# Thoughts on Using Separate Devices for “Private” and “Everyday” Activities?

**URL:** https://discuss.privacyguides.net/t/thoughts-on-using-separate-devices-for-private-and-everyday-activities/35179
**Category:** Questions
**Tags:** please-eli5
**Created:** 2026-02-04T13:56:03Z
**Posts:** 53

## Post 1 by @rob45ls — 2026-02-04T13:56:03Z

I’ve been thinking about the idea of separating digital activities across different devices — for example, one device for everyday use (social, shopping, casual browsing) and another for more privacy-sensitive tasks. For those who’ve tried this approach, did it meaningfully improve your threat model, or did it mostly add complexity? How do you decide what belongs on which device?Curious to hear practical experiences and whether people feel this separation is worth the effort.

---

## Post 2 by @anon80329175 — 2026-02-04T14:09:29Z

Using difference devices is overkill if you ask me.

Using different browsers, PWAs, browser profiles, user accounts on your device, etc. are all better or good enough options to compartmentalize your activities.

To me its not worth the effort nor the cost to maintain multiple devices for each type of use case.

---

## Post 3 by @PurpleDime — 2026-02-04T14:52:30Z

> [@anon80329175](#):
>
> Using difference devices is overkill if you ask me.

I think it depends on what for. If I could afford it, I would definitely use separate devices for separate things. I don’t think it’s strictly a privacy issue, though.

**WORK DEVICES**

_ **Work Laptops** _

Many people have had jobs where they have been issued work laptops, including myself. Many of them do a lot of personal things on their work laptop, even NSFW things, which is insane. I know this because the head of IT in my last company told me so many stories of the kind of personal info past employees leave behind. Some people left hundreds of photos from their personal life on their work laptop.

I myself, have only allowed myself to check my personal email on my work laptop, beyond that I never saved any personal information and I never visited controversial sites on it, which from a professional perspective can include NSFW sites, file sharing sites, but also sites that badmouth your employer or are clearly on the opposite side of them politically. I would never visit a union site on my employer’s computer, not even from home.

_ **Work Phones** _

I’ve never had a work phone, but I know many people who have. I also know many people who were required to use their personal phone for work stuff like social media. Hence, the need for separation.

**SHARED DEVICES**

I personally do not like lending my computer to anyone, or even letting someone use my computer for something. Although I haven’t had to do that in years, it sometimes happens. Having a second computer where none or most of my personal life is visible is preferable.

I feel the exact same way about external hard drives and thumb drives because I always fear that someone will mistreat them or drop them. Hence, I try to have one that is for lending, so that if whoever I lend it to breaks it, or accidentally install a virus on it, or loses all my personal files that were on it, the damage is contained.

**FINAL THOUGHTS**

IMHO, unless you have unique needs, having more than 2 devices for separating certain aspects of your like is overkill. But 2 IMHO, is perfectly reasonable if you can afford it and if it works for you. Two computers plus two mobile devices.

---

## Post 4 by @KathyM — 2026-02-04T16:36:55Z

If you have cash to burn then absolutely get another device.

If you don’t, and aren’t expecting a targeted attack, then hardening your regular device is fine.

If you don’t, and are expecting a targeted attack then time to install graphene and qubes, reject all un-encrypted phone calls, etc etc.

---

## Post 5 by @kissu — 2026-02-04T18:42:27Z

Me after reading this message from @KathyM, thinking what all users from PG community with a work + personal GOS phone are in real life :joy:

![giphy](https://forum-uploads.privacyguidesusercontent.com/original/3X/d/2/d223107a230e2417e5f1806754ff628e11ba3fe4.gif)

---

## Post 6 by @FranklyFlawless — 2026-02-04T21:15:14Z

The idea can work if you are able to sustainably maintain both devices’ separation, but the practice itself may not necessarily decorrelate your digital identity across devices depending on your threat model.

