Home > Skiantoù > Stlenneg > Secure banking apps on GrapheneOS
Secure banking apps on GrapheneOS
Wednesday 2 September 2026, by
All the versions of this article: [brezhoneg] [English] [français]
With GrapheneOS, which is more secure for banking apps: creating a separate profile to launch the apps, or using the private space?
A separate profile is more secure than Private Space, even if it’s a little less convenient for everyday use.
Why:
- A secondary user profile is a complete and isolated Android environment: its own encryption key, separate storage, and, most importantly, a separate VPN for each profile (secondary profiles have their own VPN configuration, just like Private Spaces)—but the isolation goes further for profiles, with complete system-level partitioning, as if it were a second device.
- Private Space (the Android 15 feature adopted by GrapheneOS) runs within the same user session. Isolation exists (separate data and apps), but it’s less airtight than a true profile, since it shares more of the main profile’s context.
Specifically for your banking apps: The practice recommended by the GrapheneOS community is to create a dedicated profile (often called “Google” or “Banking”) in which you install sandboxed Play Services plus your banking apps. This avoids any compatibility issues, as these apps then function just as they would on a standard Android device. You switch to it only when you need it, then switch back to your main profile. [1]
The downside of a separate profile: you have to switch sessions (which takes a few seconds), and data sharing between profiles isn’t built-in—you’ll need to use an app like Inter Profile Sharing if necessary.
If the hassle of switching profiles really puts you off, the private space is more than enough for most uses—but if maximum security for banking is your priority, the separate profile is the most robust choice.
Do apps need to be installed from the main profile, or can they be installed directly on the “Banking” profile?
Apps are installed directly in the “Banking” profile—not from the main profile.
How it works:
- Switch to the “Banking” profile (via the unlock screen menu or system settings).
- From this profile, you install GrapheneOS’s sandboxed Play Store (Sandboxed Google Play), then your banking apps via that Play Store.
- Each profile has its own Play Store and its own installed apps: nothing installed in the main profile appears in the “Banking” profile, and vice versa.
Two useful tips:
- If an app is already installed in the main profile, GrapheneOS lets you install it in another profile without re-downloading it, using the “Install available apps” feature—which is handy if you use the same app (e.g., an authentication app) in both profiles.
- From the main profile (Owner), you can disable app installation in the secondary profile once you’ve added everything you need to it—this prevents a malicious or compromised app from being installed there later without your knowledge.
In summary: You configure everything from within the “Banking” profile itself; the main profile is only used to manage global settings (profile creation, installation permissions, etc.).
If I disable app installation, will apps that are already installed still receive updates?
No — disabling this option also blocks updates, not just new installations.
The setting is actually called “App installs and updates” in the GrapheneOS settings, not just “installation.” When you disable it for the “Banking” profile, nothing can be installed or updated in that profile, regardless of the method (Play Store, Install Available Apps from the main profile, ADB, etc.)—the block is complete.
In practice, this means:
- Your banking apps will not receive security updates as long as this setting is disabled.
- To update them, you must temporarily re-enable the option, let the Play Store perform its updates, and then disable it again.
A more practical alternative: Instead of completely blocking installations, select the “First party only” option if it’s available in your profile—it allows updates via the Play Store or the legitimate installer while blocking the installation of apps from other sources. Otherwise, a simple routine is to re-enable the option once a week or every two weeks to allow updates to install, then disable it again.