A Practical Guide to Migrating to a Privacy-First Smartphone
When the Optus breach dropped in late 2022, millions of Australians realised how much personal data a phone number, an address, and a few ID documents can reveal. The Medibank incident a few weeks later reinforced the same point. Both episodes showed that the information quietly stored on a modern smartphone is rarely as private as people assume, and that the companies holding it do not always keep it safe. Moving to a privacy-focused smartphone is one way to reduce the surface area available to thieves, advertisers, and data brokers in the first place.
The switch does not have to be dramatic. A weekend of preparation, a handful of new apps, and a slightly different daily routine are usually enough to leave the worst tracking behind. This guide walks through the practical steps Australians can take, from picking the right operating system through to changing how they pay for coffee in Sydney or groceries in Brisbane.
Picking an Operating System That Respects You
The first decision is the operating system, because that choice shapes every other setting later. Mainstream Android and iOS ship with deep hooks into Google or Apple services: cloud backups, app stores, location history, advertising identifiers, and crash reporting all flow back to the parent company. A privacy-first OS strips those hooks out, while still running the apps most people need.
Four options dominate the conversation. GrapheneOS is the strictest, hardened against exploits and designed for Pixel phones. CalyxOS sits next to it, also Pixel-only, but with optional microG support that lets apps that depend on Google Play Services keep working. /e/OS, from the makers of the Murena phone, ships on a few European handsets and aims for a friendlier experience. LineageOS is the longest-running custom Android, runs on dozens of older devices, and appeals to tinkerers happy to configure things by hand.
| Operating System | Best Hardware Fit | App Compatibility | Maintenance Burden | MicroG Support |
|---|---|---|---|---|
| GrapheneOS | Google Pixel 6-9 | Sideload required | Low | Optional add-on |
| CalyxOS | Google Pixel 6-9 | Most Play apps work | Low | Built in |
| /e/OS | Murena phones, Pixel, Fairphone | Most Play apps work | Medium | Built in |
| LineageOS | Many older devices | Sideload required | Medium to high | Optional add-on |
For most readers, a Pixel running GrapheneOS is the easiest balance of security and simplicity. GrapheneOS verifies the boot chain, ships security patches on the same day Google does, and runs sandboxed apps through a hardened memory allocator. A secondhand Pixel 7 or 8 bought through a local refurbisher in Melbourne or Adelaide runs the OS without compromise, and the camera remains good enough for everyday use.
Preparing Your Data Before You Switch
Migration works best when the old phone is still intact, because most operating systems include an export tool that pushes contacts, calendars, photos, and notes to a single file. On Android, that lives inside Settings under System and then Backup. On iOS, the nearest equivalent is a local iTunes or Finder backup. The resulting file can then be imported through DAVx5 for calendars and a contact importer for the address book.
Passwords deserve their own migration step. Export from the old phone's password manager, or simply keep using a cross-platform manager such as Bitwarden, Proton Pass, or KeePassXC, and let the new phone log in once. Two-factor codes are trickier, because most authenticator apps lock their secrets to a single device. Print or export the recovery codes from Google Authenticator, Aegis, or Authy before wiping anything. Several Australian banks, including CBA, ANZ, and NAB, also support time-based codes through their own apps, which makes recovery easier if a token is lost.
Email is the other heavy item. Gmail and Outlook accounts can be reached through any IMAP client, but the address book inside Gmail is harder to move. A vCard export from Google Contacts on the web is the cleanest path, and it sidesteps the sync loop that otherwise follows a new phone around. For people who want a more private inbox from the start, Proton Mail and Tutanota both import old mail and run fine on a de-Googled handset. The blog at https://twentyoftime.com/ covers several of these trade-offs in longer essays.
Installing Core Apps Without Google Play
Once the new phone boots, the absence of the Play Store is the first shock. F-Droid fills most of the gap. It is a free, community-curated catalogue of open-source apps, including Firefox, K-9 Mail, OsmAnd for maps, and NewPipe for YouTube. Aurora Store sits alongside it as an unofficial front-end for Google Play, useful for the occasional app that refuses to run without Google Services, such as some banking apps and ride-share tools used around Sydney and Perth.
