Mobile Operating-System Privacy Comparison
This source-dated matrix compares four preregistered mobile operating-system paths across fourteen attributes; it is not device testing, a security verdict, or a recommendation.
/* Not legal advice. This page is research, not compliance guidance. */ /* */
What this mobile-OS comparison can establish
This matrix establishes what cited sources stated for four preregistered paths across fourteen attributes; it does not independently test devices or issue a security verdict.
The frozen roster mixes two full operating-system paths, an optional protection-mode scope, and a broad platform baseline. Side-by-side placement means the same questions were asked of each path; it does not make the scopes interchangeable. Every value keeps the device, release, channel, feature, platform, product, plan, region, claim type, source class, capture date, observation version, and applicability supplied by its exact cell.
The evidence set contains fifty-six current persisted cells: forty-eight cells with confirmed values and eight verified absences. The eight row-level absences comprise two audit-report cells for iOS with Lockdown Mode and Stock Android, four later-verification-trigger cells for CalyxOS, GrapheneOS, iOS with Lockdown Mode, and Stock Android, and two signup-identifier cells for iOS with Lockdown Mode and Stock Android. At stored-record grain, thirty-four verified-absence records occur across twenty-eight cells: twenty-two are nested within twenty cells with confirmed values, while twelve support the eight row-level absence cells. The two grains remain distinct because a whole cell can be renderable while one nested field within that cell remains unknown.
A verified absence describes only the declared source document and field recorded in its cell or nested record. It is not rewritten as no, zero, unsupported, insecure, closed-source, or nonexistent. A documented mechanism is likewise not promoted into proof of complete privacy, complete security, universal compatibility, or behavior across every device, build, release, region, application, or account state.
The comparison does not create accounts, install operating systems, activate protection modes, test devices, import unregistered third-party reviews, assign scores, rank paths, or select a preferred option. The privacy-tool comparison methodology explains the evidence labels, capture boundary, neutral ordering, and correction path. There is no affiliate, referral, sponsorship, gift, preferred-access, or paid-placement relationship with a listed vendor.
Supported devices, releases, and update paths
Device compatibility and update availability are separate questions, so support for a device family does not establish which release channel, update source, rollout model, or support window applies.
The device-support column reports only the device families, models, hardware requirements, availability boundaries, release scope, feature scope, and exceptions carried by the current cell. A device family named in a source is not treated as evidence that every model, regional variant, carrier build, or later release has the same support. An optional feature remains limited to the devices and releases for which the cell documents it.
The update column answers a different question. It preserves the update source, publisher or signing actor, release channel, cadence statement, rollout model, support window, device scope, and release locator represented by the cell. A past release history does not establish a future cadence, and a documented update source does not establish that every eligible device receives an update at the same time.
These boundaries matter because device eligibility can outlast, precede, or differ from a particular update statement. A compatibility claim does not supply an unsupported rollout date or support duration. An update claim does not expand the eligible hardware list. Where a nested field is a typed unknown, the unknown remains attached to that field instead of being filled from another record or a general platform description.
Read the two columns together without collapsing them into a longevity or security rating. The device cell answers where the documented path applies. The update cell answers who publishes an update and how the cited source describes delivery. Neither column predicts future availability, guarantees continued support, or establishes equivalent behavior across the mixed roster.
