Wherever in the world you go, the smartphone landscape is dominated by Android and iOS, and while this has always been problematic, recent events have made the dependency on two American tech giants for what is probably our most personal computing device even more problematic than it already was. We use our smartphones to keep our secrets, do our banking, interact with our governments, share our deepest thoughts with our friends and family, and a whole lot more. Having this invaluable tool the vast majority of us depend on tied entirely to Google and Apple is not just bad for the market, it’s also a downright threat to the national security of anyone not living in the US.
Here in Europe, there’s been an awakening lately, with governments, companies, and people alike finally realising that having our entire digital infrastructure controlled by foreign, adversarial interests is a terrible idea. Sadly, breaking free from our Android and iOS chains is not so easy. The most ideal solution would be a truly open source alternative smartphone operating system, but that’s a hard sell for 99.9% of smartphone users who need the applications required to do their finances, talk to their friends, or interact with their governments. The cold and harsh truth is that with very few exceptions, these applications simply do not (yet) exist for smartphone operating systems that aren’t Android or iOS.
The only viable alternative at this point in time is to take whatever’s left of the Android Open Source Project, remove anything that ties it to Google and its services, fill in the gaps with alternative services and applications, and sell it as a Google-free or de-Googled Android platform. There’s several projects in this space, and with Europe drunkenly stumbling out of the technological hole it dug itself into, it’s no surprise that two of the more popular alternatives to Apple or Google-controlled smartphones come from Europe (and from the same country, no less). Today, we’re taking a look at one of these: iodéOS.
Iodé is a company based in Toulouse, France, which focuses on offering a Google-free Android called iodéOS, either preinstalled on phones you can buy, or as a ROM you can install yourself on supported devices. As a company, iodé makes its money through selling devices with iodéOS preinstalled, through an optional premium subscription (that I didn’t take a look at), and through donations, and all of their code is published as open source on their Gitlab instance hosted in France.
Iodé loaned me a Fairphone 6 with iodéOS preinstalled, one of he many smartphones and tablets they sell through their online store for review. This isn’t going to be an Android review; you already know what Android is like, and there’s no need for me to rehash any of that. Instead, I want to focus on the things that make using de-Googled Android different from using Google Android.
Don’t be afraid of microG
There are various ways to go about making a de-Googled Android variant, and iodéOS chose the LineageOS route, with microG installed on top. For those unaware, microG is a project which aims to replace the various proprietary parts of Google Play Services, required by many Android applications, with open source reimplementations. While it doesn’t offer 100% compatibility, it works exceptionally well, and you’ll be hard-pressed to find applications just don’t work at all with microG. IodéOS updates its microG installation through a dedicated F-Droid repository that’s obviously enabled by default, so you don’t have to do anything yourself.
Using microG instead of Google Play Services doesn’t mean you have to rely solely on whatever’s available in F-Droid, since there are a variety of alternative Play Store frontends available. IodéOS ships with the Aurora Store, which is an open-source frontend to the Play Store that can be used with or without a Google account. If you use it with your Google account, you’ll gain access to whatever applications you already own, including paid ones, but you won’t be able to buy applications inside Aurora. You can, however, buy an application on the Play Store website, after which it will show up in Aurora as well, assuming you’re logged in with the same account.
Aurora also comes with something something called FakeStore, which is sadly an important part of the puzzle; it’s a stub application that has the same package name as the real Play Store. Some applications check whether the Play Store is available before working properly, so this is sadly needed to ensure maximum compatibility. The only issue I sometimes ran into with Aurora is that it would load up its listings, but then any application I tapped on said it was unavailable. When this happened, reloading the Aurora application always fixed the issue. Annoying, but not gamebreaking.
A few things did not work for me when using microG on iodéOS, and they’re exactly the things you’d expect not to work. If you have a WearOS device, you’re out of luck; WearOS devices simply do not work when using microG, but there is a bounty to add support for it. If you want to use a smartwatch with iodéOS, there are various options available, such as Garmin devices, which is what I used during my testing and it worked flawlessly.
