In this video I walk you through the sandbox principle and how to set permissions intelligently.
A False Sense of Security
An app launches. Five popups appear. Most users reflexively tap "Allow". That's exactly where the false sense of security begins. The sandbox only protects you if you know how to make decisions. GrapheneOS is not a magic shield. It doesn't make decisions for you. It just ensures that bad decisions cause less damage.
What Does "Sandbox" Actually Mean Under GrapheneOS?
Under GrapheneOS, every app runs in isolation:
- No silent cross-access to other apps
- No hidden system privileges
- No special rights running in the background
Even Google Play Services are ordinary apps under GrapheneOS. No god mode. No system-wide omnipotence.
Important:
- Sandbox does not mean an app is automatically harmless
- Sandbox means damage is contained
The responsibility for making sensible decisions stays with you.
The Most Important Rule
The core rule for every permission:
An app gets only what it strictly needs for its core function.
Everything else is optional convenience โ and that's exactly where most problems originate.
How to Read Typical Permissions
Network Access
Typical claim: "The app won't work without network access"
Assessment:
- Messenger, browser, maps โ makes sense
- Flashlight, calculator โ red flag
Decision logic:
- Core function online? โ allow
- Convenience only? โ weigh it up
- No connection? โ deny
Location
Location data is among the most sensitive information there is.
Distinction: Precise / Approximate / Never.
Recommendations:
- Navigation โ precise (temporarily)
- Weather โ approximate
- Social apps โ usually no
GrapheneOS lets you enable location on demand and disable it again immediately.
Microphone and Camera
Clear rules:
- Only while actively in use
- Never permanently
- System toggles show live access instantly
Microphone and camera are high-risk permissions. When in doubt, grant less rather than more.
Files and Storage
Distinction: Full storage / Individual files / Media only.
Recommendation:
- Always granular
- Never blanket access unless absolutely necessary
Notifications
Notifications are convenience, not security.
- Push is not a requirement
- Many apps abuse notifications
- Fewer push notifications means more calm and control
Background Activity and Battery Optimization
Background activity means permanent presence.
Risks: Increased tracking potential, higher battery drain.
Recommendation:
- Messengers and security-relevant apps โ allowed
- Everything else โ restrict
Google Play Services in the Sandbox
A common misconception:
Google Play Services have no special privileges under GrapheneOS.
- They run in isolation
- They are optional
- Many apps work fine without them
A pragmatic approach:
- Install when needed
- Isolate them
- Decide functionally, not ideologically
Practical Tip: Separation
If you need Google Play Services but don't want them mixed into your daily workflow, there are two clean options:
- Separate user profiles: Move Google-dependent apps entirely into a dedicated profile
- Shelter in the main profile: Isolate Google Play Services and related apps into a work profile while keeping notifications reliably functional
Both approaches significantly increase separation. The details go beyond the scope of this article and are covered separately.
Common Concerns
- Will an app break if I deny something?
โ Usually no - Can I change permissions later?
โ Anytime - Does GrapheneOS make everything more complicated?
โ No. More honest.
Practice: Make Deliberate Decisions
The most effective approach is to consciously review permissions at first launch:
- What is core functionality?
- What is just convenience?
- What can I grant later if needed?
Two or three real apps are usually enough to internalize the principle.
Conclusion
GrapheneOS doesn't give you security.
It gives you control.
Security only emerges from your decisions.
Further Reading
Deepen your knowledge of system hardening:
Tools for Real Owners
Tools I use myself โ for Bitcoin self-custody and digital sovereignty:
- Alien Investor Handbooks: My own ebook "GrapheneOS: Android in the Age of Surveillance" โ the complete step-by-step guide to everything only touched on here.
https://alien-investor.org/buecher - 21bitcoin: Bitcoin-only app from Europe (code ALIENINVESTOR).
https://alien-investor.org/21bitcoin - โฟ BitBox: Hardware wallet for secure self-custody (code ALIENINVESTOR).
https://alien-investor.org/bitbox - Proton: Swiss all-round protection for email, VPN, and cloud.
https://alien-investor.org/proton
Note: Affiliate links. Using them supports my work at no extra cost to you. Thanks!
Sources & Support
Official project website:
grapheneos.org
GrapheneOS is an open source project that protects people's freedom and lives on donations. Support the project:
grapheneos.org/donate