How degoogled is GrapheneOS?

I frequently see comments (such as this one by @SkewedZeppelin) talking about how LineageOS is not fully degoogled.

GrapheneOS is frequently cited as the most private mobile operating system, and naturally, from that perspective, it has to remove connections to Google, since Google doesn’t respect privacy.

However, GrapheneOS’s developers maintain that it is not supposed to be degoogled by design, but that that merely happens as a side-effect of their privacy and security improvements.

Here’s my question then: how degoogled actually is GrapheneOS? Does it make any connections to Google (without the user explicitly initiating it, such as by installing sandboxed Google Play Services)?

As long as you don’t install Play Services or Google EUICC (which really should be called LPA btw), then there is only SUPL I think where some information about the device could be transmitted to Google (through a GOS proxy server). There’s more info on that here: Frequently Asked Questions | GrapheneOS But really GOS is very close to fully degoogled as far as it is possible with AOSP.


All connections it makes are documented in the FAQ.

Whether it is degoogled or not does not really matter. What matters is that it is privacy respecting and its security.

GrapheneOS doesn’t make any direct connections to Google. It does however proxy connections to Google through Attestation Key Provisioning and the SUPL. The SUPL can be disabled, the Attestation Key Provisioning can’t.

