Just installed GOS on my phone, really like it. I want to know how GOS users setup their profiles to learn from them. So far, i found out the followings:
-
everything in Owner
-
leave Owner blank. Put everything in another profile names User.
-
leave Owner blank. Put all Google stuff in user Google. Put all FOSS app in FOSS user. Put all bank stuff under Sensitive user.
-
use Owner as an app repo. So install Google Play, Acrescent, Fdroid. Install apps from there, but dont use them. Instead, when create new user, push those apps from Owner. This is similar to Side of Burritos on Youtube.
anything different?
Everything in owner because I don’t understand the implications well enough to do otherwise (so thanks for the thread).
Same. I need to step my game up! Profiles don’t look that hard, just something to learn 🙂
Got 7 profiles actually.
- is the owner of course.
- Then I have my main profile.
- A untrusted profile. Shady apps cracked apps etc. This profile also is not allowed to run in the background.
- Then my finance profile. Has my banking apps and such.
- A testing profile. Used to test backups of grapheneos and such.
- A work profile. Dont need that to run in the background either. But is useful to stay in touch over the weekends.
- And a private profile.
This way I can still use all my apps. While not requiring google play in all my profiles. Also being able to disable certain things for profiles is super useful. Running in the background, allowed to make/receive calls to name a few
Everything in Owner and a secondary phone for all proprietary work and communication apps. The secondary phone is powered off or at least disconnected once I leave work. Google stuff and banking through a computer browser whenever possible.
If I were forced to use only one phone, the secondary phone’s contents would be on a secondary profile. This used to be my setup but switching between profiles throughout the day wasn’t my thing.
You might also consider the new private space feature depending on your needs: https://www.youtube.com/watch?v=G94V5I2xH1E
Eagerly awaiting multiple private spaces so I can move everything to owner profile.
I have everything in Owner profile (including Sandboxed Google Play)
One profile. No Google sandbox stuff. All open source programs.
On my work Pixel tablet I have a home profile as owner with Aurora store just to be able to load it on the other profile. Then a secondary “work” profile with all the bloat
I have 7 profiles
- owner - network setup and app management (mullvad vpn)
- Daily - no google services and 95% of my daily usage app (always on VPN to my home)
- GPS - navigation and other apps that need location services (mullvad vpn)
- PS-USA - playstore account and google services with USA identity (fake of course), (US residential VPN for sports streaming)
- PS-CH - playstore account switzerland and google play services, my banking stuff lives here (residential vpn CH)
- PS-DE - playstore account germany and google play services (mullvad vpn) - used for apps not available in US and CH when traveling through Germany
- NOVPN - this account only has vanadium and connectbot (ssh) for network diagnostics in case I have issues with a wifi or something. My only account without always on VPN
hmm i really like the idea of navigation apps with location service in 1 profile. So you just dont listen/stream music while driving? Because thats another app right?
Also thats a lot of vpns lol.
I usually listen to radio while driving, I am kinda old school there.
Also, I think having some commercial service like Spotify or TuneIn track my taste in music, radio stations or podcasts is an invasion of my privacy. I actually selfhost an internet radio service if you wanna call it that by running a DVB-C tuner on my homeserver that grabs my favorite channels from my cable provider and streams them to my phone on demand if I wanna listen to radio on the go.
I have a work profile for my work stuff. All my personal stuff is on Owner.
All you people with multiple profiles better have insane backup strategies and love doing it often and it’s a removed. You have to backup each profile and restore individually once booted back up starting with owner then one after another. It’s a nightmare.
You also cannot use a single drive to backup each profile as the backup reading process that distinguishes each profile does not understand.
Meaning the same drive cannot even be partitioned to have a save of each profile. It requires different drives entirely. The absolute simplest process for backups are having a flash drive for each profile. Graphene os is very cumbersome to backup and DOES NOT backup all data. Once you restore from a backup you’ll understand all the pains I say, including the data you have to restore separately. A good backup is only good if you know you can restore and it works.
Hope this helps people refine their profile strategies. Most people avoid owner usage. I think there are pros and cons to that strategy. Like no pop up messages, notification delays, many other lacking options outside of owner profile like certain settings are unavailable to tweak. Including dev mode.
I’ve used graphene for years, across multiple pixel generations. It’s not the white knight made out to be. Their project is very silo’d in security and lacks the true polish of a complete OS. I still use it and think it has great merit just note the drawbacks are many. There’s so much more to add. It is late in my timezone. Hope this helps someone.
I think after testing multiple strategies that the best is to main owner, business and Google stuff 2nd, sketchy apps and things you don’t care if they get lost to delete the phone back to factory. Backup 1 and 2 only. 3 or more are throwaways. You have far more threats to lose your data from theft or social engineering by friends or family etc. than you do someone hacking multiple encrypted browsers with sandboxes of apps and then across encrypted profiles. Most of those scenarios are too complex but your imagination makes them appear big and real because of movies or TV.
Reality is the true threats are often much easier and simple. Bad actors tend to be least effort to get their goal. Nor are most Jason Bourne.
I do…
Owner - these are the apps I daily drive.
Work - all work stuff lives here.
Google - apps that require the playstore.
I thought about using my owner profile as a hub for app stores and then a 2nd profile as my main profile but I found the 2nd profiles a bit unreliable in terms of receiving calls and texts.
I have all of my open source apps in my main profile, a Shelter profile for proprietary apps (which I hardly use nowadays), a user profile for apps needed for my university, and another user profile for apps needed for a certain gig I’ve been involved with
Thank you. I can’t inform a response, but your question is very helpful for me with limited / low level ideas and poised to jump to GOS.
This thread is illuminating and makes my GOS use feel very pedestrian. I just use a single profile, I keep everything off my default and only enable what I need when I need it (GPS for instance which is rare) and then disable again, and I have no accounts logged in to anything on my phone.
Currently everything in owner, with banking apps in my private space.
I was tempted by the idea of owner as an app repo but the private space is only available in the owner profile.
Someone else in this thread mentioned they were using another device for their app repo and sideloading from there. That’s an intriguing idea for keeping even sandboxed Google off my owner profile. An idea for the future maybe.
In standard Android yes, but on GrapheneOS has 1 (one) private space per profile.
do you use a different Google account to download the bank app? or no Google at all in private space, and instead push an app downloaded from main?
A different google account in the private space.
Just the one profile that comes with the install. I need a way to get Ticketmaster tickets in to a wallet tho, so I may need to set up another profile with Play Services and Google wallet, just for tickets. Either that or reset my old Samsung phone and download the tickets on to it, bring it with me to the concert. I have one year to figure it out, the concert is Dec 2026.
There are a couple of apps that work just for ticket files (.pkpass). I’m currently using FOSS wallet. Catima works too but I didn’t love the layout.




