Mobile Privacy · Australia

5 Popular deGoogled Phone Operating Systems Compared

By Tony · FreedomTech · 12 min read · Updated June 2026

GrapheneOS recommended Bootloader relock decides it 5 systems, 1 verdict Australian view
deGoogled phone operating systems compared, GrapheneOS, CalyxOS, /e/OS, LineageOS and BraX3 on a dark background

Before you compare deGoogled phone operating systems, look at what happened in September 2022. Optus handed over the personal details of 9.5 million Australians to whoever was clever enough to ask.

Names. Dates of birth. Home addresses. Driver's licence numbers. Passport numbers. Gone.

Every one of those people had a phone in their pocket, most running standard Android or iOS, built by companies that earn billions knowing everything about you. The breach was not the start of the problem. It was just when Australians noticed.

So which of these systems actually fixes it? GrapheneOS, CalyxOS, /e/OS, LineageOS, the BraX3. A lot of people online will tell you they are much the same. They are not, and here is the straight version.

9.5M
Australians had personal data exposed in the September 2022 Optus breach (OAIC).

The short version

  • Only one earns the word deGoogled without an asterisk: a Google Pixel running GrapheneOS, bootloader relocked, verified boot on.
  • The deciding question no review asks is bootloader relock. Without it, the phone can never confirm its own software is untampered.
  • CalyxOS, /e/OS, LineageOS and the BraX3 each fall down on relock, on Google contact, on hardware modem isolation, or on a stalled project.
  • Google's developer verification, enforced from September 2026, squeezes privacy apps off standard Android. On GrapheneOS it has nothing to enforce.
Foundations

Why deGoogled Phone Operating Systems Matter More Than Any App

Most people approach phone privacy the wrong way. They switch off a location permission. They delete an app. They install a VPN.

All reasonable. None of it touches the actual problem, because the operating system is the layer underneath, and it decides:

  • What every app is allowed to reach
  • What gets sent, and to whose servers
  • Whether the software loading at startup has been tampered with
  • Whether someone with physical access can plant malware you never see

Fix the apps and ignore the OS, and you have fitted a better lock to a door with no walls.

340
Times a day a dormant standard Android phone can ping Google's servers with location data (Digital Content Next, 2018).

Not while you search. Not while you use Maps. While it sits in your pocket. That is what the OS was built to do. Alternative systems break this at the foundation, but not all equally, and some barely at all.

The Verdict

GrapheneOS: The Only One We Call deGoogled

GrapheneOS is built by a Canadian non-profit that has hardened Android since 2014. Edward Snowden uses it and recommends it publicly.

In March 2026 the Irish Times reported that experts rate it highly for balancing security with usability. We install it on every phone we sell.

It is built on AOSP, the open-source foundation under the Android you know. But raw AOSP and the Android on your phone are not the same thing. Google has been replacing open parts with closed software since 2007. GrapheneOS goes the other way. In practice:

  • Its own servers handle connectivity and location checks, not Google's
  • Vanadium, a hardened browser that does not talk to Google
  • No advertising identifier anywhere on the device
  • Nothing reaches Google unless you deliberately set it up to
The Deciding Question

The Question Nobody Asks About deGoogled Phone Operating Systems

Here is the question that almost never makes the reviews, and it matters most. After you install a new operating system, can you lock the bootloader again?

The bootloader runs before the OS and checks it has not been tampered with. To install a custom OS you unlock it. Unlocked, the phone can no longer verify what it is running.

Verified boot, the check that confirms your OS is intact at every startup, only works with a locked bootloader. No relock, no verification, ever.

On Pixel hardware, GrapheneOS lets you relock with its own keys. Every start, the phone confirms the OS is exactly what it should be. That is stock Pixel security, without Google's software.

This is why we build only on Pixel. Three things no other consumer Android hardware offers:

  • Bootloader relock with a custom OS installed
  • Verified boot running on every startup
  • An IOMMU that walls the cellular modem off from your apps and data, in hardware
The 2026 Change

What the 2026 App Verification Changes Actually Mean

You may have seen that Google is locking down sideloading on Android. Here is the accurate timeline.

  1. March 2026. Developer verification opens to all developers.
  2. September 2026. Enforcement begins in Brazil, Indonesia, Singapore and Thailand. Apps from unverified developers will not install on certified devices.
  3. From 2027. The policy rolls out globally.

That breaks open-source stores like F-Droid, which signs apps with its own key rather than tying each one to a Google-verified identity.

GrapheneOS is not a certified Android device. The Register confirmed in February 2026 that the policy does not affect AOSP builds like GrapheneOS. F-Droid, Aurora Store and direct APK installs keep working exactly as today.

On standard Android, the window to install privacy apps freely is closing. On GrapheneOS, there is no window to close.

Second Choice, No Longer

CalyxOS: Never Our First Choice, Now Not a Consideration

CalyxOS was, at best, a reluctant fallback. Built on AOSP, relock on Pixel, microG instead of Play Services. We never recommended it with confidence. Then August 2025 happened.

