I have a "banking" profile set up with Google Play services installed. 98% of the time I'm using my phone, I'm using the primary Owner profile. All the other profiles are encrypted-at-rest, meaning that until I enter my Banking-profile-specific PIN, the apps and data (including the Google Play Services installed there) are just encrypted files, and unable to do anything at all. (There are provisions for allowing a secondary profile to run in the background, but in this case I have obviously left that disabled.)
So yes, you can hand the phone over to a friend or family, and they cannot get to any other user profile. Or you can set up a separate profile just for them, and they will have their own isolated set of apps - something like a separate user account on a desktop PC. And if only they know the PIN for their profile and you don't, they can keep secrets from you on that profile.
> Both iOS and Google Android transmit telemetry, despite the user explicitly opting out of this. When a SIM is inserted both iOS and Google Android send details to Apple/Google. iOS sends the MAC addresses of nearby devices, e.g. other handsets and the home gateway, to Apple together with their GPS location. Currently there are few, if any, realistic options for preventing this data sharing
P.S: Citing a paper from 2021 is propably useless. Apple was the driving force in dropping trackable App ids, google had to follow suit. More stuff has happend in the space since then.
But that is exactly what your previous comment said:
>> Sounds like an awful lot of work vs. just having an iPhone and regularly install your banking app on it, and still not get spied on.
Installing GrapheneOS admittedly requires a computer, a browser, and about 15 minutes of your time after you buy the device, assuming you've never done it before, but claiming that that's "an awful lot of work" compared to "just" having an iPhone is false. They don't provide even remotely the same level of control over your privacy or security. With technical hardening measures on one side, and on the other, a vague promise that Apple might crack down on third party tracking methods that happen to be misaligned with their own business goals.
> AirDrop works offline only between devices etc.
That's actually a great example because Apple obediently restricted AirDrop as soon as Chinese authorities discovered that it was being used for anti-government protests. Apple doesn't care about privacy ideologically, their actions in other countries and their commitment to growing their advertising business should serve as proof of that, but there's clearly some dissonance at play.