---

## Post 7 by @iluvprivacy — 2026-02-12T14:56:07Z

I’ve been thinking about how to best do this since I just got my third phone in preparation to install GrapheneOS on it. I’ve used two phones for years as a way to separate work from personal data. So now I’m going to have iOS, Google Pixel, and GrapheneOS. How would you guys approach this if you’re me? If you were going to pick one phone to install apps like Facebook and Instagram, which OS would you pick?

---

## Post 8 by @dadnerd — 2026-02-12T17:38:38Z

TLDR; You have two options:

a. Use the proprietary apps on your iPhone and isolate all sensitive and private data onto the GrapheneOS phone. (In this case you can stop using the stock Android phone, or use it for a dedicated purpose like work or travel.)

b. Install the proprietary apps in the private space or a secondary user profile on the GrapheneOS phone. While this will be a “more secure" platform to install the apps, you risk weakening the security & privacy of the device by installing such invasive apps.

I would lean towards option a.

With their new AI integration and enshittification, the gap is closing fast, but I believe Apple still has a slight privacy edge over Google in their mobile OSes.

Personally I would only ever use proprietary apps (especially social media) on a dedicated device that was only used for those apps, and then could be turned off and stored in a Faraday bag when not in use. I understand not all people are going to do that, but design your system to isolate those apps as much as possible, as they will be harvesting data from your phone and from other apps if they are used on a stock OS.

Using them on the GrapheneOS phone (preferably in the private profile or a secondary user profile) will somewhat contain their data harvesting, but the reality is we know that software from tech giants doesn’t work like they say it does (we know this from hundreds of lawsuits over the last decade where they have repeatedly been found guilty of lying about the data collection practices of their software). Because of this, I personally believe that installing apps like this, even on a hardened OS like GrapheneOS, is too much of a risk for certain threat models.

---

## Post 9 by @Man — 2026-02-12T18:33:04Z

Unless you are paying 2026 RAM prices I don’t see why not. Used Windows 10 PCs are affordable and cost less than a KVM to share screen and periphials. You will need a KVM for instant switching but I’d recommend if you run 2 PCs to play games with anticheat or download untrusted files.

---

## Post 10 by @iluvprivacy — 2026-02-12T22:22:29Z

Yes, I agree, and I buy used so the costs aren’t too bad.

What is a good high-quality KVM? It needs to be Windows, macOS, and Linux compatible.

---

## Post 11 by @Scott — 2026-02-12T23:02:30Z

> [@iluvprivacy](#):
>
> If you were going to pick one phone to install apps like Facebook and Instagram, which OS would you pick?

The GrapheneOS phone and have the FB IG apps in a second profile.

---

## Post 12 by @iluvprivacy — 2026-02-15T02:42:23Z

I have to admit, it’s tough figuring out which phone to put the apps on. On the one hand, GOS seems really hardened and might be the better choice. However, for communication, I would prefer GOS over the other two OS due to GOS’ commitment to privacy and security.

I guess prioritizing apps like Google and Facebook on iOS. Whatever isn’t available on Apple, install it on stock OS Pixel. Keep web browsing and communication on GOS. Only install the bare minimum and FOSS apps on GOS.

For the desktop computing environment, I would do most web apps/browsing, video/voice calls, and Signal on a Linux build. I also have a M4 Mac Mini. I’ll only use Mac apps and whatever web activity that can’t be conveniently done on Linux. Adobe and Microsoft apps will be used on Windows. I’ll also game on this machine. This will be a new build and, despite RAM prices, I also want to play and learn AI. No web browsing and communication will be done on the Windows machine.

So this is sort of a rough game plan to isolate things. It’ll be a mix of new and used components/parts to keep costs as low as possible.

---

## Post 13 by @dadnerd — 2026-02-15T05:52:12Z

> [@iluvprivacy](#):
>
> Only install the bare minimum and FOSS apps on GOS.

This is my approach. Some people feel this is overkill and like it’s fine to install whatever you want in a separate profile.

> [@iluvprivacy](#):
>
> Signal on a Linux build.

