Using Android Without a Google Account
theprivacydad.com
theprivacydad.com
Also, if you're handset model supports relocking, you can use banking apps etc.
[0]: https://divestos.org
From what I understand there's been a fair amount of drama in the de-googled OS space.
My experience with DOS has been exceptional and I'd encourage anyone who uses it to donate towards SZs ongoing efforts. It's pretty amazing what he's achieved on mostly his own.
I'm assuming you're a GrapheneOS proponent, because I noticed you rarely used "Google" as the answer to anything on Graphene even though that often is the answer. Graphene is very clear they're a security focused OS, and will consider privacy secondarily. The sandboxed Google Play is excellent for security, and provides the maximum equivalent compatibility possible with ASOP, but it's far less private than microG, which is only a little reduced by some of the extras GOS includes. Divest and Calyx are privacy focused first, and hardened security second. They use microG for the privacy, and actually take a number of the Graphene security patches. They're focused on making a device people can actually use while remaining relatively private. Obviously very different use cases and considerations between the two sets of projects.
My personal experience is that Graphene is very interested in deep system changes to improve security, but is inconsistent in whether Google is considered trusted or not (mostly for cases when it's convenient/inconvenient). The occasional privacy-specific feature gets thrown in too, which is usually excellent, but user experience is pretty low priority, and almost anything but the ultra hardened use case isn't really of much interest. Throwing raw GApps in as a sandboxed app is a perfect example, it's a great security limitation that it's sandboxed, but a haphazard privacy choice where Google is mostly considered "trusted" as a privacy source ("just don't use it if you want privacy"). The unfortunate reality is that most phones have huge usability problems if you don't have something acting as part of the GApps, e.g. location takes 5+ minutes to lock in on GrapheneOS without GApps if you haven't locked it in recently, and won't ever lock in if you try to use an app relying on GApps (almost all of them). I'm personally more focused on privacy than ultra hardened security since I'm not a journalist under threat by nation state actors (Graphene is ideal for that use case).
To be more clear you might consider splitting Graphene into 2 columns, 1 without GApps installed and 1 with.
This article doesn't explain you need to log out of all Google accounts before factory reset. If that's not possible, you'll have to find an FRP bypass and hope for the best. The e4plus is nearly 7 years old. It'll probably work, but newer devices are increasingly difficult.
And if there's no Google account, you can just skip wifi during initial setup. That way you can setup a firewall first by installing the apk over usb.
Google Play makes the bulk of its money on in-app purchases. It’s essentially the same software royalty business model as the PlayStation Store or Steam. I doubt it’s really a heavy personal information tracking app like Google Search, with the exception of personalization for ads for apps within the store (which can be de-personalized).
Now, that’s not to say I don’t think it’s good to De-Google your life. However, for me personally, stuff like breaking bank apps or being unable to buy paid apps would be something of a dealbreaker.
Using Android with an alternative browser, ad blocker, and email service that are outside of Google, and auditing your account privacy settings is already avoiding 95% of the personal info tracking that Google does on the average person, if I were to guess.
Google is quite up front and transparent about what the services do and what data they collect. The user can control pretty much all of it via device and account settings.
https://support.google.com/android/answer/10546414?hl=en
Personally, a lot of the tin foil hat privacy stuff isn’t worth losing some rather useful services like sending emergency responders my location.
On you last point, consider that some people view those features as marginally useful or view abstinence from their use as worthwhile self-deprivation (e.g. I spend no time alone, so my emergency calls are already a solved problem.)
Having said that, I don't use a Graphene OS Pixel or any other de-Googled phone, but the existence of such a market shouldn't be surprising.
It's not popular to say because Google is everyone's favorite villain, but those banking apps are far, far greater privacy threats.
A typical user session on the Chase website or mobile app might make a couple hundred https requests, and between 30% and 50% of those requests go to a dog's breakfast of 30 to 40 different non-Chase sites.
If you think it's important for your privacy to de-Google your phone, more power to you. But if you don't also de-Chase and de-Schwab and de-Instagram and de-Amazon at the same time, then your threat model is a lot different than my threat model.
If I host some static files on S3 and your browser makes some requests to AWS URLs that doesn’t mean that I’m giving all your info to AWS.