 87 by @jonah — 2023-12-06T19:43:46Z

17 posts were split to a new topic: [LineageOS vs. CalyxOS vs. DivestOS](/t/lineageos-vs-calyxos-vs-divestos/15447)

---

## Post 88 by @Naruto — 2023-12-05T16:10:17Z

I think if someone is wanting to use non-pixel phones (due to budget constraints) then in that scenario calxyOS offers a decent alternative to stock android.

We can look at recommending it with limitations.

---

## Post 90 by @Sharply — 2023-12-05T23:06:07Z

I would support Calyx being recommended, as long as its clarified that devices supported by GOS and DOS would probably be better covered by those respective operating systems.

---

## Post 91 by @anon46412288 — 2023-12-11T14:34:31Z

I too support recommending CalyxOS, even if it means we have to go over the limitations of it.

@jonah you should add it NOW! (considering majority of people here are in favour of it)

---

## Post 109 by @jonah — 2024-06-08T06:04:52Z

> [@jonah](#):
>
> Is CalyxOS worth revisiting now that they’ve [added support for the Motorola G32](https://calyxos.org/news/2023/11/20/motorola-g32-g42-g52/), G42, and G52?

So uh… where did we end up with this, folks?

Again my understanding is that CalyxOS was removed because it had equivalent device support to GrapheneOS, which is no longer the case and hasn’t been for quite a while.

I also think that if you want to use microG, CalyxOS provides a more complete user experience than DivestOS given that microG is a first-class citizen and not expressly “[unsupported](https://divestos.org/pages/broken#unsupported)” (nothing wrong with that though).

Do we want to purchase a Motorola phone to re-test CalyxOS? I think we are ~2 years out of date on the current state of things there :eyes:

> [@anon63378630](#):
>
> I’d rather see people on GOS/DOS/COS over the other alternatives

:+1:

---

## Post 110 by @anon48875053 — 2024-06-08T11:40:43Z

There is no reason to use CalyxOS over GrapheneOS if you have a Google Pixel.

Recommending phones with poor hardware and firmware security and short software support would be a huge disservice to the community. That’s not even considering that the hardware, such as the camera, screen, SoC, etc., will be a lot worse than even on budget Google Pixel devices.

I would rather add iOS to the recommendations over CalyxOS and these devices. CalyxOS has the resources to compete with GrapheneOS or even be better than GrapheneOS; they can do a lot better, but I’m not sure why they don’t. But for now, there is no real reason to use it.

---

## Post 111 by @jonah — 2024-06-08T12:05:33Z

> [@anon48875053](#):
>
> if you have a Google Pixel.

pls re-read discussion :rofl:

---

## Post 112 by @anon48875053 — 2024-06-08T12:09:04Z

> [@jonah](#):
>
> pls re-read discussion :rofl:

First paragraph is about using CalyxOS on a Pixel device. The second one is about phones like Motorola. Both add up to the conclusion that CalyxOS shouldn’t be recommended.

---

## Post 113 by @anon73886004 — 2024-06-08T12:31:54Z

My understanding is not that Motorola would be recommended over Pixel. Rather, that Calyx would be recommended in the event that a Motorola device is more accessible to you. If both money and availability are not a factor, then Pixel/GOS would still be recommended.

---

## Post 114 by @benm — 2024-06-09T01:43:41Z

If an AOSP operating system supports more devices than the Pixel and that ASOP is better for privacy than the stock version that would be installed, I think it should be recommended with the caveat that it only applies to those with otherwise unsupported devices and the real recommendation is to get a Pixel and use Graphene.

Lots of people are locked in contracts for their phones and are not in the position to buy a new phone for 2+ years, so if their existing device is supported by a better OS I think it should be recommended.

To me this is the same principle as recommending Windows software choices even though Windows is not a private operating system. It is certainly better than using non-private software.

---

## Post 115 by @dngray — 2024-06-09T04:35:45Z

> [@benm](#):
>
> If an AOSP operating system supports more devices than the Pixel and that ASOP is better for privacy than the stock version that would be installed

Except that’s [not the case for Calyx](https://calyxos.org/docs/guide/device-support/) which is what this thread is about. In the past we haven’t recommended Fairphone for various reasons - the main one being support on firmware updates from Qualcomm which is something that effects all handset manufacturers using that SoC. The Moto phones there won’t be supported next year anyway.

> [@benm](#):
>
> Lots of people are locked in contracts for their phones and are not in the position to buy a new phone for 2+ years

Which has nothing to do with anything, because carrier locked phones generally have a locked bootloader as well, meaning you can’t put any other OS on there.

> [@benm](#):
>
> To me this is the same principle as recommending Windows software choices even though Windows is not a private operating system.

Don’t conflate things.

---

## Post 116 by @benm — 2024-06-10T01:10:50Z

The reason I framed it as I did was I was laying down criteria, not commenting specifically on Calyx being a good fit. In principle, an OS that is better than stock and compatible with more devices is worthy of consideration. I’m using Graphene and don’t have any hobby horse with Calyx.

---

## Post 117 by @anon46412288 — 2024-07-28T16:30:59Z

If I see the PG criteria :

 ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/0/0d869895fce02b98e6b30a760d4eb1584a52e998.png)

1. CalyxOS is open source
2. CalyxOS supports relocking on _all its supported devices_.
3. CalyxOS published their [first Android 14 build](https://calyxos.org/news/2023/10/14/android-14/) on 14th October, 10 days after A14 release and [released A14 generally to all supported Pixels on 26th October](https://calyxos.org/news/2023/10/26/android-14-update/), which is well within a month.
4. CalyxOS got A14 QPR3 on [June 13th in their security express channel, and rolled it out to stable on June 19th](https://calyxos.org/news/2024/06/13/june-qpr3-security-update/). It was [released on June 11th](https://support.google.com/pixelphone/thread/279468838/google-pixel-update-jun-2024?hl=en&sjid=10279463173279320853-NC), so well within the 14 days timespan.
5. CalyxOS got the most recent security patch (as of now, July 2024) [on 3rd of July, and rolled out to Stable on the 5th](https://calyxos.org/news/2024/07/03/july-security-update/). This patch was released on the [1st of July](https://source.android.com/docs/security/bulletin/2024-07-01). I will be honest and say this barely made it, but as noted above, they are very timely with updates.
6. CalyxOS doesn’t [promote or support root.](https://calyxos.org/docs/guide/security/security-faq/#is-it-possible-to-root-calyxos)
7. If we are talking strictly Play Services, then Calyx meets this criteria. It uses microG instead ofc, and it is opt in. The user has a choice to disable it on first setup.
8. No Play Services, so no system modification required.

So based plainly on the criteria, I have no reason to believe Calyx shouldn’t be recommended. At least for criteria 2, it actually beats DivestOS since DivestOS does have a handful of devices without bootloader relocking (example - [https://divestos.org/pages/devices#device-avicii](https://divestos.org/pages/devices#device-avicii)).

---

## Post 118 by @anon80779245 — 2024-07-28T21:24:28Z

I saw this in their documentatiom :

> CalyxOS gives F-Droid special privileges to streamline app updates, installs, and uninstalls.

This is totally useless and dangerous. F-droid basic perform background updates like a charm (no need to even open the app and no long download time like Obtainium and Aurora Store), this with only the autorisations to install apps.

Also, I wouldn’t say Microg is “opt-in”, as it is the recommended option.

> When you first start your phone, you will be given several options for the microg implementation on your device.

We recommend the default option, microG enabled, no Google Account, push notifications enabled.

BTW, I see no point in recommending CalyxOX, as Divest OS already supports a wide range of phones.

---

## Post 119 by @anon46412288 — 2024-07-29T01:39:26Z

> [@anon80779245](#):
>
> CalyxOS gives F-Droid special privileges to streamline app updates, installs, and uninstalls.

This is [outdated information](https://calyxos.org/news/2023/09/04/f-droid/). F-Droid is a user app on CalyxOS since release 4.12.2 and btoh Aurora Services and F-Droid Privileged Extension, while included, [are on their way to be removed](https://gitlab.com/CalyxOS/calyxos/-/issues/1943).

> Also, I wouldn’t say Microg is “opt-in”, as it is the recommended option

It is a recommended option, not a required option. You will get this screen on first setup where you have the option to choose to enable microG.

 ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/a/af768259604619117ebaed7a559962814deae11d.png)

---

## Post 120 by @Niek-de-Wilde — 2024-07-29T09:11:05Z

Just as a side note, the criteria list of things a product or service should have to be considered, checking all things on the list does not mean it will be recommended.

---

## Post 121 by @anon80779245 — 2024-07-29T20:15:37Z

> [@anon46412288](#):
>
> Aurora Services and F-Droid Privileged Extension, while included, [are on their way to be removed](https://gitlab.com/CalyxOS/calyxos/-/issues/1943)

I based myself on the documentation, which still points out that F-Droid is privileged, but I have now learned that Calyx actually sponsored F-Droid Basic, so good to know.

> [@anon46412288](#):
>
> It is a recommended option, not a required option. You will get this screen on first setup where you have the option to choose to enable microG.

Great, but saying you cannot run Youtube is a bit misleading. Sure, you cannot run the Youtube app, but the web app works very well.

BTW, does Calyx still has a privileged microg ? DivestOS doesn’t, which I think is a better way of doing things. Microg doesn’t need sensor access for exam

---

## Post 122 by @Breeze7846 — 2024-12-24T16:39:36Z

Well, it’s been a while since this thread was updated. What is the state if CalyxOS these days? Maybe this subject should be revisited and considered. Or, maybe PG could reach out to Calyx with their concerns

I realize it is not as good as grapheneOS. However, considering DivestOS just ended, maybe PG should reconsider listing it, with a disclaimer on it’s disadvantages. The reality is that many people cannot afford Pixel devices, and I think PG needs to consider that fact. A great recommendation (grapheneOS) isn’t useful if someone can’t actually use it.

---

## Post 123 by @user1 — 2024-12-24T17:07:17Z

CalyxOS supports only 6 devices more than GrapheneOS, it really is not a big step forward but if you find to have one of those devices then it could be a nice stock replacement. If you own a Pixel GOS is a no brainer.

---

## Post 124 by @nayiwij577 — 2024-12-24T17:08:39Z

DivestOS didn’t even compete with CalyxOS. Divest had broad device support, which was a big reason why it was suggested. Calyx supports just a few more devices compared to GrapheneOS (all of those are insecure though). DivestOS’s place would be better suited for LineageOS IF ANYTHING because they at least have some common focus on device compatibility despite the neverending list of issues with LineageOS.

---

## Post 125 by @anon42475305 — 2024-12-24T17:13:56Z

The difference is that DivestOS was itself exceedingly clear about it’s shortcomings, whereas CalyxOS is not.

Also, I’d refer to one of my previous comments, which I believe holds true for this situation too:

> [@Android Overview - Add language about Samsung's 7 years of software updates](https://discuss.privacyguides.net/t/android-overview-add-language-about-samsungs-7-years-of-software-updates/22419/9):
>
> Accessibility is a valid concern, but it is not a valid reason to mislead people by recommending an inferior product. PG has high standards for recommendations, which, if anything, encourages developers and manufacturers to strive to do better.

---

## Post 126 by @anon48875053 — 2024-12-24T17:24:03Z

> [@Breeze7846](#):
>
> The reality is that many people cannot afford Pixel devices, and I think PG needs to consider that fact.

Nobody is forcing them to buy new, used devices are a thing.

---

## Post 127 by @nayiwij577 — 2024-12-24T17:24:17Z

And Divest didn’t scam people with selling insanely marked up, near EOL devices without any notice of them being outdated.

---

## Post 128 by @anon64393658 — 2024-12-24T20:07:13Z

I’m not a custom ROM user so I don’t have a favorite in this fight.

But from an objective perspective, if CalyxOS meets all PG’s requirements and is usable on more devices than GOS I don’t see why it would be excluded.

Signal and SimpleX are both recommended. So is Tuta and Proton. Why not two Custom ROMs that offer better privacy and security than the stock OS’s on the devices they support?

Especially with the backing of the Calyx Foundation providing a level of likely longevity and support resources most FOSS projects inherently lack.

---

## Post 129 by @TheDoc — 2024-12-25T00:59:21Z

I can’t comment on whether CalyxOS should or shouldn’t be recommended, but @Breeze7846 still has a good point on affordability. Buying used Google Pixels are cheap-ish upfront, but if you account for how long they’re guaranteed to last you still run into an affordability issue because you’ll continuously need to play catch-up in buying phones more regularly. I wrote a more in-depth [price comparison](https://discuss.privacyguides.net/t/why-samsung-phones-are-considered-by-some-more-secure-than-the-other-stock-androids/21011/83) for anyone interested.

There was a thread on [budget android hardware](https://discuss.privacyguides.net/t/150-budget-android-hardware-suggestions-needed/15399) that didn’t reach an ideal conclusion. If Pixels are too expensive you were left with choosing between a Samsung Galaxy or DivestOS. Seeing that it’s now dead, maybe CalyxOS could take it’s place?

---

## Post 130 by @anon42475305 — 2024-12-25T01:10:43Z

A Pixel 8a can be had for something like 350 USD which comes out to less than 5 bucks a month for the 6 years and 4 months that it will be supported from now. Frankly that is quite accessible to most people even if the flagship Pixels are significantly more expensive. It makes much more sense to run a genuinely secure and private OS like GrapheneOS on that than to buy a marginally cheaper device running CalyxOS.

---

## Post 131 by @nayiwij577 — 2024-12-25T01:25:10Z

Signal and Simplex have both strengths and weaknesses compared to each other. Which is not the case for CalyxOS. It under-performs in most metrics to iOS, PixelOS, and even to OneUI.

---

## Post 132 by @anon64393658 — 2024-12-25T01:58:54Z

Are you really arguing that Calyx is less private than Pixel stock OS or OneUI?

Thats simply not a credible position.

---

## Post 133 by @asanyan — 2024-12-25T03:06:35Z

Only accurate in first world countries, and if you buy used you typically cannot split into multiple payments so it’s a big investment, and in something that won’t even have a warranty because it’s used.

---

## Post 135 by @anon42475305 — 2024-12-25T05:09:10Z

Please explain what you mean by first world countries, it’s an outdated term which referred to the US and its allies during the cold war. It’s not clear what countries you are referring to.

I fail to see how a cheaper device with zero privacy or security is better than a slightly more expensive device. Although I think 350 USD is great value for what you get.

---

## Post 136 by @anon21489307 — 2024-12-25T05:21:57Z

> [@anon42475305](#):
>
> 350 USD is great value for what you get.

In my country, a brand new Pixel 8a with warranty is selling at around $600 ± $50, not $350.

If money is the problem for the person, compared to Galaxy A16 5G that’s selling at $180 with 6 years support, or a year old phone A25 at the same price, but with 4 years support left and a lot better spec. These phone are no brainer to get a decent secure phone that can be used for a long time. And the price also goes down by the time, while the stock support time goes up, custom ROM makes much less sense, unless the benefit is real like GOS.

Pixel is not selling here officially, and also not many place around the globe, so the price goes up depending on the importer.

---

## Post 137 by @nayiwij577 — 2024-12-25T05:30:14Z

It certainly is. No need to exlcude iOS. By your metric iOS is just as bad as PixelOS. They only have first party tracking and its to the same degree. OneUI is worse but it still provides a better foundation for a reasonably good setup than CalyxOS.

(And I’m talking about the OS itself, excluding OEM services for a fair comparison. Many of the issues with stock os, that people criticise are entirely opt-in features/services)

---

## Post 138 by @anon5410820 — 2024-12-25T05:50:31Z

I agree with your point that Pixels aren’t cheap (they’re horribly difficult to get here and cost quite a bit), but I don’t see how this is a good argument for Calyx? Calyx generally have the same support as Graphene (except adding Fairphone, which are arguably even harder to get)

---

## Post 139 by @Breeze7846 — 2024-12-25T08:17:19Z

I don’t know enough about Calyx to make a hard recommendation on it specifically.

What I am saying is two things: first, having all eggs in one basket (GrapheneOS) is a bad idea. Anyone here remember what happened with Copperhead OS? That was, bluntly, a complete disaster.

Second, many people simply cannot get Pixel devices. The world is much bigger than American concerns. The Pixel is often not sold, or if it is, it costs an absurd amount of money that makes no sense when compared to practically any other model of android phone.

Maybe Calyx isn’t the answer. But surely there isn’t only _one_ answer; if there truly is, we are in big trouble because eventually Graphene will run into problems, one way or the other.

