The De-Googled Phone Checklist
A practical, vendor-neutral checklist for choosing and setting up a privacy-hardened phone — what to verify before you buy, and the traps to avoid. No email required — read it here, or save it for later.
1. Decide what you're actually protecting against
Privacy isn't one thing. Pin down your goal before you spend — it changes what matters.
- Stop apps and the OS from profiling you (the most common goal)
- Reduce your exposure if the phone is lost or seized
- Separate a sensitive identity from your everyday one
- Keep using normal apps — banking, maps, messaging — while doing all of the above
2. Choose the operating system
The OS is 90% of the privacy story. GrapheneOS on a Pixel is the current gold standard for a de-googled phone.
- GrapheneOS — strongest sandboxing, verified boot, runs Google Play sandboxed (no privileged access)
- Avoid OS builds that ship with root enabled — root breaks the security model
- Check the OS is actively maintained with fast security patches
- Confirm your banking / 2FA / work apps are known to work on it
3. Pick hardware that can actually be secured
Most phones can't relock the bootloader after installing a custom OS. That single detail decides whether the device is tamper-evident.
- Google Pixel — supports verified boot re-lock after flashing (this is the key one)
- A dedicated hardware security chip (Pixels use the Titan M2)
- A device still inside its guaranteed security-update window
- Bought new or verifiably clean — not a mystery second-hand unit
4. Verify the install — don't just trust it
A privacy phone you can't verify is just a promise. Everything here is checkable with public, official tools.
- Bootloader is re-locked (the boot screen states the OS and lock state)
- Verified boot is enabled and the device passes its own attestation
- No unknown apps, accounts, or profiles are pre-loaded
- You — not the seller — set the first screen-lock and encryption password
5. Set it up for daily life
A hardened phone you fight with gets abandoned. Aim for private and livable.
- Install apps from a sandboxed Google Play or F-Droid, not sideloaded blindly
- Use per-app permissions — deny location, contacts, and network where you can
- Set up a strong passphrase plus a duress/PIN strategy if you need one
- Keep automatic security updates on
6. Red flags when buying pre-configured
If a seller does any of these, walk away.
- Claims official affiliation or endorsement from the OS project
- Ships with the bootloader left unlocked, or won't say
- Pre-installs their own accounts, VPN logins, or unknown apps
- Offers no returns and no real human support
Test your work — free, in the browser
Hardening the OS is most of the job; the browser is the rest. Two quick checks show what yours still gives away: how identifiable your browser fingerprint is and whether it's sending Do Not Track and GPC signals.
Want the checklist done for you?
NordSecure ships a Google Pixel with GrapheneOS professionally flashed, hardened, and verified-boot re-locked — every box above ticked before it reaches you. If it's not for you, there's a 30-day money-back guarantee.
See the deviceBonus: pair it with an anonymous data eSIM — mobile data that isn't tied to your name or ID.