From your order to a phone that's private by default
You choose the device. We do the technical heavy lifting. You get a phone that protects you the moment it powers on — no setup expertise required.
- 1
Choose your device
Pick a supported Pixel and storage. We only sell devices that officially support privacy-hardened Android, so verified boot can be fully re-locked afterwards.
- 2
We flash & harden
We install privacy-hardened Android (GrapheneOS) by hand and apply our hardening: private DNS, sensible security defaults, and optional sandboxed Google Play so your everyday apps still work.
- 3
Verified boot re-locked
We re-lock the bootloader with the operating system's own verification keys. Your phone checks its own integrity at every boot and warns you if anything was tampered with.
- 4
Ships to you
Your device ships in discreet, unbranded packaging with tracking. You complete first-boot setup yourself, so your PINs, keys, and logins are only ever known to you.
What happens on first boot
The phone arrives wiped, with nothing signed in. That is deliberate: the setup you do yourself is the part we could not hand over to anyone else, even if we were asked to.
You set the PIN and passphrase
The disk encryption key is derived from a secret you choose on first boot. We never see it, which is the entire reason we do not set it for you — a phone we could unlock is a phone someone could make us unlock.
You choose whether Google Play exists
If you asked for sandboxed Play we leave it available to install; you decide whether to sign in, and with which account. Nothing is signed in when it reaches you.
You verify the device, if you want to
The OS project publishes an attestation app that checks the phone's integrity independently of us. It will tell you the truth about whether verified boot is locked and the system is unmodified — including if we had got it wrong.
You restore your own data
Move over your apps and files at your own pace. There is no migration wizard tied to a cloud account, which is slower on day one and quieter forever after.
After it arrives
What keeps working, what we help with, and what nobody can do for you — including us.
Updates come from the OS project, not from us
Security updates arrive over the air directly from GrapheneOS on their schedule. We are not in the path and cannot delay or alter them — which also means your phone keeps updating normally regardless of what happens to this shop.
Support is for the setup, not the software
We help with getting started, configuration questions, and working out whether an app problem is the OS or the app. We do not develop the operating system and cannot make a bank's app accept it.
We cannot unlock or recover your device
No remote access, no management profile, no recovery key held on your behalf. If the passphrase is lost, the data is gone — by design, and it applies to us exactly as it applies to anyone else.
Questions about a specific app or setup step are worth asking before you order — the FAQ covers the common ones, and we answer the rest.
What's done before it ships
Every device leaves us in the same hardened state. No two-hour setup guide, no half-finished configuration.
- Privacy-hardened Android (GrapheneOS), installed by hand
- Verified boot re-locked with the OS's own keys
- Private DNS configured out of the box
- Automatic reboot to a stronger at-rest state
- Optional sandboxed Google Play — apps without the surveillance
- No Google account, no telemetry, no bloatware
Got a NordSecure eSIM? Here's its life cycle
Our travel eSIMs work the same privacy-first way as our phones — no account, no email, nothing to register.
Step 1
Buy — card or crypto
Pick a country and either a fixed data plan or your own amount. No sign-up, no email — pay and you're done.
Step 2
Save your ICCID + PIN
Shown exactly once at checkout. The ICCID is your eSIM's own number and your username; the PIN is your password. They can't be recovered — store them safely.
Step 3
Log in & claim within 14 days
Scan your activation QR from the account page. Logging in claims your eSIM — unclaimed orders are voided after 14 days.
Step 4
Top up & spend, forever
Add more data anytime to the same eSIM — no new QR, nothing to reinstall.
What next?
You now know what happens to the device. The obvious follow-ups are what it costs, and how to confirm we did it.
Your first order can be live in minutes
A hardened phone, an anonymous eSIM, a real number or a one-time code — bought without a name. Card or crypto, nothing stored.
Just need travel data? Browse anonymous eSIMs