Generally, PG should only provide the best recommendations. **However, don’t let perfect be the enemy of good**. An example is Linux; even if a mainline distro isn’t Fedora or Qubes, it is still miles better than any Windows or OSX device.

---

## Post 140 by @asanyan — 2024-12-25T12:18:04Z

> [@anon21489307](#):
>
> Galaxy A16 5G that’s selling at $180

That’s much better though not as cheap where I live, but stock is also very bad for privacy. Pixel 8a goes for around $800 here and is hard to find.

> [@anon42475305](#):
>
> Please explain what you mean by first world countries, it’s an outdated term which referred to the US and its allies during the cold war. It’s not clear what countries you are referring to.
> 
> I fail to see how a cheaper device with zero privacy or security is better than a slightly more expensive device. Although I think 350 USD is great value for what you get.

Western Europe and US. Minimum wage in some countries can be as low as $250 or even less, and It’s not just “slightly” more expensive (see above). The fact that Calyx supports some Moto G devices is very attractive, because these devices are considerably cheaper (actually\* around $250 new)

EDIT to avoid doublepost: Does Calyx actually ship kernel updates for non-pixels? I remember one big gripe with Divest was the eol kernels. If so, I might actually buy a G52, seems pretty good value.

---

## Post 141 by @anon48875053 — 2024-12-25T12:37:56Z

> [@anon21489307](#):
>
> If money is the problem for the person, compared to Galaxy A16 5G that’s selling at $180 with 6 years support, or a year old phone A25 at the same price, but with 4 years support left and a lot better spec.

Both of those are complete garbage. Pixel 6a, 7a, and 8a completely blows them out of the water even when ignoring the privacy and security.

There is no way, that someone could use these devices for 6 years, they’re hardly usable just after launch.

> [@asanyan](#):
>
> If so, I might actually buy a G52, seems pretty good value.

A phone with pretty bad hardware that was released in 2022 with 3 years of software support, so it has less than 1 year left. Definently a good deal.

---

## Post 142 by @asanyan — 2024-12-25T12:58:40Z

> [@anon48875053](#):
>
> A phone with pretty bad hardware that was released in 2022 with 3 years of software support, so it has less than 1 year left. Definently a good deal.

The hardware isn’t that bad for the price, 6 GB of RAM is still usable. It’s only useless if Calyx can’t provide kernel/os updates after official support is over, which unfortunately seems to be the case.

---

## Post 143 by @anon21489307 — 2024-12-25T13:19:31Z

> [@anon48875053](#):
>
> Both of those[A16, A25] are complete garbage. Pixel 6a, 7a, and 8a completely blows them out of the water even when ignoring the privacy and security.

A25 is faster than iPhone 11 in every matrix, almost as fast as iPhone 12. I wouldn’t say that it’s slow or unusable. Also, a lot better camera, speakers, etc.

I could agree with A16. But if you’re not playing games, Facebook, messaging, and web browsing wouldn’t make it sweating.

For the money you paid, both are perfectly usable phone IMO, especially when Pixel is hard to find new, let alone the really old one like 6a or 7a, they’re the answer. If money is not the issue, go with Pixel.

---

## Post 144 by @BlackDog — 2024-12-25T13:22:27Z

> [@anon64393658](#):
>
> Especially with the backing of the Calyx Foundation providing a level of likely longevity and support resources most FOSS projects inherently lack.

This is the reason I went with Calyx. I reckoned they’d be more stable and longer-lived (and possibly not rely on a single or small number of devs?) than Graphene or Divest. Although I have seen recently that Proton has been giving funds to Graphene which is reassuring. Maybe I’ll give it a try in the new year.

---

## Post 145 by @anon21489307 — 2024-12-25T13:31:57Z

> [@asanyan](#):
>
> Does Calyx actually ship kernel updates for non-pixels?

It seems they update the kernel for non-Pixel devices, since the kernel is open source. But all the firmware are left out. Moto G52 for example:

> **[Install on moto g52](https://calyxos.org/install/devices/rhode/linux/#security-notes)**
>
> From a Linux computer

This device is possibly the best non-Pixel device that’s able to use with CalyxOS. But it’s rather old and more expensive than the current mid-range Galaxy, which has many years of support ahead of them.

* * *

Edit: It doesn’t seem like CalyxOS supports relocking the bootloader on non-Pixel devices (I don’t even know what SHIFT6mq phone is):

> **[Bootloader locking](https://calyxos.org/docs/guide/security/bootloader-lock/)**
>
> Details about bootloader re-locking

I would use a stock phone rather than any other ROMs without verity boot.

---

## Post 146 by @nayiwij577 — 2024-12-25T13:59:45Z

Despite the millions of dollars Calxy earns, it translates to zero privacy/security work over AOSP. And then it becomes hard to explain how Calyx was worse than Divest which was run by one guy.

---

## Post 147 by @nayiwij577 — 2024-12-25T14:02:15Z

> ..having all eggs in one basket (GrapheneOS) is a bad idea.

CalyxOS has this same problem. Whatever OS you choose, it will be a basket for your eggs.  
By this logic, drop your password manager.

> An example is Linux; even if a mainline distro isn’t Fedora or Qubes, it is still miles better than any Windows or OSX device.

No its not. Especially MacOS. But that’s for another topic.

---

## Post 148 by @asanyan — 2024-12-25T16:09:15Z

> [@nayiwij577](#):
>
> Then drop your password manager.

Apples and oranges. A (non-cloud) password manager doesn’t even need that much maintenance given that the crypto behind it is sound.

> [@nayiwij577](#):
>
> No its not. Especially MacOS.

For privacy? Yes it is. 100%.

> [@anon21489307](#):
>
> I would use a stock phone rather than any other ROMs without verity boot.

Fair enough, but it’s not like a device is immediately terribly insecure without verified boot. It may be a worthwhile tradeoff for better privacy given that the device still gets OS and kernel updates.

This is not offtopic.

---

## Post 152 by @crossroads — 2024-12-25T20:27:18Z

> [@anon21489307](#):
>
> Edit: It doesn’t seem like CalyxOS supports relocking the bootloader on non-Pixel devices (I don’t even know what SHIFT6mq phone is):

Shiftphone is repair & environment friendly company similar to Fairphone. Their latest model 8 has same SoC as FP5, so I expect same support. Though they also pack de-googled version of their own ROM (ShiftOS Light).

> [@anon21489307](#):
>
> I would use a stock phone rather than any other ROMs without verity boot.

I was recently thinking what could be my next phone if/when this one fails, and I realized I will never again buy a device (not just phone) that I can not fix or replace a part easily by myself. Which means GraphneOS (Pixel) will never be an option for me. And it’s OK, as my threat model is just to avoid FAANGM and surveillance capitalism. And CalyxOS looks like a good option if it works on some of those devices.

---

## Post 153 by @Redroyach — 2024-12-25T21:01:21Z

That’s understandable, my only real concern with pixels is repairability and environmental/ethical impact but if I was to use a Fairphone or Shiftphone I don’t see how CalyxOS would improve my privacy over stock OS, it doesn’t have many privacy features exclusive to itself, it can’t make these insecure devices secure in any meaningful way and afaik includes privileged google services even without microG, I would personally just try to harden and “degoogle” the stock OS.

---

## Post 155 by @Breeze7846 — 2024-12-26T01:44:05Z

> [@nayiwij577](#):
>
> No its not. Especially MacOS. But that’s for another topic.

Most mainline Linux distros like Fedora, Debian, etc are much better than OSX for security and privacy. Even many spinoff distros are decent. Apple has **repeatedly** been shown to exaggerate their privacy claims

> [@crossroads](#):
>
> I realized I will never again buy a device (not just phone) that I can not fix or replace a part easily by myself. Which means GraphneOS (Pixel) will never be an option for me.

And this is one reason why there needs to be a ROM beyond GrapheneOS for privacy. PG should not let perfect be the enemy of good. Limiting recommended privacy to 1 ROM running on 1 model of phone, does run the risk of having **nothing** if something goes wrong with GrapheneOS or Pixel

---

## Post 156 by @pinkandwhite — 2024-12-26T03:32:18Z

> [@Breeze7846](#):
>
> And this is one reason why there needs to be a ROM beyond GrapheneOS for privacy

Unfortunate as it is, this is _privacy_guides, not _right-to-repair_guides. If GOS manages to implode or Google does something particularly nasty with Pixels, that’s a bridge to cross at that point, not a reason to list an objectively worse option _right now_.

