• General
  • App installation and compartementalization models for a privacy-minded use case

Hi,
I've recently committed to using GrapheneOS and am in the process of studying its usage guide, FAQ, and browsing this discussion forum to this end. I've noticed that questions regarding how many profiles to create and how to use them are plentiful (I've seen this thread, this one, this one, this one and that one); I'll keep my question focused: how should I square the two following assertions found in the Sandboxed Google Play section of the usage guide?

  • I you want to choose which apps use Google Play [...] it makes more sense to try to use as much as possible without Google Play rather than treating not using it as the exceptional case.
  • The Play Store app is also the most secure way to install and update apps from the Play Store.

Does the latter point not plead in favor of making the Play Store, hence all of the GSF bits, available to all profiles instead of relying on some third party store like Aurora, or an alternate installation and update mechanism, for one or more non-GSF profiles? I've taken to sideloading APKs and keeping them updated with de.apkgrabber in such profiles for the moment, but I'm wondering how misguided I might be in doing so given this latter point in the usage guide.