If you’re worried about your comms being secure, running Signal on a Linux machine is almost certainly going to be your weakest link. Like, there’s not really a lot of benefit to compartmentalizing your comms all to this separate GOS phone just to run Signal on Linux. (Ignore this advice if you’re somehow planning to have separate Signal accounts, which is totally an option.) Also, I think your best bet for Signal on Linux is either running it on a .deb based distro or running it in a .deb VM. The containerization options (like Distrobox) I think mostly (or all) significantly reduce the sandboxing of the app (by design). I tried running Signal that way and ultimately decided it didn’t feel like a good solution for me.

---

## Post 14 by @anon63272567 — 2026-02-15T06:17:32Z

That’s how I operate. One “clean” device, one “dirty” device. Former has important stuff, later privacy invasive. Both are hardened. At one point I was using three devices but it was too much of a hassle to keep up. You can pair up iOS and Android and get the best of both worlds if you wish so.

---

## Post 15 by @iluvprivacy — 2026-02-15T06:23:03Z

When I’m home, I prefer to use a computer so that’s why I said use Signal on Linux. I need a physical keyboard. I’m not against using macOS if it makes sense. Definitely not Windows. I don’t trust Microsoft!

---

## Post 16 by @dadnerd — 2026-02-16T05:36:14Z

> [@dadnerd](#):
>
> your comms being secure, running Signal on a Linux machine is almost certainly going to be your weakest link. Like, there’s not really a lot of benefit to compartmentalizing your comms all to this separate GOS phone just to run Signal on Linux. (Ignore this advice if you’re

It’s an option to connect your GOS phone to a monitor and bluetooth keyboard & mouse. I think it’s honestly a good option for a lot of people. Then you can game and stream stuff and do all your more insecure stuff on a Linux laptop/desktop.

---

## Post 17 by @Colter — 2026-02-16T17:39:27Z

If you don’t have a very high threat model, then I think this is not worth the effort.

Put every proprietary app in private space and shut it down when it don’t need to run and your fine

---

## Post 18 by @iluvprivacy — 2026-02-17T11:53:10Z

Is that really usable, though?

---

## Post 19 by @dadnerd — 2026-02-17T17:03:21Z

For simple things like messaging, absolutely. It’s not a full desktop replacement, but if you need security it’s a good option to look into.

---

## Post 20 by @iluvprivacy — 2026-02-18T01:38:29Z

> **[‘Predator’ Spyware Used to Hack iPhone of Journalist in Angola](https://www.bloomberg.com/news/articles/2026-02-18/-predator-spyware-used-to-hack-iphone-of-journalist-in-angola)**
>
> A prominent journalist in Angola was targeted by a government-grade spyware in the first known case of its kind in the southern African nation, researchers have found.

Another example of a phone being infected after clicking on a link. I know the solution is to obviously not click any links or download any software from unknown sources. However, sometimes we do inadvertently click on something sent from a trusted contact. Is there a safer way to do that? I know I can avoid downloading or clicking anything with my phone. However, can I do this on a PC with WhatsApp in a VM or something so that I can check things out?

---

## Post 21 by @Tux — 2026-02-18T03:10:16Z

Absolutely, especially if you live in a country that “requires” (or at least makes it very inconvenient not to) use a device blessed by Apple or Google for banking or some related “official” activities. This means a GrapheneOS device for everyday use, and one cheap secondary device for the handful of apps which need a “certified” device. For work, a secondary Graphene user profile and a separate SIM may be enough however.

---

## Post 22 by @FranklyFlawless — 2026-02-18T03:20:54Z

> [@iluvprivacy](#):
>
> However, can I do this on a PC with WhatsApp in a VM or something so that I can check things out?

Yes:

> **[email - Disposable customization](https://doc.qubes-os.org/en/latest/user/advanced-topics/disposable-customization.html#open-a-link-in-a-disposable-based-on-a-non-default-disposable-template-via-command-line-from-app-qube)**
>
> Sometimes it can be useful to start an arbitrary program in a disposable. This can be done from an app qube with qvm-run-vm: | Introduction: A disposable can be based on any disposable template. You can have as many disposables or disposable...

There is an `email` qube referenced in this example, but that can be easily changed to a `whatsapp` qube or whatever name you want to identify it against the untrusted application.