And besides, if I were to break the screen on a fancy pants pixel fold, I could get a genuine replacement part and get full functionality, even if it’s not as “easy” as on a FP or similar to do the repair.

---

## Post 157 by @anon42475305 — 2024-12-26T03:44:22Z

> [@Breeze7846](#):
>
> Most mainline Linux distros like Fedora, Debian, etc are much better than OSX for security and privacy. Even many spinoff distros are decent. Apple has **repeatedly** been shown to exaggerate their privacy claims

This is incorrect, though as others have said, thoroughly off-topic. If you wish to continue this discussion, I encourage you to open a new topic.

> [@Breeze7846](#):
>
> And this is one reason why there needs to be a ROM beyond GrapheneOS for privacy. PG should not let perfect be the enemy of good. Limiting recommended privacy to 1 ROM running on 1 model of phone, does run the risk of having **nothing** if something goes wrong with GrapheneOS or Pixel

Unfortunately, many aspects of this argument are fundamentally flawed. Firstly, the assumption that CalyxOS is ‘good’ and that Privacy Guides requires perfection in their recommendations. Neither is true, and both are incredibly subjective. It is my opinion, based on my knowledge of the shortcomings of CalyxOS, that it isn’t an acceptable alternative to GrapheneOS, even for harm reduction. Therefore, even if the “perfection is the enemy of good” argument was logically sound, it ultimately doesn’t further the discussion on whether CalyxOS should be recommended.

The reason the arguments that “perfection is the enemy of good” and “… risk having nothing” aren’t good arguments is because they encourage complacency and harmful compromise. The goal of Privacy Guides is not to recommend every privacy-focused product available; rather, they intentionally maintain extremely high standards for their recommendations, which is a point of pride for the project. It is far better to foster an attitude of quality over quantity among developers and manufacturers. Take CalyxOS for example, they certainly have the resources to compete with or even surpass GrapheneOS. Instead, they mislead users and fall behind with basic security practices, presumably to maximise profits. The only way an attitude like that will change is to hold them accountable for that sort of behaviour, not to endorse and encourage it.

GrapheneOS currently exists as the gold standard of secure and private mobile OSes, and even if Pixel hardware disappeared tomorrow, GrapheneOS would have 7 years to find new, acceptable hardware to develop for.

---

## Post 159 by @anon48875053 — 2024-12-26T08:57:49Z

> [@Breeze7846](#):
>
> Most mainline Linux distros like Fedora, Debian, etc are much better than OSX for security and privacy. Even many spinoff distros are decent. Apple has **repeatedly** been shown to exaggerate their privacy claims

Captain, wake up, you’re spewing nonsense in your dreams.

> [@Breeze7846](#):
>
> And this is one reason why there needs to be a ROM beyond GrapheneOS for privacy. PG should not let perfect be the enemy of good. Limiting recommended privacy to 1 ROM running on 1 model of phone, does run the risk of having **nothing** if something goes wrong with GrapheneOS or Pixel

GrapheneOS isn’t perfect, it’s the only recommendable option.

---

## Post 160 by @Breeze7846 — 2024-12-26T09:30:21Z

I can understand that. I just hope we aren’t caught with our pants down again, like we were with CopperheadOS. I’m not claiming calyx is better; I have little knowledge of calyx specifically. I’m advocating PG simply be future-oriented in planning. That is the substance of my argument.

> [@anon48875053](#):
>
> ![](https://forum-cdn.privacyguides.net/user_avatar/discuss.privacyguides.net/breeze7846/48/14_2.png) Breeze7846:
> 
> > Most mainline Linux distros like Fedora, Debian, etc are much better than OSX for security and privacy. Even many spinoff distros are decent. Apple has **repeatedly** been shown to exaggerate their privacy claims
> 
> Captain, wake up, you’re spewing nonsense in your dreams

And as for that, my stance on Linux is simply in line with what PG currently recommends, and what the IT space/news has been saying for years. It will take a lot of quality evidence to prove otherwise

---

## Post 162 by @Redroyach — 2024-12-26T14:28:03Z

Yup, I think that’s the main issue with calyx, it doesn’t seem to even provide benefit over a well configured stock OS. Both In privacy and specially security.

---

## Post 163 by @anon44060584 — 2024-12-26T15:02:02Z

I’m using Calyx on a Fairphone 4 with a locked bootloader so it’s definitely supported. I know there are flaws with the fairphone security but that setup is one of the least sucky options I could find with this phone right now.

Is that worse than stock OS considering play services run in the background on stock 100% of the time? You also need a Google account if you want to use the Play store in an official manner. I nuked mine with all my purchased apps years ago when I switched to Proton and lineage/microg.

I am also pro right to repair after dealing with phones that use glue (I did repairs on them) so I would feel dirty buying a Pixel phone…I don’t have the money anyway. I guess a good change is the EU law forcing manufacturers to use removable batteries (2027).

---

## Post 164 by @BlackDog — 2024-12-26T15:35:36Z

> [@Redroyach](#):
>
> Yup, I think that’s the main issue with calyx, it doesn’t seem to even provide benefit over a well configured stock OS. Both In privacy and specially security.

Does that mean if I debloat my Samsung and replace some apps with things like Heliboard, it’s as good for privacy and security as my Pixel running Calyx?

---

## Post 165 by @Redroyach — 2024-12-26T17:31:52Z

Obviously it depends on your device (Pixel\>Samsung) but what im trying to say is that your pixel is not really more prívate or secure with Calyx than it would be if you harden the stock OS.

---

## Post 166 by @Redroyach — 2024-12-26T17:53:37Z

AFAIK Calyx always has privileged Google services and libraries, specially with microG which downloads and runs propietary Google code, also if you use mainstream apps they probably have Google code bundled inside them and it can run for as long as you use them even if your OS has no play services.

If you use Calyx with microG or propietary apps you might be tracked by Google just like in the stock OS.

---

## Post 170 by @crossroads — 2024-12-27T04:50:18Z

I asked in LOS topic, but could also ask here - Is there any comparison of different phone settups (e.g. Samsung as it is, Samsung de-googled as much as possible without rooting, CalyxOS with microG, CalyxOS without microG…) and how much data they are sending to Google?

There was that news few years ago, that Android phones are sending 4MB of data per day, with almost 400 connections. If CalyxOS is at e.g. 100KB, then I would say it is much better and it might make sense to use it.

And regarding PG recommendations, I’m not saying it should be on the list. There’s a clear description and guideline how and why things get recommended, so if CalyxOS doesn’t fulfills criteria, it shouldn’t be there. But I would like to see clear pros and cons of using (un)recommended products and services, so people can make a decision based on their preferences and threat model.

---

## Post 171 by @anon21489307 — 2024-12-27T06:29:48Z

> [@crossroads](#):
>
> There was that news few years ago, that Android phones are sending 4MB of data per day, with almost 400 connections.

That could be a few years ago, and there’s no info to which brands of those Android phones. Moreover, it doesn’t matter how much of data that’s sending if it’s encrypted. There are many factors to consider other than the amount of data that’s being sent.

As I am using Samsung, all data back up and sync to Samsung account are end-to-end encrypted, but the user has to enable them manually, since the user has to keep the encryption key themselves.

Data back up to Google account should have the same security and privacy across the board among Android devices running Google services, including the one running in CalyxOS.

> **[Back up or restore data on your Android device - Android Help](https://support.google.com/android/answer/2819582?hl=en)**
>
> You can back up content, data, and settings from your phone to your Google Account.

> Your backups are uploaded to Google and encrypted with your Google Account password. For some data, your device’s screen lock PIN, pattern, or password is also used for encryption.

> All data, including photos and videos, messages and more are encrypted as they move between your device, Google services, and our data centers.

> Some data is further encrypted with your device’s screen lock. Photos and videos in Google Photos, and MMS media received from your carrier aren’t encrypted by your device’s screen lock.

IMO, I don’t see the point of CalyxOS at all. Even if my phone is supported, most of its [features](https://calyxos.org/features/) are not convincing me enough to use this OS specifically, since there are 3rd-party apps for that, or the user can simply achieve the same features in the stock settings, e.g. private DNS.

On the other hand, _Secure Folder_ in stock Samsung devices is hard to replace as a privacy tool. It’s not simply an app locker, but another profile that’s encrypted and requires a password or other authentications to access.

