The Android privacy ROM ecosystem
Once you decide to take your phone's privacy seriously, sooner or later you run into three names: GrapheneOS, CalyxOS and DivestOS. All three are Android-based operating systems that strip out Google's trackers and harden security. But each has a distinct philosophy, a different target user and a set of technical trade-offs worth understanding before you choose.
In this comparison we look at all three from real day-to-day use on Pixel devices —the only ones that support all three— to help you decide which fits your risk profile, your daily needs and your technical level. There is no absolute winner: there is a right system for each person.
GrapheneOS: security without compromise
GrapheneOS is the reference standard in mobile security. Developed by a team led by Daniel Micay, its approach is radical: rebuild Android from the kernel up to eliminate every possible attack vector. This isn't about adding privacy features on top of Android —it's about redesigning Android so security is the foundation, not a layer.
GrapheneOS's hardened sandboxing is its most distinctive feature. Every app runs in a far more restrictive cage than on any other Android. Even if a malicious app managed to execute, its ability to read other apps' data or reach sensors is drastically limited. The system applies extra restrictions on native code, and permissions are granted per session, revoked automatically when the app moves to the background.
Other GrapheneOS-only advantages include USB blocking while the device is locked (charging only, no data), auto-reboot mode that detects physical tampering, and fully isolated work profiles with independent encryption. It also lets you install Google Play Services in an unprivileged sandbox, achieving compatibility with banking and service apps without granting access to the core of the system.
The price you pay: GrapheneOS only runs on Google Pixel. There's no support for other manufacturers, and that's by design —Pixels are the only Android devices that meet the hardware security requirements GrapheneOS demands (Titan M2, verifiable bootloader, long-term firmware updates).
CalyxOS: usable privacy for everyone
CalyxOS starts from a different philosophy: privacy without friction. Developed by the Calyx Institute, a non-profit organisation, its goal is a Google-free Android anyone can use with no learning curve. If GrapheneOS is a bunker, CalyxOS is a house with good locks and reinforced windows —but one you can live in comfortably.
CalyxOS's big advantage is its support for multiple devices. Beyond Pixels, it runs on some Fairphone models and on older Pixels that GrapheneOS no longer supports. It also ships MicroG by default —a free implementation of Google Play Services— which means most apps that depend on push notifications and location services work with no extra setup.
CalyxOS includes well-built apps of its own: Calyx VPN (based on Riseup), free Dialer and Contacts, and excellent integration with Signal, Tor and F-Droid. The user experience is polished, and the graphical installer makes migrating from stock Android surprisingly simple.
The trade-offs: CalyxOS has a less strict bootloader lock than GrapheneOS —it allows relocking with your own keys, but the process is less airtight. The sandboxing isn't as aggressive, and while MicroG is practical, it introduces extra attack surface that GrapheneOS avoids entirely. For users with elevated threat models, these differences matter.
DivestOS: radical freedom on modest hardware
DivestOS is the spiritual heir of LineageOS in the privacy world. Developed by Tavi (known as SkewedZeppelin), it's a LineageOS fork that removes every piece of proprietary code it can and applies security patches across a far broader range of devices than the other two systems combined.
DivestOS's great strength is its massive hardware support: more than 80 devices from dozens of manufacturers get monthly updates. That includes old phones the manufacturers abandoned years ago —DivestOS gives them a second life with current security patches. If you have an old phone in a drawer, it can probably run DivestOS.
DivestOS strips out all the proprietary code it can: drivers, binary blobs, network services. It includes Mulch WebView (a Chromium fork without Google), Hypatia (real-time malware scanner) and Mull (Firefox without telemetry). It ships neither Google Play Services nor MicroG —compatibility with apps that need them is very limited.
The downsides: the user experience is more spartan. Some hardware features may not work (NFC, certain sensors) depending on the device. Installation is more technical —it requires flashing recovery, formatting partitions and, in some cases, dealing with bootloaders that can't be relocked. DivestOS is for technically confident users, or for those who put hardware longevity and freedom of choice above convenience.
Technical comparison: head to head
Kernel security and sandboxing: GrapheneOS leads by a wide margin. Its kernel is hardened with specific patches, the sandboxing is more restrictive, and the per-session permission model has no equivalent in the other two. CalyxOS uses the standard Android kernel with some improvements. DivestOS applies patches from the Linux Hardened project but without GrapheneOS's level of integration.