Browsers deserve a deliberate choice. Brave blocks trackers by default and ships with a built-in Tor mode. Firefox with the uBlock Origin extension is another strong option, particularly when paired with the Mull or Iceweasel forks that strip Mozilla's own telemetry. Whichever browser is picked, set it as the default, then revoke the default-browser permission from every other app that requested it during setup.
Messaging is straightforward: Signal handles end-to-end text, voice, and video for free, and is the closest thing to a privacy default in Australia. For people who still need to reach friends on WhatsApp, the app runs fine on GrapheneOS or /e/OS through Aurora, but loses some of its privacy benefits when paired with a Google account. Signal offers a transferable identity key for shifting devices, and local copies of important chats can be exported before the move.
Locking Down Network and Location Tracking
A privacy-focused phone is only as private as the network it sits on. Australian carriers collect metadata by default under the Telecommunications (Interception and Access) Act 1979, and the Assistance and Access Act 2018 allows agencies to request access to encrypted communications under certain warrants. None of that changes with a custom ROM, but reducing the metadata at your end is still worthwhile.
The first move is a VPN with a privacy-friendly logging policy, though readers weighing their options may want to read the VPN trust problem write-up first, since not every provider keeps the promises they make in marketing. Pair the VPN with a private DNS resolver such as Quad9 or NextDNS, both of which block known tracking domains at the resolver level and work on de-Googled handsets.
Location services need a separate pass. GrapheneOS and /e/OS let the user deny precise location to any app and fall back to a coarse city-level fix, which is enough for weather and maps without revealing the exact office or home address. The carrier still sees tower-level positions, but app-level granularity drops sharply when precise permission is refused. Turning off Wi-Fi and Bluetooth scanning inside Privacy settings closes another common leak.
Replacing Daily Payment Habits
Cards are usually the weakest link in a privacy migration. Every tap in a Melbourne café or Brisbane supermarket produces a record tied to the cardholder, the merchant, the time, and often the GPS coordinates of the terminal. The piece on the permanent data trail explains how that record accumulates and why it persists long after the purchase is forgotten.
Cash is the obvious alternative, and still works in most Australian settings. For online spending, prepaid Visa or Mastercard gift cards bought from a Coles or Woolworths service desk in person give a disposable number with a small float, which keeps the bank-issued card out of merchant databases entirely. PayID and direct debit continue to work, since they sit at the bank layer rather than the merchant layer, and BPAY is similarly neutral.
Bank apps themselves are a mixed bag. The big four Australian banks do not yet ship versions that run on a fully de-Googled phone, and their security teams may lock accounts that try to log in from an unusual device fingerprint. A practical workaround is to keep the bank app on a separate, lightly used device, or to fall back to browser-based banking, which the banks officially support. The phone that handles everyday communication does not need to be the same one that holds the cheque account.
Keeping the Setup Steady
Privacy drifts. New apps accumulate permissions, operating system updates reset some toggles, and the temptation to reinstall a convenient Google service grows with time. A short monthly review keeps the configuration honest. Open the permission dashboard, revoke anything granted in the last thirty days that no longer feels necessary, and check that the default browser and keyboard are still the chosen private options.
Updates deserve the same attention. GrapheneOS and /e/OS both push security patches automatically, but the underlying app catalogue does not. Aurora Store and Obtainium can be set to check for new versions of sideloaded apps, and F-Droid notifies when an installed app has an update queued. Skipping updates for convenience is the same kind of slow erosion that makes a privacy setup revert to defaults.
If a single concrete step is the right place to start tonight, open the settings app on the current phone, tap Privacy, and read the permission list out loud. The five or ten apps that have access to location, microphone, contacts, and camera reveal exactly where the data trail starts, and where the new setup will need to do its work.