> **[Secure Folder | Knox](https://www.samsungknox.com/en/solutions/personal-apps/secure-folder)**
>
> Secure Folder is a free app that creates a private, encrypted space on your Samsung Galaxy smartphone. Get an additional layer of security and privacy by leveraging the Samsung security platform.

I think a stock Samsung ROM could provide better security and privacy benefits than many custom ROM already, especially with verity boot intact.

---

## Post 172 by @jerm — 2024-12-27T09:20:29Z

[https://xcancel.com/GrapheneOS/status/1872448041656922231#m](https://xcancel.com/GrapheneOS/status/1872448041656922231#m)

> Moving from DivestOS to LineageOS, /e/OS or CalyxOS would mean giving up a bunch of privacy and security features they ported from GrapheneOS.

> Among other things, DivestOS used a port of our hardened allocator, secure app spawning, a subset of the kernel hardening, a lot of the browser/WebView hardening, Sensors toggle, Network toggle and per-connection MAC randomization.
> 
> There’s a 3rd party comparison with a privacy and security focus at [eylenburg.github.io/android](https://eylenburg.github.io/android_comparison.htm).

> Among other things, DivestOS used a port of our hardened allocator, secure app spawning, a subset of the kernel hardening, a lot of the browser/WebView hardening, Sensors toggle, Network toggle and per-connection MAC randomization.

> DivestOS started out with the network toggles from LineageOS but provided a port of our Network toggle as a better replacement due to the LineageOS approach used in each of those other options being quite leaky.

> DivestOS didn’t have the resources needed to keep up with new Android versions or port more privacy and security hardening to it. Those other operating systems are not trying to provide similar fundamental privacy and security enhancements in the first place.

Would have been great if @anon63378630 and anyone in their team re-considers the offer by GrapheneOS to work with them when they he takes time off, they are very skilled, dedicated and committed.

---

## Post 173 by @anon46412288 — 2024-12-27T12:41:54Z

> Would have been great if @anon63378630 and anyone in their team re-considers the offer by GrapheneOS to work with them when they he takes time off, they are very skilled, dedicated and committed.

Skewed is _done_ with Android and Android-related projects for the time being. I believe they are NOT interested in continuing with Android any more.

---

## Post 174 by @BlackDog — 2024-12-27T12:42:56Z

> [@anon21489307](#):
>
> That could be a few years ago, and there’s no info to which brands of those Android phones.

There was [this study](https://hothardware.com/news/samsung-xiaomi-other-android-phones-spying-on-users) from 3 years ago.

---

## Post 175 by @BlackDog — 2024-12-27T12:47:06Z

> [@anon21489307](#):
>
> IMO, I don’t see the point of CalyxOS at all. Even if my phone is supported, most of its features are not convincing me enough to use this OS specifically, since there are 3rd-party apps for that, or the user can simply achieve the same features in the stock settings, e.g. private DNS.
> 
> On the other hand, _Secure Folder_ in stock Samsung devices is hard to replace as a privacy tool. It’s not simply an app locker, but another profile that’s encrypted and requires a password or other authentications to access.
> 
> I think a stock Samsung ROM could provide better security and privacy benefits than many custom ROM already, especially with verity boot intact.

This is the question I asked earlier. Would my Samsung A54, debloated and with 3rd party privacy apps (and maybe a different DNS?), be as private/secure as my Pixel 6a running Calyx?

---

## Post 176 by @anon46412288 — 2024-12-27T13:00:47Z

> [@anon21489307](#):
>
> Edit: It doesn’t seem like CalyxOS supports relocking the bootloader on non-Pixel devices (I don’t even know what SHIFT6mq phone is):

This is literally false. All those devices you mentioned are supported because of the ability to re-lock the bootloader on those phones. You can view their avb hashes here - [https://review.calyxos.org/c/CalyxOS/calyxos.org/+/24066/11/pages/\_data/devices.yml](https://review.calyxos.org/c/CalyxOS/calyxos.org/+/24066/11/pages/_data/devices.yml)

“Re-locking” on that page is referring to flashing something after flashing Calyx :

> These two don’t have proper rollback protections, there’s still it on recovery and stuff but not really on Verified Boot, as they need to match a number from stock; as they don’t wipe the rollback index when the bootloader is unlocked

Source : [You're invited to talk on Matrix](https://matrix.to/#/!UlsAcjNSfQqWJPccIO:matrix.org/$-sHU2A423H5XgiYWLcqUPsEz3rnH1EsOGrAUWsE97CA?via=calyx.dev&via=matrix.org&via=tchncs.de) (their matrix room)

---

## Post 177 by @anon46412288 — 2024-12-27T13:13:05Z

> [@Redroyach](#):
>
> Both In privacy and specially security.

OEM Androids are far more integrated with invasive stuff than any custom ROM. Sure you can use Android debloater, but you will not achieve the same level of privacy as with something properly degoogled like Calyx or Graphene.

Where [Calyx does use Google connections](https://www.kuketz-blog.de/calyxos-de-googled-geht-anders-custom-roms-teil2/), those are mainly for microG functionality and are [also anonymised](https://calyxos.org/docs/guide/security/identifiers/).

EDIT : Here’s another page on why [COS uses Google connections](https://calyxos.org/docs/guide/security/network-activity/#why-does-calyxos-still-use-servers-run-by-google).

---

## Post 178 by @anon21489307 — 2024-12-27T13:23:22Z

> [@anon46412288](#):
>
> This is literally false. All those devices you mentioned are supported because of the ability to re-lock the bootloader on those phones. You can view their avb hashes here - [https://review.calyxos.org/c/CalyxOS/calyxos.org/+/24066/11/pages/\_data/devices.yml](https://review.calyxos.org/c/CalyxOS/calyxos.org/+/24066/11/pages/_data/devices.yml)

What are you referring to? Many Pixels do not have the AVB hash. Does that mean those Pixels don’t support relocking?

---

## Post 179 by @anon46412288 — 2024-12-27T13:28:08Z

You said CalyxOS does not support relocking the bootloader on non-Pixel devices. That is the false part. All devices officially supported by Calyx have bootloader relocking.

---

## Post 180 by @anon21489307 — 2024-12-27T13:37:02Z

> [@BlackDog](#):
>
> Would my Samsung A54, debloated and with 3rd party privacy apps (and maybe a different DNS?), be as private/secure as my Pixel 6a running Calyx?

In terms of privacy features, I think Samsung would get an edge over CalyxOS. But I don’t know about its currently telemetry, or the telemetry of CalyxOS.

My bottom line is, if you get a Pixels, use GOS if you enjoy security and privacy over the convenient from Google services.

If you got Samsung or any other phones for that matter that relocking the bootloader is not supported, using a stock would be a much better option over a custom ROM in terms of security. In terms of privacy, it would depend on the brand. I stay with Samsung because the support is long, and the software are decent, especially Secure Folder.

---

## Post 181 by @anon21489307 — 2024-12-27T13:42:21Z

> [@anon46412288](#):
>
> All devices officially supported by Calyx have bootloader relocking.

Then why don’t they say so on [this page](https://calyxos.org/docs/guide/security/bootloader-lock/)?

> [@anon46412288](#):
>
> “Re-locking” on that page is referring to flashing something after flashing Calyx

This part is not making any sense to me, since verity boot with locked bootloader ensures that the system is intact and nothing can be tampered with it. It doesn’t matter what you want to flash, you just can’t.

---

## Post 182 by @anon46412288 — 2024-12-27T13:44:39Z

> [@anon21489307](#):
>
> In terms of privacy features, I think Samsung would get an edge over CalyxOS. But I don’t know about its currently telemetry, or the telemetry of CalyxOS.

…if you are really convinced that the company that [forcefully installs Facebook using a _system application_](https://eu.community.samsung.com/t5/mobile-apps-services/facebook-forcefully-installing/td-p/10018709), and [marks TikTok as an essential application](https://www.reddit.com/r/assholedesign/comments/wfavcf/my_new_work_phone_installed_tiktok_brand_new_out/) has the edge in terms of privacy features, then I can’t really say anything.

---

## Post 183 by @anon21489307 — 2024-12-27T13:46:00Z

None of that can’t be disabled, or uninstalled. Recommended apps are opt-in.

Yes, it doesn’t look good for their image, but we’re talking about facts as they’re presented here.