---

## Post 23 by @to — 2026-02-18T14:31:40Z

If you’re thinking smartphone, Graphene’s Users feature is pretty much already this. By making multiple User profiles for different everyday tasks, you’re segregating that data just like having multiple phones, without actually having to manage multiple phones. Not to mention if one of the phones you’re carrying around isn’t GrapheneOS, your microphone, location, sensors, etc are all being tracked/logged to a degree.

I do still believe that separating tasks like you’re talking about is worthwhile, but there are more realistic ways to approach it. For example, assuming GrapheneOS, on a singular user profile you could have three levels of separation. Your personal/default profile, a work profile through say Insular or Shelter, and lastly your Private Space. Keep in mind Private Space will shutdown when you turn off your phone, where’s your work profile will continue to be active unless toggled off. So for example if you turn your phone off, Spotify would continue to play if installed on your work profile, but not on your Private Space.

An approach you could take, is keeping your personal/default profile “clean,” meaning only privacy respecting open source apps you trust/”private” tasks. Your work profile “moderate” say social, shopping etc. And your Private Space for more “aggressive” apps, like Google Maps, maybe banking apps etc.

Another benefit to this approach is isolating where you HAVE to have Google Play Services installed. Some apps like Google Maps and banking apps require Google Play Services to function. So if you want/need Google Maps, Gmail etc but don’t want to install Google apps on your personal profile, thus forcing you to install Google Play Services alongside them, by following the approach I laid out above, you can sandbox Google Apps/Play Services onto a private or work profile without the risk of any leakage from your more private tasks you would do on your personal profile.

I’ve found this three layer approach to be a good balance of isolating different aspects of life without too much hassle. Even the Multiple Users feature included with GrapheneOS I mentioned briefly at first can get annoying to navigate, so I’ve personally found this to be a feasible middle ground.

Hope this helps

---

## Post 24 by @iluvprivacy — 2026-02-19T11:42:10Z

I don’t have any experience with profiles, but is there a lag when switching between them? Are they both active simultaneously?

---

## Post 25 by @TinFoilHat — 2026-02-19T11:57:48Z

GOS multiple user profile feature is not the silver bullet against Google’s extensive reach.

There is a user report on GOS forum where Google managed to link a users’ real google account (logged in on another device and GOS device on owner profile) with the disposable account (logged in on GOS device on a non-owner profile).

IIRC there is no definitive answer on how it happened, but I suspect it is due to how GOS’s app sharing between profile works.

So, the bottom line, I would say, even you have to enable Google play service and google play store (due to workpalce email client requirement, for example), do not log in, do not use it, instead ustilise Aurora Store to obtain and update apps.

---

## Post 26 by @cyberoxide — 2026-02-19T12:11:38Z

I’d personally prefer such device for tours only with good cameras. I have a dedicated pixel 7a for this. Reason? Small, wireless charging, small battery, good signals, speakers, and good enough to be a private buddy on long tours instead of carrying main phone, i prefer some cash, card, and a private phone where only urgent calls can be received

---

## Post 27 by @iluvprivacy — 2026-02-19T14:04:24Z

Do you have a link to that thread?

---

## Post 28 by @anonymous462 — 2026-02-19T16:05:27Z

It is a good idea. [Internet Usage Segmentation Setup - The OPSEC Bible](https://bible.beginnerprivacy.com/opsec/internetsegmentation/)

---

## Post 29 by @to — 2026-02-19T19:36:05Z

Yep, I should’ve mentioned that in my post. Not a perfect solution, few things are, but yes definitely use Aurora Store instead of Google Play, and refrain from signing in at all. In the vein of workplace email/task requirements one must complete on their phone, I’m not sure if there is a good solution except simply not doing it, and only completing work tasks on a designated PC. Even carrying around a work phone with you could increase your attack surface to an extent. I guess it all depends on threat model and convenience.

I would be curious for a link to that thread if you happen to have it.

---

## Post 30 by @to — 2026-02-19T19:45:44Z

There is maybe a 5 second delay when switching between each user profile. The owner/system profile has some background services that persist, but secondary profile and apps are isolated and inactive until you switch to that profile.

