First 24 Hours with GrapheneOS: What to Actually Do After Flashing

You flashed GrapheneOS. Now what? The actual day-one setup sequence, in order — verify, lock screen, the Google Play decision, browser, radio settings, and the permission pass that makes the whole thing worthwhile.

Share
First 24 Hours with GrapheneOS: What to Actually Do After Flashing

This guide starts after GrapheneOS is installed and the bootloader is relocked. It covers the decisions that come next: your unlock method, whether and where to install sandboxed Google Play, app sources and permissions, and the functional checks that confirm the phone actually works. If you have not installed GrapheneOS yet, start with the installation guide.

Some steps are baseline, some are choices. Each step below is marked (required) or (optional) so you can tell the difference: required steps affect security or basic function on most devices; optional steps depend on your threat model, carrier or carrier support, and how you use the phone.

The order of operations, in one glance:

  1. Verify the flash worked (Auditor) — (optional)
  2. Lock screen — choose your unlock credential. (required)
  3. The Google Play call — none, the owner profile, or a separate profile. (required decision)
  4. Browser — Vanadium. (default; optional to change)
  5. Two radio settings — LTE-only, network location. (optional)
  6. First apps — Signal, Bitwarden, then the rest. (optional)
  7. One permission pass — the ten minutes that does most of the work. (required)
  8. Functional checks — calls, data, notifications, essential apps, backups. (required)

Work down that list and you're done. Each step below is the "why" and the "how." Prefer to tick it off as you go? The interactive first-24-hours checklist is this exact sequence in a form that saves your progress.


1. Verify before you configure anything (optional)

Auditor is a worthwhile first check, but it is not mandatory — you can configure and use the phone without it. Auditor ships with GrapheneOS, so there is usually nothing to install — update it from the GrapheneOS App Store if a newer version is offered. Verification itself is not a single-device action. It is a pairing-based exchange between two devices:

  • The Auditee is your new phone — the device being verified. It must be a device GrapheneOS supports for verification.
  • The Auditor is a second Android 13-or-later device with a camera, running Auditor.

You point each device's camera at the other's QR code to exchange a challenge and the attestation, then read the result. Each unique pairing produces its own fingerprint, so the same phone verified by two different Auditors shows two different fingerprints. Alternatively, set up scheduled remote verification: create an account at attestation.app from a separate device, press "Enable remote verification" in the app, scan the account QR code, and configure an alert email so you are told if the device stops providing valid attestations. Remote verification also needs the Auditee to have network access.

Either path verifies the device against a hardware-backed key: it confirms the bootloader is locked, the installed OS is the official GrapheneOS build, and the verified-boot state matches GrapheneOS's signing keys. The check is chained from hardware, not something an app can assert on its own. Full steps are in the Auditor tutorial.

The limits are practical: local verification needs a second Android 13+ device with a camera, and ongoing remote attestation needs an account and connectivity. If you do not have a second device today, skip it — nothing else in this guide depends on verification, and you can pair an Auditor later.


2. The lock screen decision that affects everything downstream (required)

Your lock-screen credential is one input to disk-encryption key derivation, not the key material by itself. The OS derives a password token from the profile's credential with scrypt, stores a high-entropy Weaver token in the secure element, and the TEE combines the password token, Weaver token and other values such as the verified-boot key into a hardware-bound key derivation — so the credential alone cannot decrypt the data. GrapheneOS documents this in its disk-encryption FAQ.

Because auto-reboot is on by default at 18 hours, the phone regularly returns to a Before First Unlock state where those keys are evicted from memory. The timer is worth understanding correctly: it starts each time the device is locked and is cancelled by a successful unlock of any profile, so 18 hours is the longest the device stays locked before a reboot, not a fixed reboot schedule. Every unlock re-derives the encryption keys from what you typed plus the secure-element material.

That makes the credential the decision everything else leans on, but it does not mean a passphrase is the only sane choice:

  • A random 6+ digit PIN is reasonable for many people. The secure element throttles unlock attempts very aggressively, so an actually random PIN is hard to brute-force even off-device — GrapheneOS documents this as a deliberate reason it supports diceware passwords for users who would rather not rely on that throttling.
  • A passphrase (diceware, several random words) has far more entropy and does not depend on the secure-element throttling holding up. GrapheneOS supports up to 128-character passwords without a device manager.

The failure mode to avoid is a guessable credential — a birthday, a repeated pattern, a 4-digit code. Whichever you pick, make it random. If you want the wider comparison across PIN, pattern, password and biometric locks, that is covered in the most secure way to lock your smartphone.

A common middle ground is a passphrase as the primary unlock method plus fingerprint for convenience. If you want the fingerprint to remain a convenience rather than a full unlock, GrapheneOS can require a second-factor PIN after a fingerprint (optional): Settings → Security & privacy → Device unlock. That keeps a strong primary credential while allowing quick daily unlocks.