Another feature from “regular” Android that simply won’t work is RCS. There’s only one RCS client available on Android, Google Messages, and as you can imagine, Google is in no rush to allow devices without Google Play Services to register for and use RCS messaging. Tying to register with Google Messages will fail, and there are no other RCS clients available (save for a few China and India-specific clients). There’s a microG bounty for this, too, but no luck so far. Of course, there are countless messaging platforms that work just fine on iodéOS – regular SMS, WhatsApp, Facebook Messenger, Signal, and so on – and especially if you’re European, it’s unlikely RCS support matters to you at all.
I just don’t ever think or care about RCS.
The big question mark hanging over everyone’s head when they consider moving to a de-Googled Android ROM without Google Play Services is, of course, banking applications. Personally, I’m lucky in that my bank’s application works just fine without Google Play Services, and the same applies to the various related applications and services here in Sweden, such as the BankID verification application (used to verify your identity for banking, government logins, etc.) and Swish, a popular Swedish payment platform.
While I think the problem of broken banking applications is a little bit overblown, it’s still a real issue and you should do some research before making the jump. Even if your specific bank’s application is listed as broken, though, you can usually still access the same functionality through your bank’s website, even if that’s probably a little less smooth and more cumbersome. Look, nobody said ditching Google wouldn’t come with difficulties and annoyances.
While my banking situation was fine on iodéOS, the same can’t be said for NFC payments. I use Google Wallet to pay with my phone and smartwatch at stores, and it won’t come as a surprise that Google doesn’t make its Wallet application work without its Play Services installed. If you’re in the same boat, you may be able to circumvent this problem through your bank’s application, as some banks offer NFC payment functionality of their own. If not, you’re out of luck – unless you happen to have a Garmin watch with Garmin Pay, which works without Play Services or even a smartphone at all, like I wrote about extensively a year ago.
The worry about losing access to banking applications and NFC payments is probably the biggest worry people have when considering switching to a de-Googled Android ROM like iodéOS, and while that worry is valid, I do think most people will be surprised by just how many banking applications work just fine even without Google Play Services. Before making the jump, some online searching will yield several maintained lists of working and broken applications so you know what you’re in for.
That being said, this is not an ideal situation, and one that most likely needs remedying in a regulatory manner. Access to basic and often mandatory services like banking, online government ID systems, messaging, and more should not be predicated on buying a locked-down, user-hostile American device.
Relying on the community
Usually, custom Android ROMs, de-Googled or not, ship with some Chromium browser by default, but iodéOS does things a bit differently by opting for a branded Firefox fork instead that has telemetry, trackers, and so on disabled. For its other Google application replacements, iodéOS relies on various proven open source applications, like CoMaps, Thunderbird, Fossify applications, and more. The end result is a complete offering where everything you’d find on a Google Android phone has been replaced by solid, capable, non-Google offerings from the open source community.
Of course, this is Android, so you can install whatever other maps, mail, or application you want if iodé’s choices aren’t to your liking.
An important feature of iodéOS is that it ships with an operating system-wide analysis tool that provides insight into with to what and whom, exactly, your phone and its applications are connecting. A system-wide adblocker is part of this, as well, with sensible defaults sourced from various open source blocklists. Of course, you have full control over what is and is not blocked, including the ability to block entire applications or websites if you so desire. While I personally didn’t try out their optional Premium subscription service, this service provides even more control, such as various parental control features.
IodéOS also has some nice, smaller touches that I really appreciated. During the first boot and initial setup, it showed a screen where you could select which default applications to remove, something I’ve never seen before. Sadly, many of the supposedly removable applications ended up only being “hidden”, which is Android speak for system applications that can’t be removed. I’m not sure what the exact reasoning is to make some applications system applications, but I would definitely prefer if all of the preinstalled applications, or at least most of them, were actually removable. This would seem to more closely align with iodéOS’ stated goals and values.
