Skip to content
NordSecure
FAQ

Questions, answered properly

The things people actually ask before buying — including the parts that don't flatter us. If your question isn't here, ask us before you order.

General

What we are, and what we are not.

Is this an official GrapheneOS product?

No. GrapheneOS is an independent open-source project. We are not affiliated with it, not endorsed by it, and we do not speak for it.

What we sell is a service: we take a supported Google Pixel, install privacy-hardened Android (GrapheneOS), configure it, re-lock verified boot, and test it before it ships. The operating system itself is free software that anyone can download and install without paying us anything.

If you would rather do it yourself, you should — it is genuinely free, and the project publishes clear instructions. Our free hardening checklist covers the same configuration decisions we make, whether or not you buy from us.

Why buy from you instead of flashing it myself?

Because someone has already made the decisions and checked the result. Flashing takes an afternoon the first time: unlocking the bootloader, installing the OS, working out which hardening options matter, re-locking verified boot without bricking anything, then confirming it all actually holds.

You are paying for the work and the support, not the software. Every device gets the same configuration, a function test, and a person to email when something is confusing. If that afternoon sounds like a pleasant one, do it yourself — we mean that.

The one thing you cannot outsource is trust, which is why we would rather you verify the device yourself than take our word for it.

Who is behind NordSecure?

NordSecure is a small operation based in Denmark, shipping across the EU. Every device is prepared by hand rather than assembled on a line — which is the honest reason the first batch is small.

You can reach a human directly at our contact page

Devices & apps

What works, what does not, and what you should check before buying.

Will my everyday apps still work?

Most of them, yes. You can install sandboxed Google Play, which runs Google's services as ordinary apps in the normal app sandbox rather than as privileged parts of the system. From the app's point of view Play is present; from the system's point of view Google has no special access.

In practice that covers the large majority of what people install: messaging, maps, streaming, social, travel, ride-hailing, most retail apps. Signal and WhatsApp both work normally, including notifications, once Play is installed. Apps distributed outside Play — F-Droid, direct APKs, Aurora Store — work as they do on any Android.

The apps that struggle are the ones that actively check whether the operating system is the manufacturer's own, which is a small but real category. See the payments answer below, and if a specific app is critical to you, ask us before you order — we would rather talk you out of a purchase than take a return.

What about banking apps and tap-to-pay?

Tap-to-pay through Google Wallet does not work. Google Wallet requires a device attestation that a phone running a third-party operating system cannot pass, no matter how secure that OS actually is. If contactless payment from your phone is something you use daily, this is the single biggest thing to weigh before buying — take your card.

Banking apps are genuinely mixed. Many work fine with sandboxed Google Play installed. Some banks use the same integrity checks as Wallet and refuse to run; a few refuse but keep working in a mobile browser, which is often a perfectly good workaround.

Does Android Auto work?

Yes, on current GrapheneOS releases, with sandboxed Google Play installed and Android Auto enabled in settings. It is not on by default and it is not entirely frictionless, but the days of it being simply impossible are behind us.

Wired connections are the more reliable path; wireless behaviour varies by head unit. If your car is the reason you are buying the phone, that is worth a message to us first.

Which Pixel do I get, and what condition is it in?

It depends where you land in the opening batch. The first units are the Google Pixel 7 Pro; the final two are the Pixel 8 Pro. Once the batch sells out, our standard device is the Pixel 9a at regular pricing. Every one is hardened to the identical standard — the model changes, the work does not.

In the box: the phone with the OS pre-installed and configured, a USB-C charging cable, and discreet tracked shipping. The exact unit you will receive is confirmed before it ships, so you are never guessing.

We only ship Pixel models that support installing a third-party OS with verified boot re-locked, because a device that cannot re-lock cannot give you the security guarantee that makes this worth doing.

Is the camera or battery worse than a stock Pixel?

The battery is unaffected — it is the same hardware, and the OS is not doing anything unusual with power. Some people see slightly better standby time without Google Play Services running privileged in the background.

The camera is the honest trade-off. The Pixel's camera hardware is unchanged and the stock camera app works, but a few of Google's cloud-assisted photo features depend on services that are deliberately not privileged on this OS. Day-to-day photography looks like a Pixel; the most Google-dependent computational extras are the exception.

