I got a new phone. Skipped a few generations and now I’m running the current GrapheneOS, based on Android 15. I’ve moved most of the apps, but now I’d like to install my 3 banking apps and 5 discount program spyware apps. I guess I best separate them from the rest of the arbitrary stuff. Banking apps so they can’t be messed with, and shady discount programs so those apps can’t mess with me and my data…
The internet has a lot of information about Shelter, work profiles, the new(?) private spaces… But I don’t know what is current advice and what’s outdated advice… What’s the current best practice?
I saw this thread which has some discussion
https://discuss.privacyguides.net/t/android-private-space-vs-work-profile/21101/4
Which to me sounds like ‘private spaces’ is made for this purpose, while shelter + work profile was a workaround for some time. Since it is new, it might take some time for FOSS apps to implement related features, like being able to launch those apps from your homescreen.
Hopefully someone else comes with better advice :)
Edit: these ones suggests that private spaces is better
https://discuss.grapheneos.org/d/16569-android-15-private-space-please-explain
Up through Android 14 everything boils down to different programs to manage a work profile. I’ve always used Shelter or just straight up used the built in work profile support in LineageOS.
I don’t know if it’s possible to create more than one separate space.
Edit: the only way I’ve found to make two separate app containers on android <= 14 is a combination of a work profile and Samsung’s secure folder. I don’t know of any other sandbox technique.
Did no one mention the multiple users feature on grapheneos? Especially apps you need seldom you can just run under a different user.