← All Guides

Profiles and Compartmentalisation

GrapheneOS user profiles are one of the most practical privacy tools available on any mobile operating system. Each profile is an isolated workspace with its own apps, data, accounts, and encryption keys. Used properly, profiles let you separate your digital life into distinct compartments — so a compromise in one area does not automatically cascade into everything else. This is system-level isolation, not a cosmetic feature.

Why It Matters

On a conventional phone, everything lives together. Your banking app sits next to your social media. Your work email shares storage with your personal photos. A single malicious app or compromised account can potentially access data from every other app on the device.

Compartmentalisation changes that equation. By splitting your activity across separate profiles, you reduce the blast radius of any single failure. A compromised app in your banking profile cannot read the contacts in your daily profile. A travel profile that gets inspected at a border crossing reveals only what you chose to put there — not your entire digital life.

This is not theoretical. It is a concrete, measurable reduction in risk that requires no special technical knowledge to implement.

How Profiles Work

Each user profile on GrapheneOS operates as a separate workspace with its own:

  • Installed applications (independent from other profiles)
  • User accounts and sign-ins
  • Storage and files
  • Encryption keys (each profile is encrypted independently)
  • Permissions and settings for each app

Profiles do not share data with each other. An app installed in one profile cannot see files, contacts, messages, or accounts in another profile. This is enforced at the operating system level, not by app-level permissions.

Sandboxed Google Play Services can be installed in one profile without affecting any other profile. This is important — it means you can have Google Play running where you need it for compatibility without exposing your other profiles to it.

A Practical Profile Model

There is no single correct way to structure your profiles, but the following model works well for most privacy-conscious users:

Owner Profile — Administration Only
The Owner profile is the first profile created during setup. Use it exclusively for system administration: installing updates, managing settings, and configuring new profiles. Keep it minimal. Do not install personal apps, messaging clients, or browsers beyond what is needed for maintenance. The Owner profile has elevated system privileges, so keeping it clean limits your exposure.

Daily Profile — Personal Use
This is your everyday workspace. Install your secure messenger, browser, password manager, VPN, notes app, and whatever you use regularly. This profile handles the majority of your daily activity. Keep it focused — if an app does not belong in your regular workflow, it probably belongs in a different profile.

Banking/Google Profile — Compatibility Apps
Some apps require Google Play Services to function. Banking apps, rideshare services, and certain government or institutional apps often will not run without them. Install sandboxed Google Play Services in this profile, along with any apps that depend on it. By isolating these apps in their own profile, you contain Google's reach to a single compartment. Your daily profile remains free of Play Services entirely.

Travel Profile — Minimal Footprint
Create a stripped-down profile for travel, particularly for crossing borders or entering environments where your device might be inspected. Install only what you need for navigation, communication, and travel logistics. No banking apps, no full email access, no sensitive documents. If your device is examined, this profile reveals a minimal, unremarkable set of applications.

Guest Profile — Hand-off Without Exposure
A profile you can hand to someone — to make a call, show a photo, or let a child play — without exposing any of your own apps, accounts, or data. It starts empty and stays separate from everything else.

Decoy Profile — Plausible Everyday Device
A profile that looks like an ordinary primary phone but contains nothing sensitive. Combined with Phantom Protocol, a decoy profile lets a device appear unremarkable under inspection while your real workspaces stay encrypted and locked.

Every Privacy Devices phone ships with a sensible profile structure already configured — typically an administration Owner profile, a daily profile with your secure messenger and VPN, and an isolated profile for the Google Play–dependent apps — so you start compartmentalised rather than building it from scratch.

How to Create a New Profile

  1. Open Settings in the Owner profile.
  2. Navigate to System > Multiple users.
  3. Ensure "Allow multiple users" is toggled on.
  4. Tap "Add user."
  5. Enter a name for the profile (e.g., "Daily," "Banking," "Travel").
  6. Tap the new profile to switch to it.
  7. Complete the initial setup for that profile — set a PIN or password, configure Wi-Fi, and install the apps specific to that profile's purpose.

Repeat this process for each profile you need. Each one starts empty and must be configured independently.

