GrapheneOS Profiles: One Phone, Many Compartments

    CS
    Reviewed by CSG Security Engineers

    Updated August 2026 · 2 min read

    Profiles are one of the most powerful features GrapheneOS offers — isolated environments on one phone, each set up for a different part of your life. Done well, one handset behaves like several phones' worth of separation: your banking can't see your social apps, your work can't see your personal life, and none of them can see each other.

    What a profile actually is

    Every profile is its own complete instance: its own storage, its own apps and permissions, its own call, SMS and contact records, its own personalisation, and its own PIN and fingerprints. Nothing is shared between profiles by design. A few hardware-level settings — like tethering and the security configuration — stay with the owner profile, which is the one created when you set up the phone.

    Creating and switching

    Open Settings → System → Users. Add user creates a new profile; tapping an existing one switches to it. Switching is quick enough to do many times a day — and ending a session locks that profile's data back into its strongest encrypted state.

    Setting up a de-Googled profile

    New profiles start with no Google in them at all. To give one apps, open the built-in Vanadium browser, go to f-droid.org and install F-Droid, then use F-Droid to install Aurora Store — which lets you download anything from the Play catalogue anonymously, without a Google account.

    Setting up a sandboxed-Google profile

    To give a profile Google compatibility instead, install Google Play from the GrapheneOS App Store — it installs the Play Store, Play services and the special compatibility layer together, all running as ordinary unprivileged apps. Always use the GrapheneOS App Store version for this; don't sideload Play from anywhere else.

    Let calls and texts reach you in any profile

    By default, calls and SMS land in the profile that owns them. To have them follow you: in the secondary profile, open Settings → System → Users and enable send notifications to current user. Then switch to the owner profile, open Settings → System → Users, tap the secondary profile (without switching to it) and enable allow running in background and turn on phone calls & SMS.

    The strategy that works

    Live as much of your life as possible in a de-Googled profile, and keep a sandboxed-Google profile on standby for the apps that genuinely need it. If you want to go further, split the sandboxed side by sensitivity — one profile for banking, another for social apps — so even your Google-dependent apps are isolated from each other. The same trick cleanly separates work from personal, or makes a minimal travel profile with nothing worth taking.

    Good to know

    Each profile has its own PIN and fingerprints — and a profile you end the session on returns to full at-rest encryption, even while the phone stays on.

    Was this guide helpful?

    Know someone who needs this? Send them the guide.