---

## Post 184 by @anon46412288 — 2024-12-27T13:46:51Z

It is mentioned here : [Device Support](https://calyxos.org/docs/guide/device-support/)

> Ability to relock the bootloader with a custom OS installed:  
> CalyxOS is meant to be run with a locked bootloader after installation, which makes sure that the OS cannot be tampered without your knowledge. Additionally, this has to be implemented properly to not boot any other OS once a CalyxOS build signed with our own private keys is installed - whether it be another set of private keys, or the publicly available AOSP test keys.

CalyxOS _never_ supports running a device with an unlocked bootloader. In fact, when some OnePlus devices lost the ability to relock, CalyxOS stopped working on their port to those OnePlus devices.

> **[OnePlus Android 12 firmware - relocking no longer works](https://calyxos.org/news/2022/07/06/oneplus-android-12-relock-issue/)**
>
> OnePlus Android 12 firmware - relocking no longer works

---

## Post 185 by @anon46412288 — 2024-12-27T13:51:42Z

> [@anon21489307](#):
>
> Yes, it doesn’t look good for their image, but we’re talking about facts as they’re presented here.

What? Are you suggesting [this](https://calyxos.org/docs/guide/security/network-activity/) is less private than [this](https://www.scss.tcd.ie/Doug.Leith/Android_privacy_report.pdf)?

 ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/4/485f999acccc68b8be9b284671871597bdff891e.png)

---

## Post 186 by @anon21489307 — 2024-12-27T13:57:32Z

No, as I said the paper was from 2021. IIRC, TikTok also wasn’t introduced as a recommended app in Samsung then :joy: My point is the paper is outdated.

Moreover, it’s not just the telemetries, privacy features also count.

---

## Post 187 by @anon46412288 — 2024-12-27T14:04:26Z

> [@anon21489307](#):
>
> Moreover, it’s not just the telemetries, privacy features also count.

Not having a shit ton of telemetry is a very basic privacy feature too.

Also, about being outdated - here’s an [excerpt from the Samsung privacy policy](https://www.samsung.com/us/account/privacy-policy/) (effective July 1, 2024) :

> Third Party Analytics
> 
> Through certain Services, we collect personal information about your online activities on websites and connected devices over time and across third-party websites, devices, apps, and other online features and services through cookies and similar technologies. We use third-party analytics services on our Services, such as those of Google Analytics, Firebase Analytics, and Adobe Analytics. The service providers that administer these analytics services help us to analyze your use of the Services and to improve the Services. The information we obtain may be disclosed to or collected directly by these providers and other relevant third parties who use the information, for example, to evaluate use of the Services, help administer the Services, and diagnose technical issues.

---

## Post 188 by @anon21489307 — 2024-12-27T14:11:10Z

> [@anon46412288](#):
>
> Also, about being outdated - here’s an [excerpt from the Samsung privacy policy](https://www.samsung.com/us/account/privacy-policy/) (effective July 1, 2024) :

> [@anon46412288](#):
>
> Through certain Services

Sure, they have a ton of services. But it’s not related to when you back up and sync to their account with E2EE enabled.

I think I will end my opinion here regarding a stock Samsung vs CalyxOS. I gave my opinion: a stock Samsung \> CalyxOS in terms of privacy, as the privacy feature I use can’t be found in CalyxOS. I could be wrong and everyone should take it as a grain of salt.

Have a nice day.

---

## Post 189 by @anon46412288 — 2024-12-27T14:15:22Z

This is literally just Private Spaces.

> **[Hide sensitive apps with private space - Android Help](https://support.google.com/android/answer/15341885?hl=en)**
>
> To keep your sensitive apps away from prying eyes, you can set up private space, a separate space on your Android device to hide and organize apps. With private space, you can: Create a digital sa

This is included in Android 15 and above so will be in Calyx. I do not understand how you believe Samsung is more private. That is just simply not true at best and genuine ignorance at worst.

The features of Secure Folder when compared with Private spaces is like this -  
Secure Folder (i took the headlines from the page you linked) :

1. Separate and secure confidential data
2. Enhanced encryption [sidenote : it’s just marketing normal Android user profile encryption as “enhanced”]
3. Just for you - Keep your Secure Folder even safer by enabling a passcode or biometric lock.
4. Duplicate your apps: One for work, one for life
5. Lock and exit

Private spaces ([Private space &nbsp;|&nbsp; Android Open Source Project](https://source.android.com/docs/security/features/private-space)) :

1. Private Space enables users to create a secure, isolated environment on their device to keep sensitive apps away from prying eyes
2. Private space is based on the [Android multi-user model](https://source.android.com/docs/devices/admin/multi-user) [so it has separate encryption keys, like regular Android profiles]
3. [The demo on the page literally shows the private space being unlocked with biometrics]
4. Apps in the private space are installed as separate copies of the apps in the main space.
5. When the space is locked, the private profile user is stopped, and when the space is unlocked, the user is started.

---

## Post 190 by @anon21489307 — 2024-12-28T03:21:37Z

It seems you edited a part in your post that I didn’t see before. Here’s my thought:

> [@anon46412288](#):
>
> I do not understand how you believe Samsung is more private. That is just simply not true at best and genuine ignorance at worst.

Secure Folder.

> [@anon46412288](#):
>
> [Private Space]_will_ be in Calyx.

Until then. But it’s in Samsung devices for _years_, happy to see this useful privacy feature implemented in Android, finally. I have seen many users on Reddit requesting this feature on Pixels for years.

Moreover, the work is done in Android. So, back to the point that I made earlier, I don’t see the point of CalyxOS at all. There’s _almost_ nothing to make them standout in privacy space. It has a hard time even when comparing to a stock ROM.

On the hardware side, Pixel users would go to GOS over CalyxOS. Other _few_ devices that they support over GOS are either really old + non-economical (more expensive than the competitors, while almost at EOL) or niche.

It seems, after Android 15, I will have to re-evaluate this topic again. Seeing as One UI 7 is nearly release (currently in beta 2), I’m interested to see how they will go with Secure Folder. I hope that they’ll remove it in place of Private Space (if it’s essentially the same), but I don’t think so. Another duplicate app it seems :joy:

---

## Post 191 by @anon46412288 — 2024-12-28T04:38:14Z

> [@anon21489307](#):
>
> Secure Folder.

1. This feature landed on CalyxOS today (it was delayed due to some issues with the AOSP implementation that took a while to fix)

 ![privatespace](//forum-uploads.privacyguidesusercontent.com/original/2X/e/ef55ecce1632718d9c253d01267312456ca51552.png)

1. You continue to ignore the fact that Samsung has far more extensive telemetry. You **are wrong** when you say Samsung is more private just because it had one exclusive feature that stock Android didn’t have. I have tried to explain to you multiple times _with sources_ that the point is false, yet you continue to reiterate the same shit. Samsung is not private.

> I think I will end my opinion here regarding a stock Samsung vs CalyxOS. I gave my opinion: a stock Samsung \> CalyxOS in terms of privacy, as the privacy feature I use can’t be found in CalyxOS. I could be wrong and everyone should take it as a grain of salt.

If you feel like you could be wrong, why are you not taking an opportunity to at least read the links I attached? Hell, if you do not trust me, at least search for the Samsung privacy policy and _manually_ review it.

---

## Post 192 by @anon21489307 — 2024-12-28T05:02:42Z

> [@anon46412288](#):
>
> You **are wrong** when you say Samsung is more private just because it had one exclusive feature that stock Android didn’t have.

It’s **not** just this feature. And you **are wrong**. Samsung also supports _E2EE_ backup and sync that the stock Android don’t have.

The fact that I can’t possibly list all the features on top of my head right now, doesn’t mean that they don’t exist. I can’t even list all the features that I don’t use. I am just sharing my point that, a stock ROM could have more privacy benefits than a custom ROM sometimes.

> [@anon46412288](#):
>
> You continue to ignore the fact that Samsung has far more extensive telemetry.

> [@anon46412288](#):
>
> I have tried to explain to you multiple times

Didn’t I also tell you multiply times that telemetry is not everything? If you don’t agree, just agree to disagree, as there’s no point in further discussion.

> [@anon46412288](#):
>
> why are you not taking an opportunity to at least read the links I attached?

How did you know I didn’t???

> [@anon46412288](#):
>
> if you do not trust me, at least search for the Samsung privacy policy and _manually_ review it.

Again, how did you know I read it or not? Whether I put it into consideration is another matter entirely. As I told you, it’s _not_ related to E2EE which I care more than the telemetry, as it’s also a tangible privacy benefit.

