Skip to content
NordSecure
Free guide

The De-Googled Phone Checklist

A practical, vendor-neutral checklist for choosing and setting up a privacy-hardened phone — what to verify before you buy, and the traps to avoid. No email required — read it here, or save it for later.

1. Decide what you're actually protecting against

Privacy isn't one thing. Pin down your goal before you spend — it changes what matters.

  • Stop apps and the OS from profiling you (the most common goal)
  • Reduce your exposure if the phone is lost or seized
  • Separate a sensitive identity from your everyday one
  • Keep using normal apps — banking, maps, messaging — while doing all of the above

2. Choose the operating system

The OS is 90% of the privacy story. GrapheneOS on a Pixel is the current gold standard for a de-googled phone.

  • GrapheneOS — strongest sandboxing, verified boot, runs Google Play sandboxed (no privileged access)
  • Avoid OS builds that ship with root enabled — root breaks the security model
  • Check the OS is actively maintained with fast security patches
  • Confirm your banking / 2FA / work apps are known to work on it

3. Pick hardware that can actually be secured

Most phones can't relock the bootloader after installing a custom OS. That single detail decides whether the device is tamper-evident.

  • Google Pixel — supports verified boot re-lock after flashing (this is the key one)
  • A dedicated hardware security chip (Pixels use the Titan M2)
  • A device still inside its guaranteed security-update window
  • Bought new or verifiably clean — not a mystery second-hand unit

4. Verify the install — don't just trust it

A privacy phone you can't verify is just a promise. Everything here is checkable with public, official tools.

  • Bootloader is re-locked (the boot screen states the OS and lock state)
  • Verified boot is enabled and the device passes its own attestation
  • No unknown apps, accounts, or profiles are pre-loaded
  • You — not the seller — set the first screen-lock and encryption password
Step-by-step: how to verify your GrapheneOS device

5. Set it up for daily life

A hardened phone you fight with gets abandoned. Aim for private and livable.

  • Install apps from a sandboxed Google Play or F-Droid, not sideloaded blindly
  • Use per-app permissions — deny location, contacts, and network where you can
  • Set up a strong passphrase plus a duress/PIN strategy if you need one
  • Keep automatic security updates on

6. Red flags when buying pre-configured

If a seller does any of these, walk away.

  • Claims official affiliation or endorsement from the OS project
  • Ships with the bootloader left unlocked, or won't say
  • Pre-installs their own accounts, VPN logins, or unknown apps
  • Offers no returns and no real human support

Test your work — free, in the browser

Hardening the OS is most of the job; the browser is the rest. Two quick checks show what yours still gives away: how identifiable your browser fingerprint is and whether it's sending Do Not Track and GPC signals.

Want the checklist done for you?

NordSecure ships a Google Pixel with GrapheneOS professionally flashed, hardened, and verified-boot re-locked — every box above ticked before it reaches you. If it's not for you, there's a 30-day money-back guarantee.

See the device

Bonus: pair it with an anonymous data eSIM — mobile data that isn't tied to your name or ID.