Scramble PIN (optional) randomizes keypad positions on each unlock attempt, which raises the difficulty of reading a PIN from physical proximity or a motion side-channel. It applies to the lock screen and to SIM PIN/PUK. It only matters if you use a PIN — if you chose a passphrase, skip it. This is why the two steps belong together: recommending a passphrase and then unconditionally telling you to scramble a PIN never made sense.

Auto-reboot defaults to 18 hours and can be set from 10 minutes to 72 hours, or turned off: Settings → Security & privacy → Exploit protection → Auto reboot. Leaving it on is the point — it is what returns the device to the keys-evicted state after a long locked period. The countdown restarts on every lock and is cancelled by unlocking any profile, so lowering it shortens the longest window the device stays locked without a reboot. The auto-reboot cycling through the Before First Unlock state is only valuable if the credential protecting it is actually hard to brute-force — which is the whole argument for rebooting your phone as a security habit in the first place.

Two device settings to confirm before you move on

OEM unlocking should be off once the installation is complete. It exists to permit a bootloader unlock, so leaving it on keeps that door open. GrapheneOS's setup wizard disables it by default at the end of setup with an opt-out toggle; confirm it under Settings → System → Developer options → OEM unlocking and turn it off if it is still enabled. You can turn it back on later if you ever need to unlock the bootloader again.

A duress PIN/password is a destructive feature, not a routine checkbox. Entering one at any prompt that asks for your device credentials irreversibly wipes the device, including any installed eSIMs. The wipe needs no reboot and cannot be interrupted. Enabling the feature requires setting both a duress PIN and a duress password, because different profiles can use different unlock methods; each applies to its matching prompt. If you set a duress credential identical to your real unlock method, the real one takes precedence and no wipe occurs. Configure it only once you understand the trade-off, and never test it on a phone holding data you need: Settings → Security & privacy → Device unlock → Duress Password.


3. The Google Play decision (required decision)

This is the most consequential choice you'll make on GrapheneOS. Worth thinking through before just installing Play and forgetting about it.

No Google Play at all is viable for more people than they expect. Signal, Bitwarden, Vanadium, and F-Droid cover a lot of ground. Worth testing for a week before you decide you can't live without Play. A lot of people discover they only needed three Play apps and two of those have F-Droid alternatives.

Sandboxed Google Play is the practical choice for most people. On GrapheneOS the Play apps are ordinary sandboxed apps with no special privileges — GrapheneOS's own guidance notes the simplest approach is to use the owner profile alone, because apps there are sandboxed exactly the same way as anywhere else. Install it from the GrapheneOS App Store (not the Play Store), which installs Play services and the Play Store correctly as unprivileged apps.

The alternative layout is to install Play only in a separate user or work profile, so that only the apps in that profile can use it. Those two are not interchangeable. A secondary user is a separate Android user with its own encryption key; you switch to it through the user switcher, and its apps do not appear in the owner profile's launcher. A work profile keeps its apps in the same launcher behind a work badge, but on GrapheneOS it has to be created by a device-controller app, it is less isolated than a separate user, and it is only as trustworthy as that controller. Either way it is a real trade-off, not a free upgrade:

  • Play-dependent apps must be installed in that profile; with a secondary user you switch users to reach them.
  • Some functionality is profile-sensitive. RCS with Google Messages, for example, is currently only known to work in the owner profile, and Android Auto has its own setup path (including inside Private Space).
  • Notification forwarding from a background user is available but is another thing to configure.

Choose the separate-profile layout when you specifically want to limit which apps can reach Play. Choose the owner profile when you want the simplest setup and are comfortable with Play being available to apps there — they remain sandboxed either way. The goal is to match the layout to how you use the phone, not to impose one layout on everyone.

Whichever you choose, if you installed Play, grant it one battery optimization exception or push notifications won't arrive reliably: Settings → Apps → Google Play services → Battery → Unrestricted.

One thing to settle now rather than discover later: a handful of apps won't cooperate no matter where you put Play. Most banking apps work, especially with sandboxed Google Play, but some demand Google certification and misbehave, and Google Wallet tap-to-pay currently does not work — it requires device certification and hardware attestation that a non-certified OS cannot provide. That is a limitation of Google's current enforcement, not a setting you can flip, and the NFC hardware itself is fine. If a specific app is a dealbreaker, check it against what works and what breaks on GrapheneOS before you rely on it.


4. Browser (default; optional to change)

Just use Vanadium.

It ships with GrapheneOS. Hardened Chromium, site isolation enforced, JIT compilation disabled by default, virtually all remote Google services stripped out. It's also the WebView implementation for the OS: nearly all apps that embed web content use it, though a few ship their own engine. Using Vanadium as your daily browser means you're not running two separate browser runtimes side by side.

