this post was submitted on 19 Apr 2025
64 points (97.1% liked)

Privacy

37292 readers
1271 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 

For context: I recently switched to a Pixel 9, installed GrapheneOS and created a profile just for some apps I need Play Store for, which is sandboxed btw. I created a new empty google account for it too.

So I was just downloading an app and saw the option to download it on my old device too, which made me wonder how GP knows about it, since I don't think I have anything on my new phone that could link to it (except my SIM I guess)

Any ideas?

you are viewing a single comment's thread
view the rest of the comments
[–] kyub@discuss.tchncs.de 63 points 1 week ago* (last edited 1 week ago) (6 children)

Just for reference, this is what the Google Play services app transmits roughly every 20 minutes to Google if it has network access:

Phone #
SIM #
IMEI (world-wide unique device ID)
S/N of your device
WIFI MAC address
Android ID
Mail Address of your logged in Google account
IP address

And that is when you have disabled ALL telemetry in ALL of the options, even the most hidden ones. So this is the minimum amount this app is always gathering from every Android user using the Google Play services app, no matter what you selected. Other Google apps (like the Play store app) could then contain additional telemetry on top, this is just the common base of all Google proprietary apps. Or the minimum amount of privacy violations you get when using proprietary Google apps on your phone, no matter what.

If you use GrapheneOS, I'd recommend not installing/using ANY Google apps at all (not even Play store or Play services). To get apps, you should use (roughly in this order of priority): 1.) GrapheneOS's app store for the built-in apps 2.) Accrescent app store (has several good open source apps, is intended to be more secure than F-Droid) 3.) Obtainium (for getting open source apps directly from their source repos) or if you really can't get into Obtainium, use F-Droid instead 4.) Aurora Store (for getting apps from the Google Play store without sending too much data to Google. Only do this if there is no open source app available for doing the same thing).

To fully mitigate the removal of the Play services app, you also should probably install/configure something like ntfy to get battery efficient push notifications and ideally use apps which also use that, e.g. the Molly fork instead of Signal. It's quite easy to do, just something to be aware of. Otherwise your battery drain might be a bit higher. Then you're also independent from Google's push notification infrastructure. But you need a ntfy server to go along with it, either self-hosted or use a public one. There are some privacy friendly ones public ones out there.

[–] eleutheros@lemmy.ml 12 points 1 week ago (3 children)

Great to know about what it sends. I was using fdroid on my more private profile, but did not know about Aurora Store, this one I will check out. I was using GP mainly to download my banking apps, which I sadly need by the time being.

Thanks for the info!

[–] m4th1337@lemmy.world 0 points 1 week ago (1 children)

ήσουν καταπιεσμενος και τώρα είσαι ελεύθερος;

[–] eleutheros@lemmy.ml 1 points 1 week ago (1 children)

I'm not greek but a friend taught me the word and I thought it made a nice analogy of what I'm trying to achieve :)

[–] m4th1337@lemmy.world 2 points 1 week ago

that's awesome! i thought you were greek ahahaha

wish you the best!

load more comments (1 replies)
load more comments (3 replies)