Replace Google's Services: The De-Google Stack

    CS
    Reviewed by CSG Security Engineers

    Updated August 2026 · 5 min read

    A new phone is the one moment you get to rebuild your digital identity from scratch — so build it in the right order. The strategy: an encrypted Proton account becomes your real home, and Google gets demoted to a locked-down key that exists only to open the app store. Do this before you fill the phone with apps, while there's nothing to untangle.
    Best done with a computer alongside your phone — you'll be scanning QR codes from one screen with the other.

    Step 1 — Create your Proton account

    On your computer, go to proton.me and create your account. Choose a username you're happy to live with — it becomes your email address — and a password of at least 16 characters that you've never used anywhere: mixed case, numbers, symbols. Write it down somewhere physically safe for now; a password manager comes later in this setup.
    When Proton offers your recovery kit, download it and store it somewhere safe — it's your lifeline if you ever forget the password. On a paid plan you can leave the recovery email and phone number blank (the kit is your safest recovery method, and every blank field is one less thing linking the account to you). On a free account, Proton usually requires a phone number as human validation — one of several reasons the paid tier is the cleaner start.

    Proton Unlimited

    The free tier works, but Proton Unlimited unlocks the full security kit this guide uses — Sentinel attack protection, dark-web monitoring — plus the Mail, Drive, Pass and VPN you'll want on this phone anyway. One subscription, the whole Google exit.

    Get Proton Unlimited
    Keep the browser tab signed in — we come back to harden this account in a few minutes.

    Step 2 — Create a Google account that knows nothing

    Your sandboxed Play Store needs a Google account — but it doesn't need to be *you*. Go to accounts.google.com/signup and work through the prompts. The details don't have to be accurate; just note down whatever birthdate you give, in case you ever need it for account recovery.
    Here's the important move: when Google asks you to create a Gmail address, choose "use your existing email" instead — and enter your new Proton address. Verify with the code Google sends to Proton, then set a password following the same rules as before, but different from your Proton password. Google may demand a phone number or QR scan as an anti-spam check depending on your connection — comply if you must; it can be removed shortly.
    What you've just built: a Google identity with no Gmail inbox accumulating your life, whose recovery path runs through an encrypted service Google can't read.

    Step 3 — First app: Proton Authenticator

    Sign in to the Play Store on your phone with the new account, and make your very first install Proton Authenticator — it generates the 2FA codes that will guard both accounts, entirely offline, no account or cloud required. When GrapheneOS asks whether it should have network access: it works fine without.

    Step 4 — Lock down Proton

    Back on the computer: Proton Settings → All settings → Account & password. Enable two-password mode — one password for the account, a separate one to decrypt your mail. Follow the prompts: your primary can stay as the password you created; the second can come from the built-in generator. Note it down with the first.
    Then switch on the authenticator-app toggle under two-factor authentication. A QR code appears — open Proton Authenticator on the phone, tap +, allow the camera, and point it at the code. The entry appears with a six-digit code that renews every 30 seconds; type the current one into the browser to confirm. Proton then shows one-time backup codes — record these somewhere safe. They're how you get in if the phone is ever lost.
    Finally, under Security & privacy: enable Proton Sentinel if you're on a paid plan (their strongest protection against sophisticated account attacks), turn on dark-web monitoring for early warning when your address shows up in a breach dump, and enable detailed events so unusual account activity leaves a visible trail.

    Step 5 — Lock down the Google key

    Now the Google account, in its security settings: turn OFF "skip password when possible", and remove any recovery phone number that snuck in during signup — your Proton address is the only recovery path this account needs. Turn on two-factor authentication and choose authenticator app: same QR ritual, scan with Proton Authenticator, verify. When Google pushes for a phone number, skip it. Then find the newly available recovery codes option, generate them, and file them with your other codes.

    Good to know

    Authenticator codes live only on your phone — that's their strength and their risk. The backup codes you saved in steps 4 and 5 are what stand between a lost phone and lost accounts. Paper, somewhere safe, genuinely matters here.

    What you've built — and the rest of the swap

    You now have an identity stack most security professionals would envy: an encrypted home base guarded by two passwords, app-based 2FA and active threat monitoring — and a Google account that owns nothing, syncs nothing, and recovers only through a service that can't read your mail. From here the rest of the de-Google swap is one service at a time: Proton Mail replaces Gmail, Proton Drive takes storage and photo backup, Proton Pass takes every password out of your browser and your memory, and Proton VPN puts a tunnel under it all — each has its own step-by-step guide on this site when you're ready.
    Install apps freely now — the keys to everything are already out of reach.

    Was this guide helpful?

    Know someone who needs this? Send them the guide.