| Jurisdiction | Device support | Updates |
|---|---|---|
| Android Open Source Project (AOSP)Stock Android documentation names the Android Open Source Project as the project through which Android documentation and source code are available.source | Android documentation says an Android-compatible device can run third-party apps built with the Android SDK and NDK, must meet the Compatibility Definition Document requirements and pass the Compatibility Test Suite, and is eligible to participate in the Android ecosystem.source | Android documentation says devices can receive over-the-air updates to system and app software and time-zone rules, with Android 11 and later using Virtual A/B updates on modern devices.source |
| Lockdown ModeFor iOS with Lockdown Mode, Apple says personal data relating to people in the European Economic Area, United Kingdom, and Switzerland is controlled by Apple Distribution International Limited in Ireland, while data collected worldwide by Apple or its affiliates is generally stored by Apple Inc. in the United States.source | For iOS with Lockdown Mode, Apple says Lockdown Mode is available in iOS 16, iPadOS 16, macOS 13, watchOS 10, or later, with additional protections in iOS 17, iPadOS 17, macOS 14, and watchOS 10.1 or later.source | For iOS with Lockdown Mode, Apple says it regularly releases software updates for emerging security concerns and delivers updates wirelessly, with iPhone and iPad users receiving notifications on their devices.source |
| CalyxOSCalyxOS identifies the Calyx Institute End-User Terms of Service, which state that they apply to all Calyx services and websites.source | CalyxOS says it tries to support devices as long as possible and publishes estimated operating-system-upgrade and security-update dates by device.source | CalyxOS says installed devices automatically check for, download, and install frequent over-the-air updates from its servers, typically monthly after Android Open Source Project security releases.source |
| GrapheneOSGrapheneOS says the GrapheneOS Foundation was created as a Canadian nonprofit in March 2023 to receive and distribute donations.source | GrapheneOS says devices sold through some carriers may be locked and prevent installation, while officially supported devices have builds and updates available from release tags.source | GrapheneOS says its updater checks approximately every six hours when network connectivity is available, then downloads and installs updates in the background.source |
Source: 4 products. Each source link opens the authority for its cell. The page source record lists the capture date and snapshot for every cell.
Field definitions
- Device support
- Device families, models, hardware requirements, availability boundaries, release or feature scope, and exceptions stated by the current cell.
Sandbox boundaries and verified boot
Sandboxing and verified boot protect different boundaries: one constrains running software, while the other checks a documented boot chain or software state before or during startup.
The sandbox column reports the sandbox unit, isolation boundaries, permission model, interprocess-access statement, privileged exceptions, release or channel, device scope, and documentation locator represented by the exact cell. A documented sandbox does not establish that every component has identical privileges, that every application uses the same integration path, or that no permitted channel can move information across a boundary.
The verified-boot column separately reports the mechanism name, trust root or signing actor, verified components, boot-state requirements, relock or recovery behavior, update-verification statement, device scope, release or channel, and limitations supported by its cell. A boot check does not describe every behavior after startup, and a recovery or relock statement is not generalized beyond the device and state the source names.
The two mechanisms can coexist without answering the same question. Sandboxing concerns the runtime boundary described in its record. Verified boot concerns the startup or software-integrity boundary described in its record. Neither field supplies the other's missing details, and neither is converted into a claim that all data flows, applications, firmware components, accessories, or network services are covered.
Nested typed unknowns remain visible inside otherwise supported mechanisms. If a source establishes an isolation model but not one requested qualifier, the qualifier stays unknown. If it establishes a boot mechanism but not a recovery or relock detail, that gap is not filled from another path. The result is a scoped description, not a comparative-strength score or a claim of complete device protection.
| Jurisdiction | Sandboxing model | Verified boot |
|---|---|---|
| Android Open Source Project (AOSP)Stock Android documentation names the Android Open Source Project as the project through which Android documentation and source code are available.source | Android documentation says each app receives a unique user ID and runs in its own process, with a kernel-level Application Sandbox isolating apps and limiting their default access to the operating system and other apps.source | Android documentation says Verified Boot establishes a chain of trust from a hardware-protected root through the bootloader and verified partitions, while rollback protection ensures devices update only to newer Android versions.source |
| Lockdown ModeFor iOS with Lockdown Mode, Apple says personal data relating to people in the European Economic Area, United Kingdom, and Switzerland is controlled by Apple Distribution International Limited in Ireland, while data collected worldwide by Apple or its affiliates is generally stored by Apple Inc. in the United States.source | For iOS with Lockdown Mode, Apple's guide says all third-party apps are sandboxed and can access information outside their own unique home directory only through services explicitly provided by iOS, iPadOS, and visionOS.source | For iOS with Lockdown Mode, Apple's guide says startup components are cryptographically signed by Apple and boot proceeds only after verifying the chain of trust, including bootloaders, the kernel, kernel extensions, and cellular baseband firmware.source |
| CalyxOSCalyxOS identifies the Calyx Institute End-User Terms of Service, which state that they apply to all Calyx services and websites.source | CalyxOS provides a work profile and says its apps will not access data from the main profile, even if they are duplicates.source | CalyxOS says it supports fully verified boot and bootloader re-locking to ensure the operating system has not been modified and maintain physical security equivalent to stock Android.source |
| GrapheneOSGrapheneOS says the GrapheneOS Foundation was created as a Canadian nonprofit in March 2023 to receive and distribute donations.source | GrapheneOS says it hardens the app sandbox through SELinux and seccomp-bpf policy and also improves other sandboxes, including the browser-renderer sandbox.source | GrapheneOS says locking the bootloader enables full verified boot, which detects OS-partition modifications and prevents reading modified or corrupted data.source |
Source: 4 products. Each source link opens the authority for its cell. The page source record lists the capture date and snapshot for every cell.