**Stay on the matter, and please don’t assume something you don’t know about me.**

---

## Post 193 by @anon46412288 — 2024-12-28T05:08:14Z

> [@anon21489307](#):
>
> It’s **not** just this feature. And you **are wrong**. Samsung also supports _E2EE_ backup and sync that the stock Android don’t have.

OK? Do you know about the SeedVault application? It provides E2EE local backup for CalyxOS. It doesn’t have sync across devices, because it is just a backup application, but that does not matter because there is no Google account integration for syncing data across devices.

> The fact that I can’t possibly list all the features on top of my head right now, doesn’t mean that they don’t exist. I can’t even list all the features that I don’t use. I am just sharing my point that, a stock ROM could have more privacy benefits than a custom ROM sometimes.

Fine, I will accept that there aren’t much privacy exclusive features. However, it’s not completely blank.

1. There is a “Redact all cleartext traffic” option in CalyxOS to block all http traffic

 ![feature](//forum-uploads.privacyguidesusercontent.com/original/2X/3/3ac442ac898703a08ea4f79fe47c737b79452854.png)

1. [CalyxOS by default removes location metadata from images while sharing it to applications.](https://review.calyxos.org/q/topic:%22strict-location-redaction%22)

---

## Post 194 by @anon21489307 — 2024-12-28T05:15:29Z

> [@anon46412288](#):
>
> It[SeedVault] doesn’t have sync across devices, because it is just a backup application, but that does not matter because there is no Google account integration for syncing data across devices.

Why sync functionality has anything to do with Google account? Samsung account’s syncing is also not related to Google account. I doubt that SeedVault has anything you can compare to Google’s or Samsung’s backup and sync which sync on the _cloud_, while SeedVault is a _local_ backup tool.

---

## Post 195 by @anon46412288 — 2024-12-28T05:20:24Z

SeedVault has an option to backup to Nextcloud or WebDAV. It isn’t exactly syncing across devices though, you need to manually restore.

 ![nextcloud](//forum-uploads.privacyguidesusercontent.com/original/2X/e/e36b3abd4ba181945e9ef953c49f4689cf4fa83b.png)

---

## Post 199 by @anon46412288 — 2024-12-29T16:00:35Z

> [@vsucs](#):
>
> Not only is this an AOSP feature, (so they don’t deserve any praise for this) the fact they are late since October demonstrates why CalxyOS shouldn’t be recommanded quite clearly.

They delayed this to figure out [how to support VPNs with Private Spaces](https://gitlab.com/CalyxOS/calyxos/-/issues/2770), and also because [Google literally didn’t include some core features of Private Spaces in AOSP.](https://gitlab.com/CalyxOS/calyxos/-/issues/2870#note_2253770508)

> Many things in there only apply to opt-in features. For example If you’d use Calyx VPN on CalyxOS, its not their problem that you OPTED to route your traffic through them. Same with Samsung Account etc. on OneUI.

Samsung will collect telemetry regardless of whether you create an account.  
From their privacy policy :

> **This Privacy Policy applies to all of our Samsung devices** and services where we process personal information, from mobile phones, tablets, TVs and home appliances, to the customer services and online services we provide on our Samsung website. We will refer to these **devices** and services as the “Services” in this Privacy Policy.

Even their devices are referred to as Services. And like I previously mentioned :

> This Privacy Policy applies to all of our Samsung devices and services where we process personal information, from mobile phones, tablets, TVs and home appliances, to the customer services and online services we provide on our Samsung website. We will refer to these devices and services as the “Services” in this Privacy Policy.

Your data is collected when you use the device, accountless or not.

---

## Post 201 by @anon46412288 — 2024-12-30T02:57:48Z

The level of mental gymnastics I am seeing here is absolutely impressive.

> This doesn’t disprove anything i said.

You stated : “Many things in there only apply to opt-in features.”. Do you consider buying the device as an opt in feature? Because this privacy policy applies to you if you buy the device and gives Samsung full rights to collect any data they detail under their privacy policy.

If you then tell me “Well, you bought the device. Therefore you agree to having your data collected.”, then your entire “Samsung is more private than Calyx” thing falls apart. There is no form of in built telemetry in Calyx. The Calyx VPN feature is also accountless. I am not a Calyx VPN user, but please for the love of god stop spouting bullshit. (went on further detail below)

> Okay. And? Not like that matters in this context.

It matters because you assume Samsung will not collect any data (or, you say, “the telemetry is way less when you dont opt-in”)

Also. Can I have sources for these?

> My argument is that its better than you think and that the telemetry is way less when you dont opt-in to using their online services.

> Not to the same extent.

---

## Post 203 by @anon46412288 — 2024-12-30T03:33:09Z

> [@vsucs](#):
>
> Is it so hard to undestand that not everything that is being written into a general privacy policy happens INSTANTLY or automatically the moment you start using the device? Many things only trigger when you opt-in to them or use the related service.

 ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/1/1e81e14a73599a854c06909f7140d65611ad4481.png)

> So is Samsung telemetry. I brought calyx VPN up originally to make the argument that its up to the user to destroy their privacy on the device.

(Calyx VPN doesn’t have any telemetry-like features anyways, but…)  
CalyxOS does not collect any telemetry if you choose to not use Calyx VPN (unlike samsung above)

> For what? The common knowledge that if the policy says “we may do something” its highly context dependent

Can you give examples of these contexts?

---

## Post 205 by @anon46412288 — 2024-12-30T04:25:45Z

> [@vsucs](#):
>
> I never denied that they do collect telemetry. Stop acting like i did. Your image states the obvious

…I was replying with that image to your “Is it so hard to undestand that not everything that is being written into a general privacy policy happens INSTANTLY or automatically the moment you start using the device? Many things only trigger when you opt-in to them or use the related service.” statement. I then talked about the amount of telemetry to other statements.

> Of course:
> 
> **Samsung Keyboard information:** The words that you type when you enable “Predictive text”. This feature may be offered in connection with your Samsung account to synchronize the data for use on your other Samsung mobile devices. You can clear the data by going to the “Predictive text” settings.
> 
> Its from their document you cited.

Fine, but can you opt out of this data collection altogether?

Oh also, it is stated that the data is collected regardless of whether you opt in or opt out. Can you show proof that Samsung respects your choice and stops collecting data related to this service when you opt out?

---

## Post 207 by @anon46412288 — 2024-12-30T14:06:08Z

> [@InternetGhost](#):
>
> In looking into it I did find the blog post discussing [why GrapheneOS is recommended over CalyxOS](https://blog.privacyguides.org/2022/04/21/grapheneos-or-calyxos/).

It’s been nearly 2 years since that article was published, so within that period a lot of changes have happened :

1. CalyxOS has the ability to add 16 user profiles, not just 4. This was  
erronous even at the time of writing.

2. CalyxOS major OS updates have exponentially sped up. The huge delay between Android 11 to Android 12 was a one time occurence. The time taken for the first build to land after AOSP release for the next major updates are as the follows :  
COS A12 to A13 - [Took one month](https://calyxos.org/news/2022/09/15/tiramisu-pixel-4-5-6/)  
COS A13 to A14 - [Took 10 days](https://calyxos.org/news/2023/10/14/android-14/)  
COS A14 to A15 - [Took 5 days](https://calyxos.org/news/2024/10/19/android-15/)

3. One of the talking points was about microG being less compatible :

> As a result, it only supports the various parts that have been reimplemented, meaning some things such as [Google Play Games](https://play.google.com/googleplaygames) and [In-app Billing API](https://developer.android.com/google/play/billing) are not yet supported.
> 
> Larger apps, especially games, require [Play Asset Delivery](https://android-developers.googleblog.com/2020/06/introducing-google-play-asset-delivery.html) to be installed, which is currently not implemented in microG. Authentication using [FIDO](https://www.privacyguides.org/basics/multi-factor-authentication#fido-fast-identity-online) with online services on Android also relies on Play Services, and does not currently work with microG.

All of these features (except for FIDO, I believe) are now available in microG :

 ![features](//forum-uploads.privacyguidesusercontent.com/original/2X/3/3c504d2db66636462c34f52841173441061a52c8.png)

1. While not [all of the improvements for user profiles from GrapheneOS](https://grapheneos.org/features#improved-user-profiles) are available, the “End session” feature is available.

 ![endsession](//forum-uploads.privacyguidesusercontent.com/original/2X/a/a20ef67f2825347c523469e8e5baed3fb6e4e0df.png)

1. 