Can I install normal Play Store apps?

Yes. Install sandboxed Google Play from the built-in apps repository, sign in if you want to, and the Play Store behaves as you expect — including paid apps you already own.

The difference is what Play can see. It runs in the same sandbox as any other app, so it cannot quietly enumerate your device, sit in the background with system privileges, or act as an always-on identifier the way it does on stock Android. You can also skip it entirely and use F-Droid or Aurora Store.

Privacy & security

What the protections actually do — and what they do not.

What does 'verified boot re-locked' mean?

It means the phone checks its own operating system every time it starts, and refuses to boot silently into a modified one.

To install a different OS you must first unlock the bootloader, which switches that checking off. A lot of custom-OS phones are sold and simply left that way — which quietly removes one of the strongest protections the hardware has, because anyone with physical access can then alter the system. Re-locking turns verification back on, now trusting the new OS's signature.

The practical result: if someone tampers with the system while the phone is out of your hands, it will not boot as if nothing happened. You do not have to take our word for that — the OS project publishes an attestation app that checks the device's integrity for you, and it will tell you the truth whether or not we did our job properly.

What data do you keep about me?

For an eSIM: no name, no address, no ID, no account. You get an ICCID and a PIN at checkout and those are the only credentials that exist. Card payments are processed by Stripe and crypto by NOWPayments, so those providers see what they need to move the money; we do not receive or store card numbers.

Full detail is in the privacy policy.

Can you access my phone after I receive it?

No — and not because we promise not to, but because we do not have anything that would let us.

We never set your PIN, passphrase, or screen lock; you do that on first boot, and the disk encryption key is derived from a secret we have never seen. We install no remote access software, no management profile, and no support agent. There is no NordSecure account on the device.

This is deliberate and it cuts both ways: it also means we cannot recover a forgotten passphrase or unlock a device for you. Nobody can. That is the trade you are buying.

What is a duress PIN?

It is a second PIN or password that, when entered, wipes the device instead of unlocking it. The OS supports setting one; whether you do is entirely your choice, and it is off unless you turn it on.

It is meant for situations where you may be compelled to unlock a phone. Used carelessly it destroys your own data with no way back, so set it only if you have thought through when you would use it — and make sure it is not something you could type by accident while half asleep.

Where do updates come from, and what if NordSecure disappears?

Updates come over the air directly from the OS project, not from us. We are not in the path, and we cannot delay, alter, or withhold them.

That is the reassuring part of the answer: if this shop closed tomorrow, your phone would keep receiving the same updates on the same schedule as every other device running that OS, for as long as the project supports the hardware. You are not dependent on our continued existence for the security of the device.

eSIM

Prepaid data in 170+ countries, without an account.

What is an eSIM, and will my phone take one?

An eSIM is a SIM card built into the phone that you activate by scanning a QR code, instead of a plastic card you slot in. Nothing is posted to you and there is nothing to lose in an airport.

Broadly: iPhone XS and newer, and most Android flagships from roughly 2019 onward, support eSIM. The phone must also be carrier-unlocked — a handset locked to an operator will refuse a second profile even if the hardware supports it.

The quickest check is in your own settings: if there is an option to add a mobile or cellular plan by scanning a code, you are set. Pixels we sell support eSIM, so a phone and a travel eSIM work together out of the box.

What does 'no KYC' actually protect — and what does it not?

It protects your identity at the point of purchase. We do not ask for a name, an address, an email, or a document, and we do not create an account for you. Pay by crypto and there is no card in the chain either. So the purchase itself is not tied to you in our records, because those records do not exist.

It does not make your traffic private, and we will not pretend otherwise. Once the eSIM connects, a mobile network is carrying your data exactly as any network would: it can see the towers you use and therefore roughly where you are, and it can see which servers you connect to, even when the contents are encrypted.

If you want the content and destination of your traffic shielded from the network, that is what a VPN or Tor is for — an anonymous SIM and a VPN solve two different halves of the problem. Our blog covers how the two fit together.

Can I use your eSIM in the phone I buy from you?

Yes, and it is a sensible pairing: a device with no Google account on it, and data service bought without identifying yourself.

The eSIM installs like any other — scan the QR from your receipt and it appears as a second line. You can keep your existing SIM in place for calls and use the travel eSIM for data.