The default installation also comes with what is essentially a really barebones, basic changelog application. It shows nothing more than a list of recent updates with includes fixes changes, and additions, and it’s really nice to have this information easily accessible. I’m quite tired of the modern trend of empty or entirely missing changelogs, so it’s nice to see iodé putting this front and centre. The application itself could use some touching-up, but at the same time, I understand why this is probably not high on the list of priorities. It shows a changelog; it doesn’t need to win design awards.
Speaking of updates – during my use, iodéOS was never more than one month behind on Android’s security updates, which is not a bad showing compared to many much larger big-time Android OEMs. Still, I would prefer the monthly Android security updates to be available within the same month, so this is an area where iodéOS can improve and put themselves even farther ahead of most OEMs. People who are most likely to switch to a de-Googled Android are probably also going to be people who care about being up-to-date and as secure as possible.
Boring is good
Beyond the well-documented problems with WearOS, RCS, and some banking applications that are outside of iodé’s control, using iodéOS is simply boring and uneventful, and in this case, “boring” is exactly what they should be aiming for. For the vast majority of people, switching from Google Android to iodéOS will not be a particularly jarring experience, as all their favourite applications will still be available, running on the same underlying operating system they’re already used to. IodéOS does an excellent job of being inoffensive, unobtrusive, and frictionless – exactly what you want from something that aims to be a drop-in replacement for Google Android for as many people as possible.
IodéOS offers a solid Android experience to those who want to de-Google, and assuming you’re not deeply dependent on WearOS and/or RCS, it’s easy to recommend. It’s really “just Android”, and if you’re already used to Android – and statistically speaking, you are – buying a phone with iodéOS preinstalled is no different than buying any other Android device, just without all the Google baggage.
And as we realise a little bit more every day, that’s a massive value-add over Pixels and Samsung phones.

This is a great journey, but the way ahead is still too long.
A few months ago, I lost access to my alumni account, along with that my email, and many online logins. The reason? Their 2FA application flagged my pre-release OS as “rooted”.
It was not rooted, even though I don’t see any reason why I can’t do that on a rooted phone either. I mean, if I use the 2FA on that device, I am personally taking that risk myself (there is no risk of course).
But alas no, the university will not use SMS fallback, nor allow actual open 2FA variants, they won’t even support the new “passkeys” (which I have with BitWarden)
Anyway, it was really frustrating, and I had to call tech support for them to manually move the 2FA to my tablet (no desktop or laptop option was there).
Good times!
sukru,
I’ve had the exact same experience…. I’m glad some people are fortunate enough not to have had this experience because it really sucks!
Alfman,
Yes, the stress was bad. I had to cancel an online order, and could not access my account nor my email. These things seem trivial, but they might cause actual financial loss.
I’m always a little surprised to hear how many people rely on bank apps and NFC payment. I get online banking, but I only ever do that on a computer through the web page, or in person.
For NFC, you can just use a card directly can’t you? I feel like keeping a wallet of a few cards and IDs and stuff (at least in the US where we are still using physical IDs? Is that just not an option at all in Sweden?) isn’t the worst thing to avoid google.
FlyingJester,
Unfortunately banks started relying on mobile apps for authentication.
“You seem to be using a new device, we will send you a verification code… in the banking app”
This happened in at least 3 banks I use. Not sure whether I can fully uninstall and deregister them, but keeping those from fear of losing my account access.
This of course makes no sense at all.
Not only banks but also any VPN solution now needs its own proprietary 2FA app. On top of that, they change every 2 years of so — and I have now 10 different apps for the same problem.
Is this not simply due to the fact that such apps use the Play Integrity API to ensure they’re running on a non-hacked platform?
