VW has confirmed to me that they are deliberately excluding GrapheneOS users.
Thank you for your detailed feedback and the technical information regarding your device and GrapheneOS.
We would like to inform you that so-called custom ROMs — including alternative operating systems such as GrapheneOS — are currently not officially supported by Volkswagen. This applies in particular to security-related verification mechanisms such as Play Protect and Play Integrity, which are required for the login process of the Volkswagen app.
As these systems are not part of the certified Android ecosystem, restrictions may occur when using our app. A technical adjustment or activation for non-certified operating systems is currently not planned.
If you use a device with an officially supported, Play Protect-certified operating system, the login should work as usual.
Should you have any further questions, we will of course be happy to assist you at any time.
For further questions regarding our digital services, please reply directly to this email. Further contact options can be found at https://contact.volkswagen.com. When calling us, please quote your case number 0004571496 so that we can assist you as quickly as possible.
We wish you safe and pleasant journeys at all times with your Volkswagen Tayron.
Kind regards,
Your Volkswagen Team
And my reply which mentions the violation of key EU principles
Dear Sir or Madam,
Thank you for your response.
I note that Volkswagen currently deliberately does not support GrapheneOS and makes login to the Volkswagen app dependent on Play Protect or Play Integrity. As a result, access to connected vehicle services is effectively restricted to Google-certified Android systems or Apple iOS.
I consider this decision to be technically unconvincing and problematic from a consumer perspective. GrapheneOS is not a rooted, manipulated, or insecurely modified Android system. It is a security-focused Android operating system based on the Android Open Source Project. My Google Pixel 10 Pro XL is not rooted, the bootloader is locked, and Verified Boot is active.
The absence of Play Protect certification therefore does not mean that the device is insecure. It merely means that GrapheneOS is not part of the traditional Google-certified Android ecosystem.
In my view, the deliberate exclusion of secure AOSP-based Android systems violates key EU principles, in particular consumer freedom of choice, interoperability, transparency, proportionality, and fair access to connected services for connected products. It is particularly problematic that a fully updated and security-focused system is excluded, while access apparently remains possible via older but Google-certified Android systems.
For an appropriate technical solution, I once again refer to the GrapheneOS Attestation Compatibility Guide:
https://grapheneos.org/articles/attestation-compatibility-guide
This guide describes how app providers can verify secure GrapheneOS devices using standardised Android Hardware Attestation and the official GrapheneOS Verified Boot keys. This would allow Volkswagen to assess the actual integrity of the device rather than relying exclusively on formal Google certification.
I therefore request a final written statement on the following points:
- Does Volkswagen confirm that GrapheneOS is deliberately excluded from login to the Volkswagen app?
- Does Volkswagen confirm that access to connected vehicle services effectively requires a Google-certified Android system or Apple iOS?
- Which device integrity, Play Protect, or Play Integrity data are processed during login?
- What is the legal basis for this processing and the resulting access restriction?
- Will Volkswagen review support for secure GrapheneOS devices via Android Hardware Attestation?
Should Volkswagen maintain this practice, I will submit the matter to the competent authorities responsible for consumer protection, data protection, access to connected services, competition, and interoperability for review.
Thank you for your final written statement.