How do I add more data later?

Enter your ICCID on the top-up page, choose an amount, and pay. No login, no PIN — topping up only ever adds data to an eSIM, so we do not make you sign in to hand us money.

The data lands on the eSIM you already installed. There is no new QR code and nothing to reinstall; the profile on your phone stays exactly as it is.

Can I get a refund on an eSIM?

If an eSIM fails to work and the fault is ours, we will make it right. Contact us with the ICCID and we will look at what actually happened on the network side, rather than guessing from here.

Card or crypto — what do you see about me either way?

With crypto, effectively nothing. You pay an address; we receive a confirmation and issue the eSIM. No name reaches us and none is stored. We accept Litecoin, Ethereum, Monero and Bitcoin — the checkout shows which of them clear their own network minimum at the price you are paying.

With a card, Stripe handles the payment and we never see the card number. Stripe necessarily knows who you are, because that is how card networks work — so the purchase is not anonymous from the payment processor's side, only from ours.

If purchase anonymity is the point, Monero is the strongest option on that list. If convenience is the point, use the card — the eSIM itself behaves identically either way.

Shipping, returns & warranty

Where we ship, what arrives, and what happens if something is wrong.

What is the return policy?

You have 30 days from delivery to return a device for a full refund. If it isn't right for you, that's reason enough — email us with your order number before sending anything back and we'll guide you through it.

Return the device in good, undamaged condition with the accessories it came with; we factory-reset and re-flash every returned unit, so normal use is fine. Once we receive and check it, we refund to your original payment method, typically within 5–10 business days.

This 30-day money-back guarantee is voluntary and sits on top of your statutory rights — it is in addition to the EU's 14-day right of withdrawal, never a replacement for it.

What does the warranty cover — hardware or software?

The distinction matters. A cracked screen or a failing battery is a hardware matter. An app behaving oddly, an update question, or a configuration you want changed is support, and that is where we are genuinely useful.

Operating system updates come from the OS project directly and are not something we can warrant or withdraw.

Phone numbers

A number you keep, with calls, texts and data.

Will this work on my phone?

It needs a phone that supports eSIM and isn't carrier-locked. Broadly that means iPhone XS or newer, and most Android flagships from around 2019 — including every Pixel we sell. A handset locked to an operator will refuse the profile even if the hardware supports it. Check Settings for an 'Add eSIM' or 'Add cellular plan' option before buying.

Can I keep my normal number at the same time?

Yes, that's the usual way people use it. An eSIM installs alongside your existing SIM, so your everyday number keeps working and the new one sits next to it as a second line. You choose which one makes each call or sends each text.

When do I find out what my number is?

After you install it. The network assigns the number when the eSIM first connects, so nobody knows it at checkout — not you and not us. It appears in your phone's settings within a few minutes of the profile activating. You can't request a specific number or area code.

Can people call and text me on it?

Yes. It's a real carrier number, not a VoIP line, so calls and texts work in both directions and it behaves like any other mobile number to whoever is contacting you.

Will WhatsApp, Signal or Telegram accept it?

Usually. Because these are genuine mobile numbers rather than internet numbers, they pass the checks most apps run. We can't promise any specific service will accept a given number — some maintain their own block lists — so if one particular app is the whole reason you're buying, treat it as likely rather than guaranteed.

What happens when the plan runs out?

The number stops working. On USA and Global plans you can top up before that happens and keep the same number running indefinitely. Every other destination ends when the term does, and a new plan issues a new number — so check the 'Keeping the number' line on the plan page before you attach the number to anything you care about.

How quickly does it arrive?

Immediately. Payment clears and the QR code appears on your receipt straight away — there's nothing to post and nobody to wait for. Your plan's validity starts when the eSIM first connects to a network, not when you buy it, so you can buy in advance of a trip.

Do I need an account, or to give you my name?

No. There's no sign-up, no email required and no ID. You get an Order ID and a PIN at checkout, and those are the only things linking you to the purchase. We never send your details to the network — they receive a package code, nothing else.

Can I get a refund if I change my mind?

It depends on the destination, and each plan page says which it is before you pay. Where a plan is marked refundable, the eSIM must still be uninstalled — contact us with your Order ID and we'll return it to the network for you; there's no self-service button for this, so please get in touch rather than waiting. Plans marked non-refundable can't be returned once issued, and no plan can be returned after the profile has been installed, because the network counts it as used at that point.