First thing to set: default search engine. Settings → Search engine. Beyond that, it works out of the box.

If you want Brave instead, that's fine — Brave Shields handles ad and tracker blocking without extension configuration, and it's a reasonable hardened Chromium alternative. GrapheneOS doesn't recommend it over Vanadium, but it's not a bad call.

What you shouldn't install is Firefox. On Android, Firefox has no site isolation and no internal process isolation — Gecko simply doesn't implement these on the platform. That's not a general knock on Firefox. It's a specific limitation of how the browser engine handles Android's process model, and on a security-focused OS it's the wrong trade-off.


5. Two radio settings worth doing today (optional)

Both of these are optional and depend on your carrier and threat model. Neither is a blanket privacy fix.

LTE-only mode. Settings → Network & internet → SIMs → [your SIM] → Preferred network type → LTE only.

This reduces attack surface by removing the legacy 2G/3G and 5G code paths the radio would otherwise use. GrapheneOS is explicit that LTE-only mode "is not intended to improve the confidentiality of traditional calls and texts," though it "might somewhat raise the bar for some forms of interception." It is not a defense against cellular tracking: your carrier still sees your device attach to its network and still has a location estimate from the towers you connect to. Treat it as attack-surface reduction, not anonymity, and not a substitute for end-to-end encrypted calls and messages.

You'll need VoLTE (or VoWi-Fi) active on your SIM for calls — most carriers support it now, but confirm before flipping the switch, because if calls break you'll want to toggle LTE-only back off. On sixth-generation and later Pixels, GrapheneOS also exposes an Allow 2G toggle you can leave off.

Network location provider. Settings → Location → Location services → Network location.

The honest description here matters. GrapheneOS offers two options: use Apple's network location service directly, or use a GrapheneOS proxy to that same service. The proxy does not replace the backend — it sits between your device and Apple's service, so your device's location queries are relayed through GrapheneOS infrastructure rather than contacting Apple directly, and it supports offline use from a short-lived cache. Apple's service is still the data source today; GrapheneOS is building its own database and service to replace it. So the proxy reduces direct exposure to Apple but does not mean "your queries never involve Apple's infrastructure." It also needs Wi-Fi enabled (or Wi-Fi scanning on, or cell reception as a coarse fallback) to work.

MAC randomization is already on by default in a stronger form than stock Android: GrapheneOS uses per-connection randomized MAC addresses rather than a single persistent per-network address. Leave it unless your router assigns DHCP leases by MAC address and you're getting conflicts, in which case switch to per-network randomized MAC (Settings → Network & internet → Internet → [network name] → Privacy). Otherwise, the default is fine.


6. What to install first, and where to get it (optional)

Signal. Bitwarden. Then everything else. None of this is mandatory — it is simply the usual starting point.

Signal because in 2026 there's no good reason to leave your message graph on a corporate server, and standard SMS/MMS are not end-to-end encrypted. Bitwarden because you're on a fresh install and your passwords need to be somewhere immediately. (New to it? Here's the full Bitwarden setup walkthrough.) Both are optional: use whichever messenger and password manager fit your threat model.

For app sources: GrapheneOS App Store first (sandboxed Google Play, Auditor, and a few others). Then Accrescent — a limited catalog of developer-signed APKs with reproducible builds. F-Droid re-signs packages with its own key rather than the original developer's signing key, which is a different trust model rather than a strictly worse one. Within F-Droid, the IzzyOnDroid repository carries developer-signed packages. For everything else: sandboxed Play in whichever profile you chose in step 3.

Sideloading direct APKs: enable install-unknown-apps for whichever app you're installing from, install, disable it immediately after. Don't leave it open.


7. One permission pass after you're done installing (required)

GrapheneOS adds per-app network and sensor toggles that don't exist on stock Android. Running through them once after your initial app setup is worth the ten minutes — this step, more than any single setting, is what turns a technically-private phone into an actually-private one.

Network toggle (Settings → Apps → [app] → Permissions → Network): any app with no reason to phone home — offline tools, note apps, games — block it. The app receives a standard network-unavailable error. It can't tell it's been cut off rather than offline. This is one of those controls that doesn't exist on stock Android at all, which is worth sitting with for a moment.

Sensors toggle: on stock Android, several motion sensors — the accelerometer, gyroscope, compass and barometer — are available to apps without a runtime prompt, while others such as the step counter and activity recognition are gated by existing Android permissions (Activity Recognition, Body Sensors). GrapheneOS adds a per-app toggle covering all the sensors not already covered by those Android permissions — go through anything that has no plausible reason to read motion data. The list is usually longer than expected.

