5 Popular deGoogled Phone Operating Systems Compared
By Tony · FreedomTech · 12 min read · Updated June 2026
Before you compare deGoogled phone operating systems, look at what happened in September 2022. Optus handed over the personal details of 9.5 million Australians to whoever was clever enough to ask.
Names. Dates of birth. Home addresses. Driver's licence numbers. Passport numbers. Gone.
Every one of those people had a phone in their pocket, most running standard Android or iOS, built by companies that earn billions knowing everything about you. The breach was not the start of the problem. It was just when Australians noticed.
So which of these systems actually fixes it? GrapheneOS, CalyxOS, /e/OS, LineageOS, the BraX3. A lot of people online will tell you they are much the same. They are not, and here is the straight version.
The short version
- Only one earns the word deGoogled without an asterisk: a Google Pixel running GrapheneOS, bootloader relocked, verified boot on.
- The deciding question no review asks is bootloader relock. Without it, the phone can never confirm its own software is untampered.
- CalyxOS, /e/OS, LineageOS and the BraX3 each fall down on relock, on Google contact, on hardware modem isolation, or on a stalled project.
- Google's developer verification, enforced from September 2026, squeezes privacy apps off standard Android. On GrapheneOS it has nothing to enforce.
Why deGoogled Phone Operating Systems Matter More Than Any App
Most people approach phone privacy the wrong way. They switch off a location permission. They delete an app. They install a VPN.
All reasonable. None of it touches the actual problem, because the operating system is the layer underneath, and it decides:
- What every app is allowed to reach
- What gets sent, and to whose servers
- Whether the software loading at startup has been tampered with
- Whether someone with physical access can plant malware you never see
Fix the apps and ignore the OS, and you have fitted a better lock to a door with no walls.
Not while you search. Not while you use Maps. While it sits in your pocket. That is what the OS was built to do. Alternative systems break this at the foundation, but not all equally, and some barely at all.
GrapheneOS: The Only One We Call deGoogled
GrapheneOS is built by a Canadian non-profit that has hardened Android since 2014. Edward Snowden uses it and recommends it publicly.
In March 2026 the Irish Times reported that experts rate it highly for balancing security with usability. We install it on every phone we sell.
It is built on AOSP, the open-source foundation under the Android you know. But raw AOSP and the Android on your phone are not the same thing. Google has been replacing open parts with closed software since 2007. GrapheneOS goes the other way. In practice:
- Its own servers handle connectivity and location checks, not Google's
- Vanadium, a hardened browser that does not talk to Google
- No advertising identifier anywhere on the device
- Nothing reaches Google unless you deliberately set it up to
The Question Nobody Asks About deGoogled Phone Operating Systems
Here is the question that almost never makes the reviews, and it matters most. After you install a new operating system, can you lock the bootloader again?
The bootloader runs before the OS and checks it has not been tampered with. To install a custom OS you unlock it. Unlocked, the phone can no longer verify what it is running.
Verified boot, the check that confirms your OS is intact at every startup, only works with a locked bootloader. No relock, no verification, ever.
On Pixel hardware, GrapheneOS lets you relock with its own keys. Every start, the phone confirms the OS is exactly what it should be. That is stock Pixel security, without Google's software.
This is why we build only on Pixel. Three things no other consumer Android hardware offers:
- Bootloader relock with a custom OS installed
- Verified boot running on every startup
- An IOMMU that walls the cellular modem off from your apps and data, in hardware
What the 2026 App Verification Changes Actually Mean
You may have seen that Google is locking down sideloading on Android. Here is the accurate timeline.
- March 2026. Developer verification opens to all developers.
- September 2026. Enforcement begins in Brazil, Indonesia, Singapore and Thailand. Apps from unverified developers will not install on certified devices.
- From 2027. The policy rolls out globally.
That breaks open-source stores like F-Droid, which signs apps with its own key rather than tying each one to a Google-verified identity.
