Getting Your Apps on GrapheneOS

    CS
    Reviewed by CSG Security Engineers

    Updated August 2026 · 5 min read

    There are two rails for getting apps onto a GrapheneOS phone, matching the two setup styles: open app stores for a de-Googled profile, and sandboxed Google Play when you want the full catalogue with none of Google's usual power. Most people end up using both — in different profiles.

    The honest realities of a de-Googled profile

    Many Android apps are built assuming Google Play services is always there. With no Play services installed, some apps won't launch, some run with missing features, and push notifications for certain apps arrive late or not at all — apps fall back to periodically checking in rather than being instantly pushed to. None of this is a GrapheneOS fault; it's how those apps were built. Privacy-respecting apps — Signal, the Proton suite, most open-source tools — generally work perfectly.
    Two more realities: updates aren't automatic (nothing runs in the background checking versions, so open Aurora Store every week or two and update from there), and some banking, finance and government apps run integrity checks that fail on any non-Google-certified system — sometimes with an insulting "device not secure" message. That's a developer's certification choice, not a reflection of your actual security. The workarounds: install those apps in a sandboxed-Google profile, or just use the website — myGov, for example, works fine in the browser.

    Aurora Store: the Play catalogue, anonymously

    Aurora Store is an open-source storefront that fetches apps from Google's official catalogue — without you having a Google account. On first launch it asks for a series of permissions; grant them, then choose Anonymous at the sign-in screen. Aurora connects through a disassociated account, so your installs stay private while still coming from the official source.
    Two features make Aurora genuinely great for this life. Under every app listing sits a compatibility section: the developer's official Play-services requirement, followed by the community's verdict on whether it actually works without Google — real-world answers from people running phones like yours. Below that, a privacy report lists the trackers the app is known to contain, from invasive analytics down to optional crash reporting. Between those two panels, you can judge almost any app before it ever touches your phone.

    Good to know

    Every install on GrapheneOS asks one extra question no other phone asks: should this app have network access? An offline tool doesn't need the internet — deny it, and its trackers can never phone home. Install one app at a time, though: interrupting the permission prompt can silently fail the install.
    F-Droid deserves a mention alongside Aurora: it's the long-running store for free and open-source apps, and the usual way to bootstrap Aurora itself into a fresh profile.

    Sandboxed Google Play: the full catalogue, defanged

    When you want the real Play Store, install it from the GrapheneOS App Store — one install delivers the Play Store, Play services and the compatibility layer together, all running as ordinary sandboxed apps with no system privileges. You'll sign in with a Google account that operates at the app level only: it isn't required for the phone itself, and nothing auto-connects to cloud sync or backups. We have a full walkthrough for creating that account the private way — with an encrypted email as its foundation — in our de-Google guide.

    The apps already on the phone

    GrapheneOS ships a deliberately small set of first-party and AOSP apps, each chosen to do its job without reporting to anyone. The stars: Vanadium, a hardened Chromium browser with strict site isolation and none of Chrome's Google integration — the most security-hardened browser on any phone. The Camera keeps location metadata out of your photos unless you explicitly allow it. The PDF Viewer treats documents as the attack vector they are, rendering them in a sandbox. And Auditor is something special: it cryptographically verifies another GrapheneOS phone hasn't been tampered with — grab a friend with one and you can attest each other's devices.
    The rest cover the basics locally and quietly: Contacts (with scopes, so an app demanding your address book can be shown only the entries you pick), Files (storage scopes — apps see only what you grant), Messaging (plain SMS/MMS, stored locally; pair it with Signal for anything sensitive), Gallery, Telephone, Clock, Calculator, and the GrapheneOS App Store itself — which you'll mainly use for system apps, sandboxed Play and Android Auto rather than everyday installs.

    The apps worth adding

    Signal for messages and calls — end-to-end encrypted, nearly metadata-free, and the answer to SMS's shortcomings. Aves as a friendlier gallery than the built-in one, still fully local. Brave if you want a second browser: Vanadium is unbeaten on security, Brave adds aggressive tracker and ad blocking — many people run both. For navigation, Organic Maps and CoMaps are the fully private choices; Waze is the honest compromise — data-hungry by nature, but run as a guest in a de-Googled profile its collection is effectively anonymised. Your call on where convenience sits.
    And the Proton suite — Mail, VPN, Pass and Authenticator — which replaces the Google services you just walked away from. That swap is its own guide, and it's the one that makes the whole phone make sense day to day.

    Proton Unlimited

    One subscription covers the encrypted replacements for Gmail, Drive, Photos backup, your passwords and your VPN — the complete Google exit, from the people who built it for exactly this.

    Get Proton Unlimited

    Good to know

    Wondering about a specific app before you commit? Our app compatibility checker on the privacy-phones page searches community reports for 10,000+ apps — including whether yours works de-Googled.

    Was this guide helpful?

    Know someone who needs this? Send them the guide.