Field definitions
- Sandboxing model
- Sandbox unit, isolation boundaries, permission model, interprocess-access statement, privileged exceptions, release or channel, device scope, and documentation locator stated by the current cell.
- Verified boot
- Mechanism name, trust root or signing actor, verified components, boot-state requirements, relock or recovery behavior, update-verification statement, device scope, release or channel, and limitations stated by the current cell.
Application distribution and identity requirements
An operating-system path and an application-store account are separate scopes, so a distribution option does not by itself establish which identifiers or later verification steps an actor requires.
The application-distribution column reports bundled stores, alternative-store support, direct-installation support, privileged integration, the account-requirement statement, region, device scope, release or channel, and limitations supported by the current cell. A documented installation route is not treated as available for every application, region, release, or hardware configuration unless the same cell establishes that boundary.
The signup column separately reports identifier type, requiredness, collecting actor, plan, region, and platform at initial use. An identifier required by one store or service is not assigned to the operating system as a whole. An operating-system installation path is not treated as proof that a separate application-distribution account is unnecessary.
The later-verification column records a trigger, requested identifier, collecting actor, retained-by value, plan, and region only when the current cell supports those elements. A later check is not inferred from initial signup, and an initial identifier is not repeated as a later requirement without a documented trigger. Nested verified absences remain limited to their declared documents and do not establish that a check can never occur.
Keeping the three columns separate prevents actor and scope drift. The platform publisher, project, device maker, application-store operator, application developer, payment participant, and account service are not assumed to be one entity. The table reports the relationships stated by each cell without turning a distribution model into an anonymity claim, an identity verdict, or proof that every application follows the same path.
| Jurisdiction | Application distribution | Signup identifiers | Later verification |
|---|---|---|---|
| Android Open Source Project (AOSP)Stock Android documentation names the Android Open Source Project as the project through which Android documentation and source code are available.source | Stock Android documentation says Android apps may be distributed through app marketplaces, websites, or email, with users opting in before installing unknown apps.source | Unknown Verified absenceNot disclosed in the captured primary source.source | Unknown Verified absenceNot disclosed in the captured primary source.source |
| Lockdown ModeFor iOS with Lockdown Mode, Apple says personal data relating to people in the European Economic Area, United Kingdom, and Switzerland is controlled by Apple Distribution International Limited in Ireland, while data collected worldwide by Apple or its affiliates is generally stored by Apple Inc. in the United States.source | For iOS with Lockdown Mode, Apple says the design principle for iPhone and iPad focuses on centralized distribution, code signing, and strict sandboxing, while European Union users can also install apps from alternative marketplaces or authorized developer websites.source | Unknown Verified absenceNot disclosed in the captured primary source.source | Unknown Verified absenceNot disclosed in the captured primary source.source |
| CalyxOSCalyxOS identifies the Calyx Institute End-User Terms of Service, which state that they apply to all Calyx services and websites.source | CalyxOS says F-Droid Basic is its preferred app store and that its default F-Droid store installs during setup, while Aurora Store provides the option to install apps without a Google account and, for paid apps or if anonymous mode is not working, lets the user additionally enter Google account credentials in its settings (some paid apps may not work).source | CalyxOS offers microG modes without a Google Account and a mode with a Google Account.source | Unknown Verified absenceNot disclosed in the captured primary source.source |
| GrapheneOSGrapheneOS says the GrapheneOS Foundation was created as a Canadian nonprofit in March 2023 to receive and distribute donations.source | GrapheneOS says its standalone apps are developed by GrapheneOS and included in the OS; the list excludes apps with no GrapheneOS modifications or only minor ones.source | GrapheneOS says it does not provide Factory Reset Protection because the standard implementation depends on tying a device to an online-service account.source | Unknown Verified absenceNot disclosed in the captured primary source.source |
Source: 4 products. Each source link opens the authority for its cell. The page source record lists the capture date and snapshot for every cell.