I read reports about people buying phones from dodgy suppliers that (according to the press) are hacked at the OS level. Defence agains that, I guess, because those phones will never run a banking app (potentially exposing all your secrets).
DannyBackx,
It is a mix of being over cautious and a bit lazy that gives less than stellar experience on unpopular platforms.
(The same with anti-cheat making 50% of my games not playable on the Steam machines)
They are in the very common “untrusted client execution” state. The bank needs a 2FA, or maybe a whole transaction. But they cannot be 100% certain you are on the other side of the connection, but not a bot, or a scammer.
The solution is of course don’t trust and verify. But it is much easier to use the platform APIs (or an invasive third party like SecuROM).
In Nigeria, the largest denomination is 1000 NGN — less than 1 USD. You won’t make it far w/ cash. POS/card is often not working because of the network. So in fact a combination of mobile banking apps will safe your day.
In Thailand, Promptpay(QR) is so comfortable that it killed any other payment method. You can pay your fried rice at a food stall in the rural village, even when the shop owner is a 80 y/o grandma. No POS/card available anymore because simply nobody wants it.
Andreas Reichel,
Cards are a necessary evil here in the USA due to “know your customer” laws. The lovely set of lifestyle upgrades we received with the patriot bills back in the day.
Even crypto is highly regulated, and with two birds with a stone approach, they also report all transactions to IRS. Not that condone tax evasion, but it makes it very difficult to use it for actual transactions.
“Ah, you bought $400 worth of RAM from newegg with bitcoin investments, please file long term capital gains taxes”
“Can’t I just reconcile everything at the end of the year?”
“No, you have to give detailed accounting of every transaction, every partial coin, every deposit and withdrawal”
And it is pretty easy to see why it is quite impossible to use crypto “currency” as currency in the USA.
(For reference, they don’t do the same, for example when you visit Europe and spend EUROs during the visit. You don’t report every pizza you ate, every tip you left. You get one large reconciliation)
Physical IDs are still very much a thing in Sweden but wallets seem to be a thing of the past. I see younger folks having their cards in fold up mobile cases or even in between the phone and the protective shell. I’m a grumpy 52-year old and there is no talking sense into me 🙂 I refuse to give up my wallet, where would I keep my cash?
You have Swish in Sweden, which is very frustrating as tourists can’t use it.
Thom, thank you much for this article!
Thom Holwerda,
Ditto Andreas Reichel’s thank you…this review is very informative.
I’d like to emphasize that the duopoly harms the whole world including the US. We’re all in desperate need of alternatives, especially as google tightens the noose around 3rd party software.. I’m looking at getting new hardware in the near term and I’d really like something like iodeOS to be available here. I wish I could buy something that already supports FOSS & user rights out of the box. I’m looking at graphene OS, but it’s far from ideal to pay for something like a google pixel to flash myself when the purchase promotes the duopoly and proprietary software.
While my other comment with a link is awaiting moderation, I put this: Graphene OS is the only viable alternative that supports timely updates and sensible security. If you don’t want to use Pixel, your only option is to wait until next year’s Motorola phone. Graphene OS does not use insecure devices, and that’s why it receives bullying from governments.
That’s why my last two phones were Pixels bought second hand on Swappa. I wanted the security of Graphene OS without giving Google any money myself, and I don’t want to spend $1k or more on a device that will be unsupported (by Google or GOS) in a couple of years.
As for the Motorola phone, I’m not holding my breath that it will be a good device. For some reason Motorola can’t help but screw up every single phone they’ve released in the past decade. They always suffer from poor performance and glitchy hardware, and until this year they’ve had a bad track record regarding timely security updates. I’m honestly surprised the GrapheneOS team is willing to turn to that company for a trusted, secure device given Motorola’s total lack of security awareness and quality control in the past.