Bootloader locking: GrapheneOS implements full verified boot —the bootloader is locked with the official keys and verifies system integrity on every boot. If someone modifies the system, the device won't boot without your key. CalyxOS allows locking the bootloader with your own keys (an extra step many users skip). DivestOS, on most devices, can't lock the bootloader at all because manufacturers don't permit it —a serious vulnerability against physical attacks.
Security updates: GrapheneOS ships patches within hours of Google's monthly release. CalyxOS typically takes between 1 and 7 days. DivestOS ships monthly patches on schedule, but the exact timing varies by device. In all three cases it's infinitely better than stock Android, where patches can take months or never arrive.
App compatibility: GrapheneOS with sandboxed Google Play achieves the best compatibility —banking, streaming and transport apps work almost without exception. CalyxOS with MicroG has good compatibility with apps that need push notifications but can fail with some banking apps that flag MicroG as a "rooted device". DivestOS, with neither Play Services nor MicroG, has the worst compatibility —many apps simply don't work.
Hardware support: DivestOS wins outright with 80+ devices. CalyxOS supports Pixel, Fairphone and a handful of additional models. GrapheneOS supports Pixel only —and only the models still receiving firmware updates from Google.
Ease of installation: CalyxOS offers the most polished experience with a cross-platform graphical installer. GrapheneOS installs from the web browser over WebUSB —surprisingly simple, but limited to Chromium browsers. DivestOS requires flashing recovery, which means some familiarity with ADB and fastboot.
Which one fits your profile?
Maximum security, no compromises: GrapheneOS is the answer. If your threat model includes well-resourced actors —government agencies, targeted industrial espionage, law enforcement with forensic tools— or you simply want the best mobile security that exists regardless of what the device costs, GrapheneOS on a current Pixel is the only option that gives you real peace of mind.
Solid privacy with good usability: CalyxOS is ideal for the professional who wants privacy without complications. Lawyers, freelance journalists, doctors or business owners who need to protect sensitive data but aren't targets of state surveillance. MicroG integration makes the transition from regular Android almost transparent.
Tight budget or old hardware: DivestOS is your system. If you have a phone from a few years back that no longer gets updates, DivestOS gives it current security patches and a second working life. It's also the choice for anyone who values software freedom above all else and accepts the compatibility limits that come with it.
Journalists, activists and dissidents: GrapheneOS, without hesitation. Bootloader locking with verified boot, auto-reboot on physical tampering and wiping after failed attempts are protections that can be the difference between safety and a catastrophic leak. CalyxOS can be enough for mid-level investigative journalism. DivestOS isn't recommended for this profile because the bootloader can't be locked on most devices.
What the forums won't tell you
There's a degree of tribalism in the privacy community. You'll find die-hard defenders of each system who demonise the other two. The reality is that all three projects are serious, all three are built by competent people, and all three improve your privacy dramatically over stock Android.
What you do need to know is that none of these systems protects you from your own habits. If you install GrapheneOS and then use WhatsApp with your real number, grant location permissions to Google Maps and sync your photos with Google Photos, you've thrown away most of the protection. The operating system is one layer —the most important one— but it has to come with digital hygiene.
It's also worth remembering that DivestOS, by supporting devices from dozens of manufacturers, inherits each one's firmware vulnerabilities. An Android security patch doesn't fix a bug in Qualcomm's WiFi driver if the manufacturer never ships the firmware update. Pixels —the base for GrapheneOS and CalyxOS— get firmware updates directly from Google for at least 5 years.
Conclusion: there's no wrong decision, only informed ones
Any of these three operating systems is an enormous privacy leap over the Android your phone shipped with. The decision comes down to your threat model, your budget and your tolerance for technical friction.
At Securfy we work mainly with GrapheneOS because we believe the "security without compromise" model protects our clients best. But we understand that everyone's needs differ. If you're unsure which system suits you, write to us —our engineering team will advise you with no obligation and no tribalism.
Every device we ship comes with the operating system installed, configured and verified. All you do is turn it on and start using it. No 40-step tutorials, no terminal commands, no risk of bricking the device. Privacy shouldn't require a computer science degree.