The Calyx Institute published a letter to its community that opened by assuring readers the signing keys had not been compromised. When a privacy project leads with that line, something has gone wrong.

  • The founder, Nicholas Merrill, had left, and so had the lead developer
  • All development and security updates paused, four to six months estimated
  • Already stuck on the June 2025 patch level, with known remotely exploitable holes
  • The project told its own users they would be better off uninstalling

A privacy operating system telling its own users: uninstall us.

As of its February 2026 update, it is still rebuilding its signing and release pipeline. Anyone who stayed on it must wipe and reinstall for future updates. Recovering is not recovered. We are not recommending it.

The microG Question

What Is microG, and Does It Send My Data to Google?

microG comes up with all the rest, so it is worth a moment before we go on.

What microG is

  • An open-source stand-in for Google Play Services
  • Maintained by a German developer, Marvin Wissfeld
  • Contains no Google code
  • Lets apps use push and location without the real thing

What it still does

  • With push on (default on CalyxOS and /e/OS) it sends your IP and device model to Google on first registration
  • The advertising ID is disabled
  • Far better than 340 pings a day, but not zero contact
  • CalyxOS call it harm reduction, and are honest about it

GrapheneOS does not use microG at all. It runs a fully sandboxed Google Play Services that cannot reach anything outside its own container.

Good Intentions

/e/OS: Good Intentions, Real Problems

/e/OS is made by the French company Murena, founded by the man behind Mandrake Linux. The idea is sound. The execution is the problem.

  • Built on LineageOS, so it cannot relock the bootloader
  • Uses microG by default with push on, so limited Google contact is baked in
  • Lags on patches: the Register's June 2025 review found it shipped on the May patch, already behind
  • Murena themselves say it is not a security-hardened OS

Then there is the cloud. In October 2024, nearly every Murena service went offline at once: email, calendar, contacts, files.

File storage stayed down four months, into February 2025. The CEO confirmed to the Register that around 120,000 accounts were hit and some email was lost for good. Users were not told for weeks.

It was not a hack. But Murena's own documentation confirms files are encrypted on the server, with Murena holding the keys, not you. We do not install /e/OS and we do not recommend it.

Useful, Not Private

LineageOS: Great for Old Phones, Not a Privacy Solution

LineageOS runs on hundreds of phones and is genuinely excellent at its job: reviving old hardware and giving developers a clean base. It is not a privacy OS, and the deGoogled label does not fit it.

  • Same bootloader story as /e/OS, which is built on it
  • Its own FAQ warns that relocking will likely leave a phone that does not boot
  • Unlocked, the phone cannot confirm at startup that its OS is untampered

Fine for everyday use. For privacy, a problem that cannot be fixed in software.

Under the Hood

The BraX3: What Is Actually Running Inside It

You have seen it on YouTube. The BraX3, sold by Brax Technologies and tied to Rob Braxman, launched on Indiegogo in April 2025. It runs iodeOS, a LineageOS fork with microG. So: no relock, microG by default, the usual LineageOS issues. It also has a hardware problem the marketing skips.

  • A MediaTek Dimensity 6300, made in China, with no IOMMU
  • Without IOMMU, the modem and the OS share memory, so a compromised modem can reach everything
  • MediaTek's September 2025 bulletin listed CVE-2025-20708, a high-severity modem flaw needing no user action
  • The iodeOS core framework had no code commit in 18 months as of November 2025

Independent researcher 12bytes.org asked Brax directly, more than once, whether the modem was isolated from user memory. The first reply dodged it. After that, silence. Their June 2025 verdict: do not buy this phone.

"Edward Snowden endorses GrapheneOS on Pixel. That is not a close comparison."

We are not attacking anyone. Australians spending real money on privacy deserve to know what they are getting.

At a Glance

What Actually Separates These Options

Here is how the main deGoogled phone operating systems compare side by side.

OSBased onBootloader relockGoogle contactStatus, mid 2026FreedomTech
GrapheneOSAOSPYes, verified boot on PixelMinimal, own serversActively maintainedRecommended
CalyxOSAOSPYes on Pixel, but project stalledVia microG (optional)Recovering from 2025 hiatusNot recommended
/e/OSLineageOSNoVia microG (default on)Active, lags patchesNot recommended
LineageOSAOSPNo (standard builds)Optional via microGActive, not a privacy OSNot recommended
iodeOS / BraX3LineageOS forkNoVia microGUncertain, 18 month gapNot recommended
The Irony We Own

Yes, It Is a Google Phone, and That Is the Point

We get asked this a lot. If the goal is to escape Google, why build on a Google phone? Fair question, and worth answering straight. There are two parts to it.