GrapheneOS is not a certified Android device. The Register confirmed in February 2026 that the policy does not affect AOSP builds like GrapheneOS. F-Droid, Aurora Store and direct APK installs keep working exactly as today.
On standard Android, the window to install privacy apps freely is closing. On GrapheneOS, there is no window to close.
CalyxOS: Never Our First Choice, Now Not a Consideration
CalyxOS was, at best, a reluctant fallback. Built on AOSP, relock on Pixel, microG instead of Play Services. We never recommended it with confidence. Then August 2025 happened.
The Calyx Institute published a letter to its community that opened by assuring readers the signing keys had not been compromised. When a privacy project leads with that line, something has gone wrong.
- The founder, Nicholas Merrill, had left, and so had the lead developer
- All development and security updates paused, four to six months estimated
- Already stuck on the June 2025 patch level, with known remotely exploitable holes
- The project told its own users they would be better off uninstalling
A privacy operating system telling its own users: uninstall us.
As of its February 2026 update, it is still rebuilding its signing and release pipeline. Anyone who stayed on it must wipe and reinstall for future updates. Recovering is not recovered. We are not recommending it.
What Is microG, and Does It Send My Data to Google?
microG comes up with all the rest, so it is worth a moment before we go on.
What microG is
- An open-source stand-in for Google Play Services
- Maintained by a German developer, Marvin Wissfeld
- Contains no Google code
- Lets apps use push and location without the real thing
What it still does
- With push on (default on CalyxOS and /e/OS) it sends your IP and device model to Google on first registration
- The advertising ID is disabled
- Far better than 340 pings a day, but not zero contact
- CalyxOS call it harm reduction, and are honest about it
GrapheneOS does not use microG at all. It runs a fully sandboxed Google Play Services that cannot reach anything outside its own container.
/e/OS: Good Intentions, Real Problems
/e/OS is made by the French company Murena, founded by the man behind Mandrake Linux. The idea is sound. The execution is the problem.
- Built on LineageOS, so it cannot relock the bootloader
- Uses microG by default with push on, so limited Google contact is baked in
- Lags on patches: the Register's June 2025 review found it shipped on the May patch, already behind
- Murena themselves say it is not a security-hardened OS
Then there is the cloud. In October 2024, nearly every Murena service went offline at once: email, calendar, contacts, files.
File storage stayed down four months, into February 2025. The CEO confirmed to the Register that around 120,000 accounts were hit and some email was lost for good. Users were not told for weeks.
It was not a hack. But Murena's own documentation confirms files are encrypted on the server, with Murena holding the keys, not you. We do not install /e/OS and we do not recommend it.
LineageOS: Great for Old Phones, Not a Privacy Solution
LineageOS runs on hundreds of phones and is genuinely excellent at its job: reviving old hardware and giving developers a clean base. It is not a privacy OS, and the deGoogled label does not fit it.
- Same bootloader story as /e/OS, which is built on it
- Its own FAQ warns that relocking will likely leave a phone that does not boot
- Unlocked, the phone cannot confirm at startup that its OS is untampered
Fine for everyday use. For privacy, a problem that cannot be fixed in software.
The BraX3: What Is Actually Running Inside It
You have seen it on YouTube. The BraX3, sold by Brax Technologies and tied to Rob Braxman, launched on Indiegogo in April 2025. It runs iodeOS, a LineageOS fork with microG. So: no relock, microG by default, the usual LineageOS issues. It also has a hardware problem the marketing skips.
- A MediaTek Dimensity 6300, made in China, with no IOMMU
- Without IOMMU, the modem and the OS share memory, so a compromised modem can reach everything
- MediaTek's September 2025 bulletin listed CVE-2025-20708, a high-severity modem flaw needing no user action
- The iodeOS core framework had no code commit in 18 months as of November 2025
Independent researcher 12bytes.org asked Brax directly, more than once, whether the modem was isolated from user memory. The first reply dodged it. After that, silence. Their June 2025 verdict: do not buy this phone.
