
GrapheneOS user reportedly flagged to authorities; Yoti denies it
A post on the GrapheneOS forum says a user was told by age-verification provider Yoti that their device had been flagged and reported to the authorities. Yoti says the claim does not match its support records.
A post on the GrapheneOS discussion forum describes a user who says customer support at Yoti, a British age-verification provider, told them their device had been flagged and that the matter had been passed to the authorities and to the company's security team. The claim spread quickly on Reddit's r/privacy section and on Hacker News before the company responded publicly.
What the user reported
According to the forum thread, the user completed an age check through Yoti on a phone running GrapheneOS, the hardened Android-based operating system built for Google Pixel devices. A screenshot shared on Imgur shows a support reply stating that the platform "automatically flags any devices running GrapheneOS" and that such cases are reported both to law enforcement and to the provider's security team.
The episode struck a nerve because age verification is becoming mandatory in a growing number of countries, and because some of those systems rely on device-level attestation to confirm that a phone is running an unmodified, manufacturer-approved operating system.
Yoti's response
Yoti published a statement titled "Yoti does not report GrapheneOS users to the authorities." The company said it is aware of the claim circulating online and that "Yoti does not and would never report users to the authorities based on their choice of device or operating system." It added that the customer support email being shared "does not match anything in our customer support records," and that it has engaged with the GrapheneOS project to understand any issues its users may be facing.
The project's reading and the technical debate
The GrapheneOS account in the same thread called the episode fearmongering built on a support agent's claims, noting that using GrapheneOS is not illegal and that the agent was most likely improvising to close a ticket. In the project's view, services are far more likely to detect the absence of Google Mobile Services than to detect GrapheneOS specifically.
Forum members noted, however, that identification is technically easy: an app can query standard system APIs or the hardware attestation API and match the verified boot key against known GrapheneOS keys, while Google's Play Integrity checks for certified hardware running a certified stock build. GrapheneOS replied that hiding an operating system's identity from apps is not realistically feasible, and is not a side effect of its own security hardening.
Skeptics on Hacker News pointed out that the original poster had a history of posts about bypassing age verification and that a support email screenshot can be edited, so the episode's accuracy remains disputed. Either way, the thread's practical advice was consistent: keep a separate, cheap stock-Android phone for mandatory identity and age-verification apps, and treat the main device as private.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.