Verification codes

One-time numbers for signing up, and the limits of them.

How does this differ from a phone plan?

A verification code is one-time: you get a number for about twenty minutes, receive a single code, and it expires. A [phone plan](/phone) gives you a number you keep for weeks or months, with calls, texts and data. If you need to receive more than one code, or ever need the number again, buy a plan instead — it works out cheaper than repeat codes.

Which service should I pick, and which country?

Search for the service you need the code from and we do the rest: we check every country that can supply a number for it, look up how often codes actually arrive from each, and put the best first. You can override the choice, but the top option is the one most likely to work.

Why do you show a percentage next to each country?

It's how often a code genuinely arrives for that service and country. Once enough numbers have been sold for a pairing, the figure is measured on orders placed here rather than quoted from anywhere. Some popular services sit near a coin flip because they actively block numbers like these, and we'd rather show that than sell you a surprise.

What if no code arrives?

Each order includes up to six numbers, and every retry is free. Three come from the country you picked; if none of them receives anything, the next three come from the best remaining country instead — when a service blocks a range of numbers it blocks all of them equally, so changing country is worth more than changing number. Once all six are spent the order can't be credited back: we're charged per number whether or not a code is sent, which is why the delivery rate is shown before you pay.

Can I use it for my bank, or anything financial?

No, and we'd advise against trying. These numbers are single-use and expire, so any account that depends on one for password resets or two-factor codes will be locked out permanently once it's gone. Banks and financial services also reject this kind of number as a matter of policy.

Is it a real number or an internet one?

A real mobile number on a carrier network, not VoIP. That's exactly what most services check for when they decide whether to accept a number, and it's why delivery rates here are higher than services that resell internet numbers.

How long does the code take?

Usually under a minute once you request it, though the window stays open for twenty minutes. Buy the number first, then request the code from the service — not the other way round, because the clock starts when the number is issued.

The service rejected the number when I entered it. What happened?

Some services check a number against lists of ranges known to be resold for verification, and refuse it before any code is sent. That is a decision at their end, not a fault at ours — the number is real and on a carrier network. Signal and WhatsApp are the strictest about it; Telegram, Discord, Google and most sign-up forms are far more permissive. If a service rejects the number outright, a different country usually behaves differently, and that is what the free retries are for.

Can I choose the country myself?

Yes. We rank the countries by how often a code actually arrives and preselect the best one, because for most people that is the whole question. Under it is every country that service can use — searchable, with its own delivery rate and price — so if you need a specific one, take it.

Why do some countries cost more than others?

Because the supplier charges us more for them. Most land on the same price, since our floor is above what a number typically costs us, but the dearer ranges push through it. A higher price is not a promise of better delivery: pick on the percentage, not the cost.

What if you can't get a number at all?

Then you're refunded in full. That is the one case where nothing whatsoever was delivered, and it is different from a number that arrived and received no code — email us with the link to your order page and we'll return the payment.

What do you know about me after I buy?

The service and country you chose, the payment, and the number we bought for you. No name, no email, no account. Pay in crypto and there is nothing linking the order to you at all; pay by card and Stripe knows what your bank already knows. We don't ask for anything else, so there is nothing else to hand over or lose.

What happens if I close the page before the code arrives?

Nothing is lost. Every order has its own link, shown as soon as you pay, and it takes you back to the same page with the number and the code on it. There is no account to log into, so bookmark it — and the payment reference shown at checkout is enough for us to find your order if you lose the link entirely.

How do I pay, and do I need an account?

Card or crypto, no account either way. Crypto is settled in Litecoin, Ethereum, Monero or Bitcoin, though at this price only some of those clear their own network minimums — the checkout shows which. Nothing is emailed and nothing is stored beyond the order itself.

Can I reuse the number later?

No. It receives one code for the service you chose and then expires. It can't take a second code, it isn't yours to keep, and it can't be used to recover the account afterwards. That's the trade-off for not attaching your own number to a sign-up.

Still unsure?

Ask before you buy — particularly about a specific banking app, your car, or whether the phone suits how you actually use one. We would rather talk you out of a purchase than process a return.