Installing Apps in the Right Profile

When you switch to a profile, you are in that profile's isolated environment. Any app you install goes into that profile only. If you need the same app in two profiles (for example, a VPN client in both Daily and Travel), you must install it separately in each.

Be deliberate about what goes where. Before installing an app, ask: which profile does this belong in? If the answer is "all of them," reconsider — duplicating everything across profiles defeats the purpose of compartmentalisation.

Sandboxed Google Play Services

GrapheneOS allows you to install Google Play Services as a sandboxed app — it runs without the special system-level privileges it has on stock Android. This is significant: Play Services operates within the same permission model as any other app, and it is confined to the profile where you install it.

Install sandboxed Google Play only in profiles where you have a genuine need for it. For most users, that means the Banking/Google profile and nowhere else. There is no reason to install it in your Daily profile unless a specific app you use daily requires it.

To install sandboxed Google Play, open the App Store within the target profile and search for "Google Play Services." Install it, then install the Google Play Store if needed. Grant only the permissions that are required for your use case.

End Session: Locking Profiles

GrapheneOS includes an "End Session" feature that locks a profile and wipes its encryption keys from memory. When you end a session for a profile, that profile's data is encrypted at rest and inaccessible until you actively switch back to it and enter its PIN or password.

Use this feature when you are done with a profile for the day. If you finish your banking tasks, end the Banking profile session. If you are not travelling, keep the Travel profile locked. A locked profile is encrypted and cannot be accessed — even if the device is compromised while another profile is active.

To end a session: switch to the profile, pull down the notification shade, and tap "End Session." Alternatively, from the Owner profile, go to Settings > System > Multiple users, and tap the profile you want to lock.

Best Practices

  • Keep the Owner profile almost empty. It is a management console, not a workspace.
  • Assign each app to exactly one profile unless there is a clear reason to duplicate it.
  • Use a unique PIN or password for each profile. If all profiles share the same PIN, an attacker who learns one PIN has access to all of them.
  • End sessions for profiles you are not actively using. Encrypted at rest is always better than decrypted in memory.
  • Review each profile periodically. Remove apps you no longer use. Check permissions. Profiles accumulate clutter just like single-device setups if you do not maintain them.
  • Consider which profile you switch to in different contexts. At a border crossing, switch to the Travel profile before handing over your device.

Common Mistakes

  • Treating profiles as identical clones. If every profile has the same apps and accounts, you have not compartmentalised anything — you have just created extra unlock screens.
  • Installing sandboxed Google Play in every profile. This defeats the purpose of isolating it. Limit Play Services to the one profile that needs it.
  • Forgetting to lock unused profiles. A profile that stays unlocked and decrypted in the background offers less protection than one that has been properly ended.
  • Using the Owner profile for daily tasks. The Owner profile has system-level privileges. Everyday use in the Owner profile increases the risk surface unnecessarily.
  • Not setting separate PINs for each profile. Shared credentials across profiles reduce your isolation to a single point of failure.
  • Storing sensitive documents in the wrong profile. Keep high-value data in the profile with the least exposure, not the one you use most frequently.

Reality Check

Profiles provide strong, operating-system-level isolation. They are not, however, invisible walls. If your device is physically seized and all profile PINs are compelled or discovered, all profiles are accessible. Profiles protect against app-level compromise, cross-contamination, and casual inspection — they are not designed to resist sustained forensic analysis of a fully unlocked device.

Compartmentalisation is a risk-reduction strategy, not an elimination strategy. It ensures that a failure in one area does not automatically become a failure in every area. That is a meaningful and practical improvement in your security posture.

Conclusion

Profiles are one of GrapheneOS's most underused features. They require a small investment of time during setup but deliver ongoing, structural isolation that no app or setting toggle can replicate. Decide on your profile structure early, install apps deliberately in the correct profiles, lock profiles when they are not in use, and resist the temptation to duplicate everything. Clean compartmentalisation is quiet, low-maintenance, and effective.

Want a device ready for compartmentalised security out of the box?

Browse secure devices or ask us on WhatsApp.