First, the software. GrapheneOS is built on AOSP, Google's open-source Android, and Google has been closing off parts of AOSP for years. Here is how GrapheneOS answers that:

  • Its own servers replace Google's for standard connectivity checks
  • Its own browser replaces Chrome
  • Where Google components remain in AOSP, it strips them or routes around them
  • Its security work is contributed back into AOSP, now running on billions of devices

Second, the hardware, and this is the part we are happy to own. We use Google's best engineering against Google. The Pixel is the most secure consumer Android hardware made: the only one that relocks the bootloader with a custom OS, with a hardware-isolated modem, Google's Titan M2 security chip and a long update runway. GrapheneOS turns all of it to your benefit instead of Google's.

We use Google's own hardware to lock Google out of it. That is not a compromise. It is the whole strategy.

No other consumer hardware comes close, which is why every phone we build is a Pixel running GrapheneOS. For the full breakdown of the operating system itself and how we set it up, read our deep dive on the GrapheneOS phone for Australians.

What We Do

What We Build at FreedomTech

Every phone we sell is a Google Pixel running GrapheneOS: Pixel 7 through Pixel 10, Pro, XL and Fold, plus the Google Pixel Tablet.

  1. Install GrapheneOS from official sources and relock the bootloader
  2. Pre-install and configure Brave, Signal, ProtonMail, ProtonVPN, Aegis Authenticator and a tested set of privacy apps
  3. Test the phone by hand before it leaves us
  4. Email you the FreedomTech manual: setup, every app, data transfer, and what to do when you have questions

It works on every Australian carrier, Telstra, Optus and Vodafone. Port your number, 4G and 5G both work, banking and maps work. GrapheneOS is a full smartphone OS. It just does not spend the day reporting on you.

Go Deeper

Where a deGoogled Pixel Fits the Bigger Picture

This comparison is the decision-stage piece. For the full picture on why a deGoogled Pixel matters for Australians, the data broker industry, what happened at Optus, and what has changed with biometric data collection, read our hub guide on why google-free smartphones are the future of digital life.

Common Questions

Frequently Asked Questions About deGoogled Phone Operating Systems

Which deGoogled phone operating systems are worth considering in Australia? +
Of all the deGoogled phone operating systems available, GrapheneOS is the only one we recommend. It is the only option that removes Google's infrastructure entirely, supports bootloader relock with verified boot, and receives consistent security updates. Every phone we sell at FreedomTech runs GrapheneOS.
Can I put GrapheneOS on a Samsung or a OnePlus? +
No. GrapheneOS only runs on Google Pixel hardware. The reason is technical: Pixel is the only consumer hardware that supports proper bootloader relock with a custom OS, and that has the IOMMU architecture isolating the modem from user memory. A Motorola partnership announced in March 2026 should bring compatible devices by late 2026 or early 2027, but nothing is available yet.
Will my banking app still work? +
Most likely yes. GrapheneOS includes an optional sandboxed version of Google Play Services, so you can install Play Store apps, including most banking apps, without giving Google system-level access. A small number of apps that use aggressive device verification can have issues, and this gets better with each GrapheneOS update. Our own recommendation is to bank through the browser where you can.
What happened to CalyxOS, and is it safe now? +
The short version: the two people who ran the project left in 2025, security updates stopped for months, and the project told its own users to consider uninstalling. As of early 2026 it is rebuilding. Anyone who stayed on it through the hiatus will need to reinstall from scratch. We are not recommending CalyxOS at this time.
Is microG the same as having Google on your phone? +
No. microG is fully open-source and contains no Google code. But when it runs with push notifications, the default on CalyxOS and /e/OS, it does make limited contact with Google's servers when it first registers. Your advertising ID is disabled. Think of it as a heavily filtered, semi-anonymous connection rather than the full Google surveillance setup. GrapheneOS does not use microG at all.
Are those privacy phones on YouTube any good? +
It depends which one. Several, such as Above Phone and Ghost Phone, are Google Pixels running GrapheneOS or a GrapheneOS-based build. Those are essentially what we build, usually sold at a premium to the US market. Others use LineageOS forks on Chinese-manufactured MediaTek hardware with no proper modem isolation. The hardware matters as much as the software.
Do deGoogled phones work on Australian carriers? +
Yes. Telstra, Optus, Vodafone, all of them, plus the networks that resell them. You can port your existing number across. 4G and 5G both work. The phone behaves like a normal phone. It just does not report your location hundreds of times a day.
What support does FreedomTech provide after purchase? +
Every client is emailed the FreedomTech manual, covering how we set the phone up, what each app does, and how to use it from day one. We provide ongoing support at [email protected] and through our Telegram community. We are Australian based and available to our clients.

Skip the rabbit hole. Get the one that earns the label.

Every FreedomTech phone is a Google Pixel on GrapheneOS, bootloader relocked, built and tested by hand, and emailed with a clear manual. Not sure which model? Email [email protected] and we will point you the right way.

Join the conversation

Questions, or just keen to talk privacy with like-minded Australians? Visit our Telegram community.

Join our Telegram

FreedomTech · The Privacy Experts · freedomtech.com.au