graphene·playbook
Get it — $19
For journalists, activists & privacy-first Pixel owners

Make your phone useless to whoever seizes it.

A step-by-step playbook to harden a Pixel with GrapheneOS so a locked device resists forensic data extraction — exact settings, command sequences, and a verification check after every step. No guesswork, no theory.

Get the playbook — $19 Instant PDF + EPUB
30-day money-back guarantee
42 pages of exact settings PDF + EPUB, instant download Lifetime updates included 30-day money-back guarantee
§01 · The threat

What "locked" actually leaves exposed

Most people trust the lock screen. Forensic tools don't care about it — they target the gaps below it. Same phone, seized twice:

Stock Pixelseized
screen ....... LOCKED
memory ....... KEYS RESIDENT
usb port ..... ACCEPTS CABLE
profiles ..... 1 — HOLDS ALL
duress pin ... NONE
extraction ... IN PROGRESS
Hardened Pixelafter the playbook
screen ....... LOCKED
memory ....... BFU — ENCRYPTED
usb port ..... DEAD
profiles ..... COMPARTMENTED
duress pin ... ARMED
extraction ... FAILED

A cabled extraction tool can start pulling from a stock phone in under 30 seconds. On stock Android, one profile holds everything — a single unlock exposes messages, photos, and keys at once. And with no auto-reboot and no duress trigger, a seized device sits in its most vulnerable state for hours, waiting for the lab.

§02 · Straight from the playbook

Every chapter works like this

Numbered steps, exact settings, then a verification check — so you never have to wonder whether it took. This is page 41:

Ch. 4 — Duress & auto-reboot defense3 of 6 steps
Return the device to its safest state — automatically
01

Set auto-reboot to 8h so the device returns to Before-First-Unlock encryption while unattended.

02

Configure a duress PIN that wipes eSIM and profiles the moment it's entered.

03

Disable USB at the hardware level while locked — USB-C: off — to block extraction cables entirely.

VERIFY ▸ reboot, don't unlock, plug into a computer — the port must show no device.
Privacy Hardening Playbookp. 41
§03 · Contents

Six chapters. One outcome.

Written for a real threat model, not a blog listicle.

01
Clean install & verified boot GrapheneOS on a supported Pixel, with proof the OS is the one you installed.
02
Auto-reboot & PIN policy Force Before-First-Unlock encryption whenever the phone leaves your hand.
03
Duress PIN A second PIN that wipes profiles, eSIM, and keys under coercion.
04
Hardware USB lockdown Make extraction cables meet a dead port.
05
Profiles & network isolation Compartmentalize so one unlock never exposes everything.
06
Sensors, storage & permissions Close the quiet leaks, then run the full verification checklist.

42 pages · exact settings · command sequences · verification checks

§04 · Fit check

Who this is for — and who it isn't

    Get it if you

  • Carry sources, clients, or organizing work on your phone and treat seizure as a real scenario
  • Own or plan to buy a GrapheneOS-supported Pixel
  • Want exact settings and checks, not another privacy think-piece
  • Can follow numbered steps — no coding required

    Skip it if you

  • Use an iPhone or a non-Pixel Android — the steps are Pixel-specific
  • Want general "top 10 privacy tips" content — this is one job, done deep
  • Need enterprise MDM policy — this is a personal-device manual
§05 · Get the playbook
The complete playbook
$39$19
one-time payment · lifetime updates
Get instant access
  • 30-day money-back guarantee
  • Instant download — PDF & EPUB
  • Yours forever, free updates
What happens when you click: secure Gumroad checkout → instant download link on the receipt page and by email. No account required.
§06 · Questions

Before you ask

Which phones does this work on? +

Any Pixel officially supported by GrapheneOS. Chapter 1 covers checking support and installing cleanly. iPhones and non-Pixel Androids are out of scope — the hardening surfaces simply don't exist there.

Do I need to be technical? +

You need to be able to follow numbered steps carefully. No coding. Where a command sequence appears, it's given exactly, and every step ends with a check that confirms it took.

How long does the full hardening take? +

Plan for an afternoon: the install and verified-boot chapter is the longest part; the remaining chapters are settings work you can do in one sitting.

What exactly do I get? +

PDF and EPUB, 42 pages, delivered instantly through Gumroad. Updates are free for life — when GrapheneOS changes a relevant setting, the playbook is revised and you're notified through Gumroad.

This was written with AI assistance — why should I trust it? +

Because it never asks for trust. Every step ends in an on-device verification check — you confirm each hardening measure took effect on your own phone before moving on. The page you're reading follows the same philosophy: no scripts, no trackers, nothing you can't inspect.

What if it's not for me? +

30-day money-back guarantee, handled through Gumroad. Details on the refund page.

Your phone will be seized exactly once.
Harden it first.

42 pages. One afternoon. A device that keeps your work yours.

Get the playbook — $19