# Graphene OS - best practices?

**URL:** https://discuss.privacyguides.net/t/graphene-os-best-practices/27423
**Category:** Questions
**Created:** 2025-05-09T01:01:25Z
**Posts:** 5

## Post 1 by @untitled_unsterile932 — 2025-05-09T01:01:25Z

I recently picked up a Pixel 8 and installed Graphene OS to begin tinkering. My plan is to migrate (or at least try) from being a long-time iPhone user, however I have a few questions. I understand that these questions don’t all have a “correct” answer, but I at least want to understand the rationale behind the answers.

I should preface this by saying that at the end of the day, I value security more than privacy

**Where should I get OSS apps? F-Droid, APKs on Github, Aurora, Sandboxed Play Store?**  
Apps like Signal, ProtonMail, Ente, Bitwarden etc  
I was leaning toward APKs here as I’ve heard that F-Droid isn’t the safest option, and where I can, I want to avoid Google Play all together. I’m a developer, so downloading releases from Github seems fairly natural to me. Any reason I should not do this?

**Where should I get closed-source apps? F-Droid, Aurora, Sandboxed Play Store?**  
Apps like Slack, Uber, etc  
For this, I was thinking Sandboxed Google Play with a burner Google account. Same reasons as above for skipping F-Droid. Any alternative thinking here?

**Multiple users / profiles. What is the advantage to having a single “owner” account that downloads all the apps, and then separate users / profiles who have been delegated access to those apps from the owner account?**  
I don’t really have my own editorial here yet, this aspect is the most confusing to me.

**Toggle off Google Play & Services when not in use?**  
As of now, I think I’ll need these for:

- Downloading play store apps
- Using my YubiKey for 2FA to login to my password manage Bitwarden

Anything else I should consider? Thank you in advance!

---

## Post 2 by @anonymous261 — 2025-05-09T03:01:56Z

I appreciate the time you put in in writing your post and making it look polished :+1: , but I would also appreciate it if you were able to do a bit more research.

> **[Obtaining Applications - Privacy Guides](https://www.privacyguides.org/en/android/obtaining-apps/)**
>
> We recommend these methods for obtaining applications on Android without interacting with Google Play Services.

> **[Best User Profile Setup on GrapheneOS](https://seprand.github.io/articles/best-user-profile-setup/)**
>
> How to pick a profile setup that works best for you.

---

## Post 3 by @faxe — 2025-05-09T05:28:35Z

I personally have the following preference on App sources:  
Accrescent \> Play Store \> Github releases (with Obtainium + AppVerifier)

Using the owner profile only to download and distribute apps between profiles has some security benefits, as you won’t be daily driving your owner profile which has a few settings that are only accessible through the owner profile and not through secondary profiles (mostly network related stuff I think). For me that’s overkill and too inconvenient so I just use the owner profile and private space to isolate apps from each other.

Some Apps check on first launch if you have Google Play Services installed, and if that’s the case, they use it for notifications. If you disable Play Services while not actively in use, that might lead to no notifications for certain apps.

---

## Post 4 by @user1 — 2025-05-09T05:35:27Z

> [@untitled_unsterile932](#):
>
> **Multiple users / profiles. What is the advantage to having a single “owner” account that downloads all the apps, and then separate users / profiles who have been delegated access to those apps from the owner account?**  
> I don’t really have my own editorial here yet, this aspect is the most confusing to me.

Take a look at the wiki

> [@Common User Profile Setups for Android](https://discuss.privacyguides.net/t/common-user-profile-setups-for-android/27364):
>
> One of the simplest ways to isolate different applications and personal data on an Android device is to use multiple users. This is a feature which has been widely available on Android phones since 2014, but goes fairly underutilized by most people. Originally, this feature was intended to support multiple physical people sharing the same device, with the AOSP team envisioning a second user being added to a tablet for children to use, or critical response teams sharing a phone for on-call dut…

---

## Post 5 by @null — 2025-05-09T17:34:44Z

My App sources: I prefer privacy over security and I like to keep as few apps as possible on my phone.

Phone: Third Party F-driod Repositories → IzzyOnDroid → Main F-droid Repository.

Tablet: Accrescent → Third party F-driod Repositories → IzzyOnDroid → Main F-droid Repository → Aurora store.

F-drord’s security has billion posts on this topic.

Accrescent feels too much as a alpha for me and only have 2 apps that I use and both has Third Party F-driod Repositories. I pretty must only uses it on my tablet to follows Accrescent’s development.

Aurora Store vs Sandboxed Play Store idk I only use one closed-source app that need GSM so I prefer Aurora Store’s spoofing over Sandboxed Play Store when I only need one app.

Obtainium to must bloat. :slight_smile:

Maybe someone has a setup you like here.

> [@What is Your Private Phone setup?](https://discuss.privacyguides.net/t/what-is-your-private-phone-setup/97):
>
> As the title says, I am curious what kinds of setup our community uses in general, I will start with my own setup: I am currently using a Pixel 6 pro with Graphene OS. I forward all my traffic through ProtonVPN to hide my IP address, and use Vanadium for my browsing needs. Furthermore I use Aurora store to keep my apps up to date (except for Signal which updates itself) and tend to use open source apps where i can. I am looking forward to your replies :).
