GrapheneOS's goal is privacy for the world and that's achieved through secure devices. You can get a phone specifically for GrapheneOS just as you choose a new device when you're buying a new one. Soon there will be two different phone brands which you can install it on. There's already an estimated 500,000 users with Pixel exclusivity.

https://grapheneos.social/@GrapheneOS/117249893761790371

> GrapheneOS's goal is privacy for the world and that's achieved through secure devices.

Perfect is the enemy of good. What's better for privacy, an old but inexpensive smartphone running Android 11, or the same smartphone running an up-to-date third-party rebuild of Android 16 or newer with as many privacy-improving bells and whistles as the hardware can support?

> Soon there will be two different phone brands which you can install it on.

...will they be available in my country (Brazil)? I don't think I've ever seen a Google Pixel phone in person.

Are all of these unsuitable [0]?

Not sure if you have any experience with eBay. I looked it up and people had problems selling to Brazil [1] but there are various listings that offer to ship. So maybe not a great option.

KaBuM!, Intec Store, Performance Solutions all charge significantly more with a 10a being more than double than from Google.

Motorola officially sells the Signature in Brazil [2] at the same price or cheaper than in the UK. It will be supported by GrapheneOS in 2027 on the 2027 version. From then on, hopefully Qualcomm brings MTE to the non-flagship chips and Motorola and GrapheneOS support budget or midrange devices.

>perfect is the enemy of good

I don't consider that relevant when users deserve ≥ security than an iPhone. GrapheneOS is not purpose-built to avoid big-tech's services although it does that more completely than any other alternative mobile operating system, the focus is privacy.

GrapheneOS on the state of privacy and security for their ethos: https://x.com/GrapheneOS/status/2044440381803069778

[0] https://www.ebay.com/sch/i.html?_nkw=google+pixel+9

[1] https://reddit.com/r/Ebay/comments/1d92pyn/

https://community.ebay.com/forum/shipping-57923/topic/diffic...

[2] https://www.motorola.com.br/smartphone-motorola-signature/p?...

> Are all of these unsuitable [0]? [...] I looked it up and people had problems selling to Brazil [1] but there are various listings that offer to ship.

Do these phones have ANATEL certification? Because if they don't, they will be rejected by customs. It's not simply a case of the item being held until you pay a 60% import tax.

There are [1] people currently using GrapheneOS in Brazil. You can ask on the forum and you might get more clarity. The Motorola Signature will be announced in a few days but is a high end flagship with all-around better hardware than the Pixel 11 Pro XL and it's cheaper, but it's still a flagshio.

[1] https://discuss.grapheneos.org/?q=brazil%20

The purpose of GrapheneOS isn't providing a less bad operating system for insecure devices which still lacks anything close to reasonable security patches and protections. It would not be possible to provide the core GrapheneOS feature set on those devices. More importantly, they'd have many years of missing firmware, kernel, driver and HAL updates. Those are among the most important security updates and would not be available in practice. That would not be GrapheneOS and is not the purpose of GrapheneOS.

What's better for privacy, an old but inexpensive smartphone running Android 11, or the same smartphone running an up-to-date third-party rebuild of Android 16 or newer

I see your point, but it would be very misleading, since the phone would still have a lot of known holes. Only the OS would get updated, typically not the drivers, driver firmware, possibly not the kernel. The phone would still be easily compromised through all the known RCEs. So you tie up non-profit projects in a lot of extra work to get an improvement that does not really matter.

This is a mess created by the OEMs and they will continue to create this mess until people will stop buying from OEMs that only give lip service to security updates (roll out Android Security Bulletins to show a high patch level, while in reality the phone the phone has many known CVEs).

Android Security Bulletins do list a tiny subset of firmware, Linux kernel, driver and HAL patches so they do require at least very minimal updates to those. Most non-Google-certified operating systems are setting an inaccurate Android security patch level by ignoring the non-AOSP portion of the patches. GrapheneOS doesn't do that but most of the other AOSP-based projects not being certified by Google are doing it. OEMs were caught doing it too but it's not clear if it was intentional in most cases as it is with the alternate operating systems.

Android Security Bulletins set a very low bar since the AOSP patches are available to ship by OEMs 2-6 months prior to the bulletin being published. It's also only High/Critical severity patches being listed. Due to a recent policy change, it's also officially only a subset of the patches for AOSP. That's visible through the Android platform components having patches in the Pixel Update Bulletin for September 2026 despite those being applicable to other operating systems. It's because they no longer want to backport all High and Critical severity patches due to the high volume of issues discovered by AI models. It's similar to how they stopped backporting any Low and Moderate severity patches years ago due to high volume.