I am about a week in to using Graphene on a Pixel 6 Pro. I was hoping someone could anwser a permission/sandbox question.

I have installed gcam and all 3 framework, service and store packages. I configured storage scopes for gcam restricting it to a media folder, and manually removed every permission except for camera and microphone while using. I manually removed every single permission for g services, framework and store. My question is, I routinely see people suggesting a seperate profile for those things but what data could they still collect, and if they did collect it how would it be transmitted with revoked network access and background data turned off? Am I missing something? All I can think of is when I use Aurora store to update. If thats the case I will use a seperate profile but I'd prefer to keep this setup. Thanks!

    Standardwaste GCam doesn't need all the sandboxed Play Services packages it just needs Google Services Framework (GSF) with all permissions revoked. If you don't need the other two keep it lite.

    If you don't have any Play Services dependent apps then you don't need the other two. Yet no matter what you see other people doing or recommending based on their experience GrapheneOS is for Everyone and you can use it as you wish. However you use it you still get all the benefits of GrapheneOS security enhancements and hardening.

      MetropleX that will be my setup from now on. Good to know my banking app only requires GSF as well. Thanks again