---

## Post 31 by @TinFoilHat — 2026-02-19T20:04:28Z

> [@to](#):
>
> I would be curious for a link to that thread if you happen to have it.

> [@iluvprivacy](#):
>
> Do you have a link to that thread?

I spent some time looking for that thread, unfortunately I couldn’t find it, could be me forgetting the name of the thread (hence missing the keyword in search), or it got removed by GOS team (unlikely).

It is not too recent so my memory is getting vague, one of the keywords was Xiaomi, as the OP used Xiaomi phone as daily driver (!). I will spend some more time in searching, wish me luck.

---

## Post 33 by @FranklyFlawless — 2026-02-21T10:12:07Z

I am confident it is this topic:

> **[Play Store links “anonymous” owner profile to daily profile & phone -...](https://discuss.grapheneos.org/d/31071-play-store-links-anonymous-owner-profile-to-daily-profile-phone)**
>
> GrapheneOS discussion forum

---

## Post 34 by @dadnerd — 2026-02-21T16:07:46Z

I also don’t have a link, but this is absolutely the case between the main profile and the private space. Those two profiles enjoy some separation but also can very much share data (you don’t even need additional software to share files between these profiles).

---

## Post 35 by @dadnerd — 2026-02-21T16:10:14Z

On my gos phone it very much appears I can have two profiles running processes simultaneously. This seems to be the default actually.

---

## Post 36 by @iluvprivacy — 2026-02-24T02:03:01Z

I’m not sure if using private space is a better option of segregating data when there are now concerns that it’s not a foolproof solution. Having multiple devices is expensive, but buying used and not necessarily the latest models can make this very cost-effective.

---

## Post 37 by @iluvprivacy — 2026-02-24T02:08:57Z

Does stock Android on the Pixel series and GOS have the ability to minimize or even prevent cross-app tracking? iOS has it.

As part of my goal of segregating my activities to different devices, I’m leaning on using iOS as my apps phone. I’ll install all the Meta apps like Facebook and WhatsApp, and Google apps.

As I stated before, I’ll use GOS only for web browsing and communication via Signal. Only FOSS software will be installed on the GOS phone.

For the Pixel phone, I am still leaning towards not putting GOS on it, as I want to have Google Play and have a phone to test and use Android-only apps. I can also put my work/employer data on it.

My Pixel/GOS phone will only be used for personal use/data. So this is now my thinking for a 3 phone setup. Comments?

---

## Post 38 by @FranklyFlawless — 2026-02-24T02:10:21Z

> [@iluvprivacy](#):
>
> Comments?

Try it out and see if it works for you.

---

## Post 39 by @iluvprivacy — 2026-02-24T02:11:55Z

Yes, I will, as I already have the devices. I just need to flash one of the Pixels to GOS. I guess what I wanted to ask is: better to install Meta apps on iOS or stock Android?

---

## Post 40 by @FranklyFlawless — 2026-02-24T02:12:22Z

Neither, it is better not to install them at all to begin with.

---

## Post 41 by @iluvprivacy — 2026-02-24T02:13:30Z

Of course, but it’s not a viable option. Telling people to skip Meta and Google isn’t going to work for the general population.

---

## Post 42 by @fria — 2026-02-24T02:14:10Z

> [@iluvprivacy](#):
>
> Does stock Android on the Pixel series and GOS have the ability to minimize or even prevent cross-app tracking? iOS has it.

Yes effectively the iOS feature just prevents apps from seeing your advertising ID. On Android you can [delete](https://www.eff.org/deeplinks/2022/05/how-disable-ad-id-tracking-ios-and-android-and-why-you-should-do-it-now) it which is effectively the same thing.

---

## Post 43 by @iluvprivacy — 2026-02-24T02:17:14Z

Yes, I’ve already done that. So does it matter which operating system or phone to install the apps?

