Black Glove
Questions

Questions people ask

Everything below is also on the home page. It is here on its own because some of it is worth reading before you look at prices.

What is GrapheneOS, and why not just use a regular phone?

GrapheneOS is an Android built from the same open source base as the one on your current phone, with the tracking removed and the security rebuilt. A stock Android device reports to Google continuously: location, the apps you open, the networks you join, an advertising identifier that follows you between apps. GrapheneOS ships without any of that, hardens the parts of Android that attacks usually target, and lets you decide app by app what gets network access, sensors or storage. The result is a phone that works like a phone but is not, by default, a surveillance device.

Why Pixel devices specifically?

Because they are the only widely available phones that let you install a different operating system and then lock the bootloader again afterwards. That last step is what matters: a relocked bootloader with verified boot means the phone checks its own system on every start and refuses to boot if anything has been tampered with. Almost every other manufacturer either blocks alternative systems entirely or leaves the bootloader permanently unlocked, which removes the protection you installed the system for. Pixels also receive long hardware security support windows and ship with a dedicated security chip that GrapheneOS makes full use of.

What is Molly, and how is it different from Signal?

Molly is a fork of Signal, built by an independent group from Signal's own published source code. It speaks the same protocol and connects to the same network, so you message ordinary Signal users normally and they see no difference. What it adds is protection on the device itself: Molly encrypts its message database at rest and can lock it behind a passphrase, so your conversation history is unreadable while the phone is sitting locked rather than merely hidden behind the screen lock. It also strips out components that depend on Google services. If you have used Signal, you already know how to use Molly.

Do I need technical knowledge to use this?

No. The reason we configure these devices rather than sell instructions is that the setup is the hard part, and we have already done it. When you receive the phone the operating system is installed, the VPN is connected, the data plan is active, messaging is set up and the second profile exists. You use it the way you use any phone. We walk you through it in person when we hand it over, you get a printed guide, and you can reach us with questions for the length of your service period.

What happens when my service period ends?

The phone remains yours and keeps working. GrapheneOS continues to receive updates directly from the project at no cost, and the device is not tied to us in any way. What ends is the prepaid VPN subscription and the data on the eSIM. You can extend either through us, or top them up yourself directly with the providers, or move the phone to any ordinary carrier SIM. Nothing stops working when you stop paying us, which is deliberate.

Can I use my existing phone number?

Yes. The device ships with a data-only eSIM, and there is a second physical SIM slot, so you can put your current SIM in alongside it and keep your number. You can also register Signal or Molly with your existing number without keeping that SIM in the phone. If you would rather have a separate number that is not connected to your name, the eSIM with voice and SMS add-on covers it. Which of these makes sense depends on what you are trying to protect yourself from, and we will talk it through with you before you decide.

Why do you only sell in person?

Three reasons. A shipped device passes through hands we cannot account for, and the whole point of verified boot is knowing the phone has not been interfered with between our bench and yours. Shipping also requires a name and an address, which is a permanent record of who bought a privacy phone and where they live. And the handover is where the value is: twenty minutes with the device in your hands, showing you the duress PIN and the profile switch, is worth more than any manual we could write.

Do you keep records of customers?

No customer database, no email list, no order history tied to a name. We keep what we need to run the business: what a device cost us, what it sold for, and when a VPN subscription or data plan comes up for renewal. None of that is linked to your identity, because we never collect it. This website has no analytics, no tracking scripts, no cookies and no contact form, and it loads nothing from any third party. If we cannot tell you what we hold about you, it is because there is nothing to tell.

What happens if I lose the device?

Whoever finds it gets an encrypted brick. The storage is encrypted, the bootloader is locked, and without your PIN there is no way in and no way to flash something else onto it. Message us and we will disable what can be disabled remotely, such as the eSIM data plan, so it cannot be used up. What we cannot do is unlock or recover the device for you, because we do not hold your keys. That is the same property that keeps your data safe from everyone else. Back up anything you cannot lose, and we will show you how at handover.

Who is this actually for?

Journalists and researchers who need a phone that does not log their sources. People leaving abusive relationships, where a shared account or a family plan is a live safety problem. People who travel constantly and would rather not hand their identity to a new carrier in every country. Lawyers, doctors and anyone else holding other people's confidences on a device. And a fair number of people with nothing in particular to hide who have simply decided they are done being tracked by default. You do not need a threat to justify wanting privacy.

Still unsure

Ask us the one that is not on this list

We would rather spend twenty minutes talking you out of a purchase you do not need than sell you the wrong thing.