We are not attacking anyone. Australians spending real money on privacy deserve to know what they are getting.
What Actually Separates These Options
Here is how the main deGoogled phone operating systems compare side by side.
| OS | Based on | Bootloader relock | Google contact | Status, mid 2026 | FreedomTech |
|---|---|---|---|---|---|
| GrapheneOS | AOSP | Yes, verified boot on Pixel | Minimal, own servers | Actively maintained | Recommended |
| CalyxOS | AOSP | Yes on Pixel, but project stalled | Via microG (optional) | Recovering from 2025 hiatus | Not recommended |
| /e/OS | LineageOS | No | Via microG (default on) | Active, lags patches | Not recommended |
| LineageOS | AOSP | No (standard builds) | Optional via microG | Active, not a privacy OS | Not recommended |
| iodeOS / BraX3 | LineageOS fork | No | Via microG | Uncertain, 18 month gap | Not recommended |
Yes, It Is a Google Phone, and That Is the Point
We get asked this a lot. If the goal is to escape Google, why build on a Google phone? Fair question, and worth answering straight. There are two parts to it.
First, the software. GrapheneOS is built on AOSP, Google's open-source Android, and Google has been closing off parts of AOSP for years. Here is how GrapheneOS answers that:
- Its own servers replace Google's for standard connectivity checks
- Its own browser replaces Chrome
- Where Google components remain in AOSP, it strips them or routes around them
- Its security work is contributed back into AOSP, now running on billions of devices
Second, the hardware, and this is the part we are happy to own. We use Google's best engineering against Google. The Pixel is the most secure consumer Android hardware made: the only one that relocks the bootloader with a custom OS, with a hardware-isolated modem, Google's Titan M2 security chip and a long update runway. GrapheneOS turns all of it to your benefit instead of Google's.
We use Google's own hardware to lock Google out of it. That is not a compromise. It is the whole strategy.
No other consumer hardware comes close, which is why every phone we build is a Pixel running GrapheneOS. For the full breakdown of the operating system itself and how we set it up, read our deep dive on the GrapheneOS phone for Australians.
What We Build at FreedomTech
Every phone we sell is a Google Pixel running GrapheneOS: Pixel 7 through Pixel 10, Pro, XL and Fold, plus the Google Pixel Tablet.
- Install GrapheneOS from official sources and relock the bootloader
- Pre-install and configure Brave, Signal, ProtonMail, ProtonVPN, Aegis Authenticator and a tested set of privacy apps
- Test the phone by hand before it leaves us
- Email you the FreedomTech manual: setup, every app, data transfer, and what to do when you have questions
It works on every Australian carrier, Telstra, Optus and Vodafone. Port your number, 4G and 5G both work, banking and maps work. GrapheneOS is a full smartphone OS. It just does not spend the day reporting on you.
Where a deGoogled Pixel Fits the Bigger Picture
This comparison is the decision-stage piece. For the full picture on why a deGoogled Pixel matters for Australians, the data broker industry, what happened at Optus, and what has changed with biometric data collection, read our hub guide on why google-free smartphones are the future of digital life.
Frequently Asked Questions About deGoogled Phone Operating Systems
Which deGoogled phone operating systems are worth considering in Australia? +
Can I put GrapheneOS on a Samsung or a OnePlus? +
Will my banking app still work? +
What happened to CalyxOS, and is it safe now? +
Is microG the same as having Google on your phone? +
Are those privacy phones on YouTube any good? +
Do deGoogled phones work on Australian carriers? +
What support does FreedomTech provide after purchase? +
Skip the rabbit hole. Get the one that earns the label.
Every FreedomTech phone is a Google Pixel on GrapheneOS, bootloader relocked, built and tested by hand, and emailed with a clear manual. Not sure which model? Email [email protected] and we will point you the right way.
Questions, or just keen to talk privacy with like-minded Australians? Visit our Telegram community.
FreedomTech · The Privacy Experts · freedomtech.com.au