Skip to content
Platform6 min read

The Best Private Apps for a De-Googled Phone

The best private apps for a de-Googled phone: a practical no-Google stack for messaging, maps, browsing, email and files, with privacy-first picks that work.

By The PrivacyPortal Team

The best private apps for a de-Googled phone are the ones that run without Google Play Services, keep your data on your device, and are ideally open-source. This guide is a practical, install-today app stack for a phone running GrapheneOS, /e/OS, LineageOS, or any de-Googled ROM, with a deliberate focus on private messaging, since that's the part people get wrong most often.

What "de-Googled" actually changes

On a stock Android phone, apps assume Google Play Services is always there: push notifications ride on Firebase Cloud Messaging (FCM), location leans on Google's fused-location service, and "Sign in with Google" is one tap away. Strip that layer out and two things happen at once. Some mainstream apps misbehave or refuse to start, and you get to choose replacements that don't quietly report back to Google.

Two principles keep a de-Googled stack sane:

  • Prefer apps that work without Google Play Services. microG is optional, not mandatory. The cleanest apps need neither.
  • Prefer open-source software from a source you trust rather than any random APK.

Where you get apps matters as much as which apps you pick. The three sensible sources are F-Droid (a catalog of open-source apps), Aurora Store (an anonymous front-end for the handful of Play Store apps you still need), and direct APKs from a project's own website or GitHub releases.

The private app stack at a glance

Category Private picks Why it fits a de-Googled phone
App source F-Droid, Aurora Store Open-source catalog + anonymous Play access, no Google account
Browser Mull, Brave, Vanadium (GrapheneOS) Hardened, tracker-resistant, no Google sign-in
Search DuckDuckGo, Startpage, SearXNG No profile built from your queries
Maps Organic Maps, OsmAnd OpenStreetMap data, offline, no Play location
Email Proton Mail, Tuta Encrypted mailboxes, no Gmail lock-in
Passwords Bitwarden, KeePassDX Open-source vaults, local or self-hosted options
Keyboard OpenBoard, FlorisBoard No cloud typing telemetry
Files & notes Standard Notes, local storage On-device, encrypted where it counts
Messaging See below The one worth thinking hardest about

You can mix and match, but the list above gives you a full daily driver without ever touching a Google service.

Why messaging is the hard part

Everything else on a de-Googled phone is a fairly clean swap. Messaging is harder because it drags in a second problem: identity. Most mainstream messengers tie your account to a phone number, and many still rely on Google Play Services for push notifications. On a de-Googled phone, both are friction, and a phone number is a permanent, real-world identifier you may not want attached to your conversations at all.

Here's an honest read on the popular options, and how each behaves once Google is out of the picture.

Signal

Signal is end-to-end encrypted by default, open-source, and works hard to minimise metadata (its sealed-sender feature hides who is messaging whom). It has adopted a post-quantum key-agreement layer (PQXDH). The catch for this use case: Signal requires a phone number to register. Usernames can hide that number from other users, but registration still needs one. Its official builds use FCM for push; on a de-Googled phone it falls back to a background websocket, which works but affects battery and notification timing.

WhatsApp

Message content is end-to-end encrypted using the Signal Protocol, so the messages themselves are protected. But WhatsApp is owned by Meta, ties you to a phone number, and collects a lot of metadata around your usage. Cloud backups are not end-to-end encrypted unless you specifically turn on encrypted backups. It also expects Google Play Services and is awkward on a de-Googled device.

Telegram

A common misconception: Telegram is not end-to-end encrypted by default. Its ordinary cloud chats can be accessed by Telegram, and only opt-in one-to-one "Secret Chats" are end-to-end encrypted. It also requires a phone number. Treat it as a social app, not a private one.

Session and Threema

Session needs no phone number, routes traffic through an onion network, and is open-source. Threema is a paid, Swiss app with open-source clients that also does not require a phone number. Both are reasonable choices if a number-free identity is your priority.

For a deeper comparison, see our pillar guide to the best encrypted messenger, and our walkthrough of messaging without Google Play Services.

Where Graphite fits

Graphite is built for precisely the situation a de-Googled phone puts you in. There is no phone number and no email to sign up. Your identity is a 12-word recovery phrase generated on your device — there is no account sitting on a server to leak, subpoena, or lose.

A few things that make it a natural fit for this stack:

  • Runs without Google Play Services. The Android build is a sideloaded APK that works on GrapheneOS and de-Googled phones with no Google dependency. There are also a portable Windows .exe (with Tor bundled) and a web app.
  • Strong, modern encryption. Messages use NaCl/libsodium X25519 sealed boxes, with a hybrid post-quantum layer (ML-KEM-768) and Signal-style double-ratchet forward secrecy.
  • Tor by default, fail-closed. Bundled Tor connects to a hidden service, hiding your IP and network. Tor carries the signaling and messages; real-time call media is peer-to-peer DTLS-SRTP (not routed over Tor) for quality, and on mobile calls are routed so the other person doesn't see your IP.
  • A relay that stores almost nothing. It holds only sealed ciphertext, for a 7-day maximum, deleted after delivery. It never sees your plaintext, your keys, or your recovery phrase.
  • The features you expect. Encrypted voice and video calls, encrypted group chats, file sharing, and on-device AI message search — nothing about that search is uploaded.

Graphite doesn't replace Signal or Session for everyone; if all your contacts are already on one network, meet them there. But if you want a messenger whose identity model matches a de-Googled phone — no number, no email, no server-side account — it slots in cleanly. For the GrapheneOS angle specifically, see the best encrypted messenger for GrapheneOS.

Putting it together

A sensible order to set up a fresh de-Googled phone:

  1. Install F-Droid and Aurora Store first — everything else flows from there.
  2. Lock down the basics: a hardened browser, a private search default, and an OpenStreetMap maps app for offline navigation.
  3. Move email and passwords to encrypted, open tools so you're not re-authenticating through Google.
  4. Pick your messengers deliberately. It's normal to run two: one for contacts you can't move, and one number-free option like Graphite for conversations you'd rather keep off a phone-number identity.

A de-Googled phone is only as private as the apps you put on it. Choose tools that don't assume Google is in the room, and the whole device gets quieter.

Try Graphite

Graphite is a free public beta (v1.13.25) and a good fit for any de-Googled setup. There's no phone number, no email, and no logs — just a 12-word recovery phrase you control. It runs on Windows, Android, and the web, works on GrapheneOS and de-Googled phones with no Google Play Services, and keeps Tor on by default.

Get it at graphite.chat.