the phone is the best surveillance device ever carried voluntarily: a bundle of persistent identifiers, always-on sensors, and dozens of apps phoning home, riding a cellular network that must know where you are in order to ring you. total escape is not on the menu. large, cheap improvements are, and one genuine upgrade if you want it.
audit permissions. location to "while using" or denied, contacts, microphone and camera only where the app's actual job requires them. be ruthless. a flashlight does not need your address book, a game does not need your location.
delete unused apps. every installed app is a small data collector with a network connection and background access. the site version in a browser often works fine and sees far less.
kill the advertising id. the cross-app tracking key data brokers use to stitch your activity together. ios: settings, privacy and security, tracking, turn off "allow apps to request to track", and under apple advertising turn off personalized ads. android: settings, privacy, ads, delete advertising id.
randomize your radios. use randomized wi-fi mac addresses (on by default on modern ios and android) so networks cannot track your device across locations by its hardware address.
keep it updated. most phone compromises exploit known, already-patched bugs. a current os is itself a privacy measure.
apple limits everyone's tracking except apple's, and asks you to trust apple completely. a reasonable default for the first profile in threat model. two settings most people miss are worth turning on. advanced data protection extends end-to-end encryption to most icloud categories (backups, photos, notes), so apple itself can no longer read them, at the cost of you owning recovery. lockdown mode hardens the phone aggressively for people at risk of targeted, mercenary spyware, disabling the risky attack surface that such exploits abuse. neither is on by default.
stock android is, by default, a google terminal with a phone attached, reporting to google as the platform owner. you can reduce this, but the base assumption is google-in-the-middle. fine for ordinary ad-and-profiling concerns, the wrong base for the third profile.
android rebuilt without google as the default, on pixel hardware only (chosen for strong hardware security, verified boot, memory tagging on newer models, and long update support). what you actually get:
it is a daily driver, not a hair shirt. avoid resellers shipping "degoogled" phones flashed with who-knows-what. install it yourself from the official web installer, which takes about fifteen minutes and lets you verify what you are running.
the app store is itself a tracking relationship. prefer f-droid for open-source apps, and aurora store to install from the play catalog anonymously, without a google account attached to your identity. fewer accounts, fewer profiles, less linkage.
the cellular network locates your baseband whenever the radio is on. your sim broadcasts identifiers (the imsi), the carrier logs which towers you are near, your imei ties the hardware to you, and cell-site simulators (stingrays) can force nearby phones to reveal themselves. this is physics plus billing, not a software bug, and it applies to grapheneos too. for the rare occasions where that matters, the only answers are airplane mode, a faraday bag, or leaving the phone at home. knowing this limit is part of the setup, not a reason to despair.

.:: eof ::.