Field definitions
- Application distribution
- Bundled stores, alternative-store support, direct-installation support, privileged integration, account-requirement statement, region, device scope, release or channel, and limitations stated by the current cell.
- Signup identifiers
- Identifier type, requiredness, collecting actor, plan, region, and platform stated by the current cell.
- Later verification
- Trigger, requested identifier, collecting actor, retained-by value, plan, and region stated by the current cell, preserving nested verified absences.
Telemetry defaults, retention, and deletion
A telemetry default, a retention statement, and a deletion mechanism answer different questions, so none of the three establishes the complete lifecycle of every device or account record.
The telemetry column reports the diagnostic, analytics, crash, usage, or related category; its documented default state; the controller or recipient; the configuration path; and the device, release, feature, application, or account scope carried by the current cell. A stated default is not extended to every regional build, device maker, installed application, network service, or later setting change.
The retention column separately preserves the data category, trigger, duration, exceptions, and controller represented by the cell. A duration attached to one category is not applied to every record associated with a device or account. A platform-level statement is not assigned to a separate project, store, application, or service unless the cited record makes that connection.
The deletion column reports the initiation path, completed-erasure statement, exceptions, timeframe, and controller. A reset, uninstall, account closure, local deletion, or feature change may address one layer without establishing completed erasure from another device, backup, log, service, project, store, or legal archive. The table preserves that boundary rather than joining separate mechanisms into one promise.
These columns describe source-bounded states, not observed network traffic or a completed-erasure test. A default setting does not prove what every endpoint transmits. A retention statement does not prove that no other actor holds a distinct record. A deletion mechanism does not prove that every related artifact is erased. Any nested typed unknown remains attached to the field and document where the gap was recorded.
| Jurisdiction | Telemetry defaults | Retention | Deletion |
|---|---|---|---|
| Android Open Source Project (AOSP)Stock Android documentation names the Android Open Source Project as the project through which Android documentation and source code are available.source | Stock Android support documentation says enabling Usage & diagnostics sends Google information such as battery level, app-use frequency, and network-connection quality and duration, and the setting can be turned off.source | Google says retention varies by data type, use, and settings: some data is user-deletable, some is automatically deleted or anonymized, some remains until account deletion, and some is kept longer for business or legal purposes.source | Google says users can delete content or individual items from specific services, delete specific Google products and their associated information, or delete an entire Google Account.source |
| Lockdown ModeFor iOS with Lockdown Mode, Apple says personal data relating to people in the European Economic Area, United Kingdom, and Switzerland is controlled by Apple Distribution International Limited in Ireland, while data collected worldwide by Apple or its affiliates is generally stored by Apple Inc. in the United States.source | For iOS with Lockdown Mode, Apple says analytics about removal recommendations are sent only if the user agrees to share them through the specified Analytics & Improvements settings on iPad, iPhone, or Mac.source | For iOS with Lockdown Mode, Apple says it retains personal data only as long as necessary for the purposes for which it was collected or as required by law, seeking the shortest period permitted by law when retention is required.source | For iOS with Lockdown Mode, Apple says exercising privacy rights requires account sign-in and identity verification, and some deletion requests may be denied, for example when Apple is legally obligated to keep a record of a transaction or when granting the request would undermine Apple's legitimate use of data for anti-fraud and security purposes.source |
| CalyxOSCalyxOS identifies the Calyx Institute End-User Terms of Service, which state that they apply to all Calyx services and websites.source | CalyxOS says the operating system or microG initiates connections for system updates, anti-tracking-filter updates, optional online location services, and GPS-assistance data.source | CalyxOS says release.calyxos.org per-request logs are retained briefly before aggregation and destruction, while long-term aggregate data contains request totals by country and device model.source | CalyxOS says personal information is kept on an encrypted basis while a person remains a Calyx member or registered user, then deleted promptly once retention is no longer required by policy or law.source |
| GrapheneOSGrapheneOS says the GrapheneOS Foundation was created as a Canadian nonprofit in March 2023 to receive and distribute donations.source | GrapheneOS says it has no analytics or telemetry and makes default remote connections only to GrapheneOS services and network-provided DNS resolvers.source | GrapheneOS says its public-service servers retain logs for at most 10 days, with a lower limit or no persistent logs for some services.source | GrapheneOS says deleting a profile wipes its corresponding Weaver slot, while a factory reset wipes all Weaver slots.source |
Source: 4 products. Each source link opens the authority for its cell. The page source record lists the capture date and snapshot for every cell.
