

If you have Aurora installed that is still being done. If you don’t want to send that list then don’t use any play services.


If you have Aurora installed that is still being done. If you don’t want to send that list then don’t use any play services.


It runs as an unprivileged user app and uses randomized accounts.
Google play services under graphene are all also unprivileged.
You can add all apps you dont want Google to know of to your blocklist, so the unique fingerprint from your app list is extremely reduced
I wouldn’t say extremely, as you still need to keep all of the apps which you install from the store itself unblocked to get updates. Anecdotally for me, that list is all of the niche apps which I can’t use FOSS alternatives for, like banking, work, transit, etc. so it’s very likely still uniquely identifying. If you’re hiding system services in Aurora that you don’t want it touching, that makes it even easier to identify you, because Google play doesn’t do that.
Aurora is WAY better for privacy
I’m not a security researcher and am basically regurgitating what the Graphene team has said about it, as I think they know a lot more about how the play store works under the hood and the information that is required to send to Google than I do. I think they have a blog post about it somewhere.


The GrapheneOS team explicitly recommends against installing the aurora store for that exact reason. If you can install the stock play store with a burner email then the aurora store doesn’t actually give much of a privacy benefit (you are still uniquely identified either way) but aurora store is playing a game of whack-a-mole with Google.
Worth noting that when you buy a pixel from a carrier in the US the bootloader is typically locked anyway, at least for the big ones. This even includes versions where the SIM is unlocked to support other carriers