Morgan,
I won’t be able to wait that long anyway. But yeah I’m sure GrapheneOS team know all these and maybe even sympathize. Realistically, given how unfriendly manufacturers are to community FOSS projects like this in general, they’re probably lucky to have any partners. Even though the experience might not be perfect, I’d still place value on official support because in truth I am getting wary of flashing alternative OS on an unsupported phones. Obviously this is the fault of manufacturers who aren’t catering to us.
A Motorola and GrapheneOS partnership improves the status quo and I am hopeful these manufacturing-FOSS partnerships prove to be fruitful.
Consider Fairphone perhaps. But hard to find in the USA.
Kochise,
I did consider them in the past and ruled them out after seeing a large number of complaints activating them on US plans. Take a fairphone IMEI number such as this one and plug it into ATT’s BYO device onboarding tool.
https://www.imei.info/?imei=355214500286412
att.com/buy/byod/identify?devicetype=phone
ATT is lying through their teeth here. They’re not actually checking for a device’s compatibility. Instead they are checking the IMEI against their partner whitelist. Because of the limitations of their blocking infrastructure you can actually activate a SIM with an approved phone and transfer that same SIM to an unapproved phone. The “not compatible” phone does work on ATT’s service for a few hours until ATT’s systems eventually flag it and degrade service on their end!
Previously the FCC prohibited US carriers from discriminating against customers using the phone of their choosing. However under Ajit Pai’s traitorous leadership so many consumer protections were aggressively overturned and so we’re back to US carriers being allowed to dictate what hardware customers are allowed to use. 🙁
https://www.howardforums.com/threads/are-there-any-workarounds-or-solutions-to-the-att-whitelist-block-for-byod.1928380/
I hear that Fairphone works best on T-moble, since they’re not being dicks about blocking phones like ATT. Alas we left Tmobile because their rural coverage was inferior and we had too many dead spots through them. IMEI reprogramming hacks could work because ATT would get it’s whitelisted number, but ugh… it’s so annoying that corporations are assholes and take away our liberties to begin with.
Security updates for Motorola phones are a bit lackluster, yes, but I’ve had Motorola’s for over a decade, and they perform fine and have no glitches.
Unfortunately, any “de-Googled Android” will need to guarantee 100% compatibility with all banking apps (world wide!) and Google Authenticator and Microsoft Authenticator.
Banks are requiring you use the mobile phone app to login and/or approve payments. Banking apps must work, its a non-negotiable.
If the operating system doesn’t support those critical apps then it isn’t “frictionless”.
Just scanned through the article and wanted to know your opinion of how it compared with /e/OS (hope I got the name correct!), marketed by Murena? I suspect that /e/OS is the better known and more developed solution. The question is why somebody should consider iodeOS instead?
The first problem for all these (GraphenOS, /e/OS, iodeOS, postmarketOS: limited device support. You almost have to buy a second-hand phone to get one of these working on a phone. Ok, Murena is an exception, as they sell preinstalled devices.
But then comes the main problem: do the apps you need (like the banking 2FA app, your 2FA app of choice, and the other ones you need) work on this OS? You won’t know until you have tried it.
And if only one of the needed apps don’t work your investment in some better mobile OS / ecosystem is wasted money.
Murena has “app lounge” that uses the google software repository – sorry, “app store” – and was able to install the sadly almost mandatory Whats app as well as HSBC banking app. Unfortunately I very soon damaged the phone with water ingress and scuttled back to the iphone for now. But when that starts to die the migration already started can be completed and will spring for a better device with Murena.
I don’t know if it’s a solution for some of the problems (and I haven’t tried) but there are at least two virtual machine managers in Android VMOS and Virtual Master) so perhaps one can install a ROM with Google Play services to run the problematic applications and only turn them on when needed.
>Here in Europe, there’s been an awakening lately, with governments, companies, and people alike finally realising that having our entire digital infrastructure controlled by foreign, adversarial interests is a terrible idea.
Meanwhile: https://www.osnews.com/story/145405/european-digital-id-wallets-are-a-gift-to-google-and-apple/