---

## Post 44 by @fria — 2026-02-24T02:20:19Z

iOS has a few things that protect you a bit more from third party apps, like iOS has a paste permission that stops apps from reading your clipboard whenever they want. It also has the Contacts picker which lets you pick and choose specific contacts instead of giving full access to all of them (GOS already has a more advanced version of this). iOS also has the local network permission which stops apps from seeing other devices on your network, which Android has an equivalent to but it’s not enforced yet. Overall, iOS is probably a bit better than stock Android at protecting you from third party apps, but that will likely change in the future when Android adds the same features.

---

## Post 45 by @iluvprivacy — 2026-02-24T02:44:29Z

Ah, thx and that’s what I needed to know. Has Google announced similar features for Android 17?

With regards to GOS, I’m not against having both Pixels with it, but how do I configure GOS to be more like Pixel’s Android and just work with Google Play and all of its apps like banking, Meta, and what not?

---

## Post 46 by @fria — 2026-02-24T02:45:01Z

> [@iluvprivacy](#):
>
> Ah, thx and that’s what I needed to know. Has Google announced similar features for Android 17?

Not that I’ve seen but we’ll see when it comes out.

> [@iluvprivacy](#):
>
> With regards to GOS, I’m not against having both Pixels with it, but how do I configure GOS to be more like Pixel’s Android and just work with Google Play and all of its apps like banking, Meta, and what not?

You would install sandboxed Google play and use it normally. Most apps work just fine.

---

## Post 47 by @iluvprivacy — 2026-02-24T02:53:08Z

I don’t want to fiddle around with different profiles. Will Google Play still be sandboxed?

---

## Post 48 by @FranklyFlawless — 2026-02-24T02:53:38Z

Yes:

> **[Sandboxed Google Play - GrapheneOS usage guide](https://grapheneos.org/usage#sandboxed-google-play)**
>
> This is a guide covering some aspects of using GrapheneOS. See the features page for a list of GrapheneOS features. | Usage instructions for GrapheneOS, a security and privacy focused mobile OS with Android app compatibility.

---

## Post 49 by @Colter — 2026-02-25T16:12:46Z

> [@iluvprivacy](#):
>
> For the Pixel phone, I am still leaning towards not putting GOS on it, as I want to have Google Play and have a phone to test and use Android-only apps. I can also put my work/employer data on it.

You can have Google Play on GrapheneOS.

> [@iluvprivacy](#):
>

> [@iluvprivacy](#):
>
> As part of my goal of segregating my activities to different devices, I’m leaning on using iOS as my apps phone. I’ll install all the Meta apps like Facebook and WhatsApp, and Google apps.

> [@iluvprivacy](#):
>
> As I stated before, I’ll use GOS only for web browsing and communication via Signal. Only FOSS software will be installed on the GOS phone.
> 
> For the Pixel phone, I am still leaning towards not putting GOS on it, as I want to have Google Play and have a phone to test and use Android-only apps. I can also put my work/employer data on it.
> 
> My Pixel/GOS phone will only be used for personal use/data. So this is now my thinking for a 3 phone setup. Comments?

Why not put the proprietary apps in the private space and the clean apps in the main space?

---

## Post 50 by @Colter — 2026-02-25T16:14:16Z

> [@iluvprivacy](#):
>
> ’m not sure if using private space is a better option of segregating data when there are now concerns that it’s not a foolproof solution.

Of which threat are you concerned that private space can’t prevent but seperate phones can?

---

## Post 51 by @iluvprivacy — 2026-02-25T22:52:30Z

Potential data leaking between the two profiles. I don’t trust it.

---

## Post 52 by @iluvprivacy — 2026-02-25T22:55:06Z

You’re not going to be able to convince me to use one phone for everything. Furthermore, I’ve already been using two phones for years. I never mix work and personal data in one device. For people who only use one device for everything, they probably won’t understand or care. It’s like the people who don’t believe in using a seatbelt or getting the COVID vaccine. At some point, it is what it is.

---

## Post 53 by @Colter — 2026-02-26T17:19:53Z

> [@iluvprivacy](#):
>
> Potential data leaking between the two profiles. I don’t trust it.

Do you mean for example that Google camera in the main Spaces could communicate with Google Play in the private space to share pictures?

It would be better to discuss this with clear scenarios in mind