Field definitions
- Telemetry defaults
- Telemetry or diagnostics category, documented default, controller or recipient, configuration path, and device, release, feature, application, or account scope stated by the current cell.
- Retention
- Data category, trigger, duration, exceptions, and controller stated by the current cell.
- Deletion
- Initiation path, completed-erasure statement, exceptions, timeframe, and controller stated by the current cell.
Operating responsibility, public source, audits, and requests
Project identity, source availability, audit disclosure, and lawful-request reporting are four distinct evidence categories, and none is an overall trust or security badge.
The operating-responsibility column names the company, project, platform owner, publisher, or controller supported by the current cell and keeps each jurisdictional statement at its documented scope. A project name is not silently converted into a corporation. Incorporation, governing law, hosting, controller location, software origin, and device availability remain different facts, and a statement about one does not fill an unknown in another.
Source availability reports the repository URL, license, component, version, and release locator represented by the cell. A public repository for one component does not establish that every service, store, application, build system, privileged integration, policy layer, or infrastructure component is public. A nested unknown about one requested source field is not converted into a product-wide closed-source conclusion.
The audit column reports the assessment date, assessor, scope, access, and report locator supported by the stored records. Two whole audit cells—iOS with Lockdown Mode and Stock Android—are verified absences at cell-row grain; CalyxOS and GrapheneOS print supported audit values. Those markers describe the declared documents read; they do not establish that no assessment, review, or nonpublic report exists.
Request reporting records the period, jurisdiction, unit, scope, count, and absence reason supplied by the exact cell. Requests, orders, accounts, devices, users, identifiers, disclosures, and challenged matters are not assumed to be interchangeable units. An absence reason is not a count, and a verified absence is not printed as zero. The four columns remain evidence categories rather than inputs to a score or recommendation.
| Jurisdiction | Operating responsibility | Source availability | Audit record | Request reporting |
|---|---|---|---|---|
| Android Open Source Project (AOSP)Stock Android documentation names the Android Open Source Project as the project through which Android documentation and source code are available.source | Stock Android documentation names the Android Open Source Project as the project through which Android documentation and source code are available.source | Android documentation says the Android source and its full change history are hosted by Google across a collection of Git repositories.source | Unknown Verified absenceNot disclosed in the captured primary source.source | Google says it receives government and court requests for user data worldwide, reviews every request, and frequently pushes back when a request appears overly broad or does not follow the correct process.source |
| Lockdown ModeFor iOS with Lockdown Mode, Apple says personal data relating to people in the European Economic Area, United Kingdom, and Switzerland is controlled by Apple Distribution International Limited in Ireland, while data collected worldwide by Apple or its affiliates is generally stored by Apple Inc. in the United States.source | For iOS with Lockdown Mode, Apple says personal data relating to people in the European Economic Area, United Kingdom, and Switzerland is controlled by Apple Distribution International Limited in Ireland, while data collected worldwide by Apple or its affiliates is generally stored by Apple Inc. in the United States.source | For iOS with Lockdown Mode, Apple says source code for its operating systems and developer tools is available through downloadable releases and Git repositories.source | Unknown Verified absenceNot disclosed in the captured primary source.source | For iOS with Lockdown Mode, Apple says its transparency report provides information on government requests for customer data received globally.source |
| CalyxOSCalyxOS identifies the Calyx Institute End-User Terms of Service, which state that they apply to all Calyx services and websites.source | CalyxOS identifies the Calyx Institute End-User Terms of Service, which state that they apply to all Calyx services and websites.source | CalyxOS says its development occurs in public source-code repositories, with source available on GitLab and mirrored to GitHub.source | CalyxOS identifies a security assessment titled Calyx Institute HSM Provisioning Ceremony Scripts Security Assessment, dated January 23, 2026.source | CalyxOS says it shares available personal information with law enforcement or government agencies with the user's written consent, under apparently valid legal process, or when applicable law requires disclosure.source |
| GrapheneOSGrapheneOS says the GrapheneOS Foundation was created as a Canadian nonprofit in March 2023 to receive and distribute donations.source | GrapheneOS says the GrapheneOS Foundation was created as a Canadian nonprofit in March 2023 to receive and distribute donations.source | GrapheneOS says it is an open-source project with an open development process and many source repositories.source | GrapheneOS says its code is continuously reviewed by external security researchers, companies, and organizations, with most review and audit results visible through public pull requests and issue trackers.source | GrapheneOS says it is not able to comply with a government order to build, sign, and ship a malicious update to a specific device based on information such as an IMEI or serial number, and it rejects updates constrained to a serial number.source |
Source: 4 products. Each source link opens the authority for its cell. The page source record lists the capture date and snapshot for every cell.