Storage Scopes: where you granted broad storage access during setup, check if you can scope it. Settings → Apps → [app] → Permissions → Storage Scopes. The app sees exactly what you've authorized and nothing else — it can't distinguish the scoped view from full access. GrapheneOS documents the caveat: an app that loses its Storage Scopes grant can lose access to files it created if you uninstall and reinstall it, and you can re-grant access through the file picker.

Contact Scopes is the same idea for contacts: if an app demands the all-or-nothing Contacts permission, you can enable Contact Scopes instead and grant read access to only a contact, a group, or specific data. Write access is blocked while it is enabled.


8. Functional checks before you call it done (required)

The setup sequence is only finished when the phone does the things you need it to. Run these checks yourself — they take a few minutes and catch the problems that are annoying to find later:

  • Calls, SMS and mobile data. Place a call and send/receive an SMS. Confirm mobile data works. If you enabled LTE-only and calls fail, your carrier likely doesn't support VoLTE on this device — toggle LTE-only back off.
  • Notifications while the screen is locked. Lock the phone, then have someone message you on Signal and another app. Confirm notifications actually arrive. If they don't, revisit the Google Play battery exception and per-app notification settings.
  • Required bank and work apps. Open each one and complete a real login. Do not test a banking app by making an actual payment — a login exercises the same certification and Play-services checks without moving money. Certification-dependent apps are where GrapheneOS setups fail, and finding out at a checkout counter is worse than finding out now.
  • Backups and recovery access. Confirm you can reach your password manager, your authenticator codes and any account recovery material from this phone. Then make a backup of anything you have already created on it.

If one of these fails, work out whether it is a compatibility or carrier limitation before assuming a misconfiguration, and vice versa — the compatibility guide covers the common cases.


When you're done

Privacy Guides recommends GrapheneOS for anyone with a Google Pixel, citing its security hardening and additional privacy features; its criteria require the Pixel hardware to meet GrapheneOS's security requirements. The setup above is what puts you on the right side of that recommendation in practice rather than just technically running the OS.

The work is front-loaded. After the permission pass, the radio settings and the functional checks, there's nothing left to configure — the phone is meant to be used, not continually tuned. The complete Android privacy guide covers the threat model behind these decisions if you want to understand why the defaults land where they do. And once Bitwarden is set up, the passkey workflow is worth building out — a fresh GrapheneOS install is exactly the right moment to form the right habits. If you're going to add a hardware security key to that, a fresh device is the cleanest time to enroll a YubiKey.


Frequently Asked Questions

Should I set a PIN or a passphrase?

Either can be fine if it is random. A random 6+ digit PIN is protected by the secure element's aggressive attempt throttling, which is why GrapheneOS supports it as a reasonable choice. A passphrase (diceware words) has more entropy and does not rely on that throttling. What matters is avoiding a guessable credential. The fingerprint vs PIN breakdown covers how biometrics interact with this.

Do I have to install Google Play?

No — and a lot of people need it less than they expect. Signal, Bitwarden, Vanadium, and F-Droid cover most daily use. If you do want Play, install it from the GrapheneOS App Store. The simplest layout is the owner profile alone; a separate profile is for limiting which apps can use Play, and it carries profile-switching and per-app trade-offs.

Which browser should I use on GrapheneOS?

Vanadium, which ships with the OS. It's hardened Chromium with site isolation and JIT disabled by default, and it's also the system WebView nearly all apps use to render web content. Brave is a reasonable alternative. Avoid Firefox on Android — its engine doesn't implement site isolation on the platform.

Do banking apps and tap-to-pay work?

Most banking apps work, especially with sandboxed Google Play; a minority that demand Google certification can misbehave. Google Wallet tap-to-pay currently does not work because it requires device certification and hardware attestation a non-certified OS can't provide — that is Google's enforcement rather than a missing setting, and it could change if Google permits alternate-OS attestation. The full picture is in what breaks on GrapheneOS.

Where should Google Play go — the owner profile or a secondary profile?

Either is supported. The owner profile is the simplest and apps there are sandboxed the same as anywhere else. A separate user or work profile lets you limit which apps can use Play, at the cost of profile switching and some profile-sensitive features; a secondary user is switched through the user switcher, while a work profile keeps its apps in the same launcher behind a work badge but needs a device-controller app to create. Match it to how you use the phone.

What should I install first?

Signal and Bitwarden are the common starting point, then everything else. Signal is a widely used end-to-end encrypted messenger; Bitwarden gets your passwords onto the fresh device immediately. Neither is mandatory — pick the messenger and password manager that fit your threat model. Pull them from the GrapheneOS App Store or Accrescent where possible.

How long does the day-one setup take?

Budget an hour if you're thorough — most of it is the permission pass and the functional checks. The security-critical parts (verification, choosing a random unlock credential) take five minutes.

## Convertkit Newsletter