> Android 12 comes with special support for seamless app updates with [third-party app stores](https://android-developers.googleblog.com/2020/09/listening-to-developer-feedback-to.html). The popular Free and Open-Source Software (FOSS) repository [F-Droid](https://f-droid.org) doesn’t implement this feature and requires a [privileged extension](https://f-droid.org/en/packages/org.fdroid.fdroid.privileged) to be included with the Android distribution in order to have unattended app updates.
> 
> CalyxOS includes the [privileged extension](https://f-droid.org/en/packages/org.fdroid.fdroid.privileged), which may lower device security.

While it is true that CalyxOS includes the F-Droid Privileged Extension, this is [mainly for backwards compatibility with installs from when F-Droid didn’t have automatic updates](https://gitlab.com/CalyxOS/calyxos/-/issues/1943). They moved to F-Droid Basic ([and were in fact directly responsible for adding support for auto-updates to F-Droid](https://calyxos.org/news/2023/09/04/f-droid/)). F-Droid is also no longer a system app from release 4.12.2 (link above).

---

## Post 208 by @starkle — 2024-12-30T18:46:38Z

I feel like this thread is missing the forest for the trees. 80 replies after DivestOS was ended last week, when it should be plain to see CalyxOS is no replacement.

AFAICT, DivestOS was recommended for its broad hardware support. GrapheneOS sets a really high bar for privacy, security, UX etc., but not everyone can afford or obtain a Google Pixel.

How does CalyxOS compare?

CalyxOS supports exactly 5 devices other than Google Pixels at this time (three Motorollas and two Fairphones); a far cry from what DivestOS supported. I could not find any listing for these less phones than $450, and I’m not confident they are easier to obtain in regions that people have trouble getting Google Pixels (especially Fairphones). They are also significantly worse for privacy/security perspective. I mean, [Motorolla requires you to make an online account to unlock the bootloader](https://en-us.support.motorola.com/app/standalone/bootloader/unlock-your-device-a) and sign additional legal terms. Why in the world would Privacy Guides _recommend_ that?

We all miss DivestOS but CalyxOS just doesn’t fill the hole it left behind. On the same hardware, there’s really no reason to recommend CalyxOS alongside GrapheneOS. Unless either of those things change, I don’t think anything else really needs to be said.

---

## Post 209 by @anon39565454 — 2024-12-30T23:03:19Z

This was never really reported anywhere, but on some samsung devices (I know P205, dunno about others)

Onedrive is a system app, uninstalling it with adb bricks the system

---

## Post 210 by @TheG — 2024-12-30T23:20:19Z

No, uninstalling onedrive with adb does not break the system. I have an S23 that has been debloated through adb.

---

## Post 211 by @anon21489307 — 2024-12-30T23:24:23Z

> [@anon39565454](#):
>
> Onedrive is a system app,

OneDrive is _part of_ a system app (Gallery). Itself is not a system app that can’t be disabled. I disabled mine without adb:

 ![sss](//forum-uploads.privacyguidesusercontent.com/original/2X/7/71c068708ede4d7cea430d23187259bff2ada57d.jpeg)

---

## Post 212 by @anon39565454 — 2024-12-30T23:35:47Z

It depends on the device, I know it doesn’t affect _all_ systems, but it definitely does affect _some_ systems

---

## Post 214 by @ph00lt0 — 2024-12-31T12:53:54Z

13 posts were split to a new topic: [Samsung Secure Folder](/t/samsung-secure-folder/23614)

---

## Post 215 by @ph00lt0 — 2024-12-31T13:01:31Z

7 posts were merged into an existing topic: [LineageOS vs. CalyxOS vs. DivestOS](/t/lineageos-vs-calyxos-vs-divestos/15447/19)

---

## Post 233 by @ph00lt0 — 2024-12-31T12:39:12Z

please gents keep this on topic, your discussion does not belong here.

Had to move 20 posts… it was quite messy. See above splits to find your conversations.

This thread should be solemnly about whether to add calyx.

---

## Post 235 by @anon39565454 — 2024-12-31T12:47:55Z

Practically speaking, Calyx fits the criteria and supports more device than Graphene. So whilst I think that lineage is better than Calyx, for all intents and purposes Calyx does fulfill some of the gap graphene has (device support) and thus should probably be added

---

## Post 236 by @ph00lt0 — 2024-12-31T13:14:23Z

I don’t really feel much for it. The only reason one should consider perhaps to use CalyxOS is if you already have one of those motorola or fairphone devices and you have no funds to buy yourself an actual secure device.

We shouldn’t recommend people to get such hardware and we already [don’t](https://www.privacyguides.org/en/mobile-phones/).

I don’t think such edge cases are worth to be recommendations. It is really a niche that people will find their own way in if they are that dedicated to be running a custom distribution like that.

---

## Post 237 by @ph00lt0 — 2024-12-31T13:18:31Z

I think it bottles down to my philosophy that we should not list every option to gain privacy but rather a golden path that anyone can follow. For more advanced topics and discussions people do a deep-dive anyway and are welcome to discuss so on the forum. It is not really a recommended route lets say.

---

## Post 238 by @anon39565454 — 2024-12-31T13:25:13Z

Whilst I do agree with the general sentiment, I do think that this site does still allow for some amount of compromise (eg. iOS software recommendations in general, iOS is obviously not exactly a privacy friendly system even if it’s considered secure). I think the discussion is moreso whether or not calyx fits this compromise window

---

## Post 239 by @overdrawn98901 — 2024-12-31T20:04:39Z

I think there are two schools of thought:

1. Unable to switch from/already have default stock OS. With this, some users need to do their best to secure what they have, rather than jump onto a new OS which might not be their threat model or even capability. Having a hardening guide for iOS, stock Android, Windows, MacOS, and maybe ChromeOS will help a lot of people get in a better place without sacrificing what they know.
2. Willing to install their own OS. At this point, whatever is recommended should be worth the “hassle” of flashing this on their own device. This should have considerable gains in privacy/security over the stock option imo, and should have a clear distinction over other recommendations.

CalyxOS needs to be significantly better enough than stock Android and a distinct alternative, but still comparable to, to GrapheneOS.

---

## Post 240 by @anon5410820 — 2025-01-01T10:21:53Z

> [@starkle](#):
>
> We all miss DivestOS but CalyxOS just doesn’t fill the hole it left behind.

Inclined to agree as a former-DivestOS user. I don’t hate Calyx or anything (like I think it’s still preferable to things like /e/OS) , it’s just not a significant improvement over Graphene in terms of device support and harm reduction.

---

## Post 241 by @lucasmz — 2025-01-28T18:42:40Z

> [@ph00lt0](#):
>
> if you already have one of those motorola or fairphone devices and you have no funds to buy yourself an actual secure device.

Pixels are only properly available in privileged countries, good luck getting a Pixel in most of the global south

---

## Post 242 by @Regime6045 — 2025-08-03T13:13:27Z

It appears that CalyxOS is currently “on hold”. The founder left, it can’t be downloaded any more, and existing installs won’t get any updates. The project still wants to continue in the future but is in the process of restructuring everything.

Source: [A letter to the CalyxOS community](https://calyxos.org/news/2025/08/01/a-letter-to-our-community/)

---

## Post 243 by @anon11657877 — 2025-08-03T14:54:24Z

Why don’t we just reject this already since CalyxOS is “on hold” and it’ll likely die soon? Even if they do restructure and downloads become available again, the fact this even happened means it’ll take a couple years of consistent updates for CalyxOS to even be considered.

---

## Post 244 by @Ganther — 2025-08-03T16:49:52Z

Yeah, pretty wild times for CalyxOS at the moment.

I’d be genuinely surprised if it was included now after they go “on hold” out of the blue with barely any info. Pretty strange if you ask me.

---

## Post 245 by @Average_Joe — 2025-09-09T02:09:45Z

How is Calyxos in 2025?

---

## Post 246 by @anon16234852 — 2025-09-09T09:23:28Z

dead

---

## Post 247 by @Average_Joe — 2025-09-09T19:51:49Z

I appreciate your reply!

I’m really saddened to hear that…

---

## Post 248 by @ph00lt0 — 2025-09-09T22:08:21Z

See also: [A letter to the CalyxOS community](https://discuss.privacyguides.net/t/a-letter-to-the-calyxos-community/29669)