Field definitions
- Source availability
- Repository URL, license, component, version, and release locator stated by the current cell.
- Audit record
- Assessment date, assessor, scope, access, and report locator, preserving row-level and nested verified absences.
- Request reporting
- Period, jurisdiction, unit, scope, count, and absence reason, preserving typed unknowns rather than printing zero.
Limits, capture dates, and corrections
This matrix records what cited sources stated at each cell's capture date; it does not establish universal platform behavior, comparative effectiveness, or future support.
Every displayed value is transcluded from a current persisted cell with its product, plan, region, platform, claim type, source class, source URL, capture date, observation version, applicability, and typed unknowns. The page date follows the newest printed cell, but each individual statement keeps its own source and capture boundary. A later product or policy change can therefore require a cell update without changing unrelated rows.
The mixed roster remains a material limit. Two full operating-system paths, an optional protection mode, and a platform baseline can answer the same fourteen questions only when device, release, channel, feature, platform, and application scope stay attached. A not-applicable value is authorized only by its exact cell. It is not inferred from the roster label or copied from another path.
Documented device support does not guarantee equal controls on every phone. A sandbox does not prove that no permitted data flow exists. Verified boot does not describe every runtime behavior. An update path does not predict future cadence. An application-distribution option does not decide identity collection for every store or service. A telemetry default, retention statement, or deletion mechanism does not establish the complete lifecycle of every record.
The privacy-tool comparison methodology provides one email-based correction procedure for every vendor and page, plus a log for request date, affected claim, status, resolution date, and change note. The roster and ordering remain neutral. The page carries no score, rank, preferred provider, affiliate parameter, sponsorship, gift, preferred access, paid placement, most-secure claim, most-private claim, or universal recommendation.
How to read Unknown
- Unknown: Verified absence
- The captured authority was searched and shows no such rule or filing. No value is printed because the absence is the finding. The reason and the authority are printed beside the badge.
- Unknown: Not yet verified
- The captured sources did not settle this field yet. No value is printed, not even an earlier one. The reason is printed beside the badge, and an authority is linked only when one was supplied.
Frequently asked questions
What does a mobile operating-system privacy comparison measure?
This matrix measures fourteen documented attributes for four preregistered paths, including device and update scope, isolation and boot mechanisms, application distribution, identity requirements, telemetry, lifecycle statements, and four evidence categories. It reports cell-bounded claims rather than independently tested effectiveness.
Does device support guarantee the same controls on every phone?
No. A device-support cell applies only to the families, models, hardware requirements, releases, features, regions, and exceptions that its source establishes. It does not prove identical behavior on every device or later release.
Are sandboxing and verified boot the same protection?
No. Sandboxing describes a documented runtime isolation boundary, while verified boot describes a documented startup or software-state check. Neither mechanism supplies the other's missing scope or establishes complete device protection.
What does a verified absence mean in this matrix?
A verified absence means the declared source document did not disclose the specified cell or nested field under the recorded method. It does not mean zero, no, unsupported, insecure, closed-source, nonexistent, or a negative product verdict.