Start typing to search

GemiGuard

Knowledge Base · Banks · Diia · GrapheneOS

Banking apps, Diia and Reserv+ on GrapheneOS: what works on a Pixel in Ukraine

Privat24, monobank, Oschad, Sense SuperApp, MyRaif and KredoBank work on a Pixel with GrapheneOS through sandboxed Google Play; Reserv+ works even without Google services, and Diia works under two conditions; tap-to-pay through Google Wallet is unavailable. The answers rest on compatibility reports published from 2022 to 2026 and on our own tests.

Reference Published Updated 8 min read

A Google Pixel 10 smartphone at an angle on a dark background, with a small payment card icon in the corner

The short answer

Most Ukrainian banks’ apps work on GrapheneOS with sandboxed Google Play: Privat24, monobank, Oschad, Sense SuperApp, MyRaif and KredoBank have compatibility reports from 2022 to 2026. We tested monobank, Privat24 and MyRaif ourselves in 2026: they work. Reserv+ works even in a profile with no Google services. Diia works under two conditions: it is installed from the Play Store under a separate Google account, and exploit protection is relaxed for that one app. Binance works.

The NFC chip works, while tap-to-pay through Google Wallet and Google Pay is unavailable on GrapheneOS: Google permits it only on operating systems it has certified itself, and Ukrainian banks run NFC payment through Google Pay. With a GrapheneOS phone you pay with the physical card or with a watch that has its own NFC wallet.

Why banks have questions about GrapheneOS at all

Most financial apps check the device through Google’s Play Integrity API, which has three levels. GrapheneOS passes Google’s “basic” level. The “device” and “strong” levels require the operating system to be certified by Google, and no system other than Google-certified Android passes them. The GrapheneOS developers put it plainly on 10 May 2026: the Play Integrity API bans GrapheneOS although it is more secure than anything Google permits.

GrapheneOS does not try to bypass the check by faking responses, because such a bypass breaks with every Google update. Instead the project offers developers Android’s standard hardware attestation mechanism, which GrapheneOS supports in full and which gives a bank a stronger guarantee than Play Integrity. In practice: an app that requires only the basic level, or never calls Play Integrity, works; an app that requires Google certification refuses.

Sandboxed Google Play

GrapheneOS installs the optional Google services and the Play Store as ordinary apps without system privileges, with only the permissions we grant them. For most banking apps that is enough: they get notifications, SMS codes and the other functions they expect from Google services, and the system stays hardened. We recommend keeping Google Play, Diia and the banking apps in a separate, isolated user profile with a separate Google account created for that profile alone.

From the GrapheneOS guide: some banking apps carry their own anti-analysis mechanisms, and the “Native code debugging” toggle in the exploit protection settings can interfere with them. If an app crashes, that toggle may be the quick solution.

Banks: what has been verified

AppStatusSource
Privat24 (PrivatBank)Fully working. Occasionally asks for the SMS permission for Google services; the codes arrive without it.Tested by GemiGuard, April 2026
monobankFully working.Tested by GemiGuard, April 2026
Oschad (Oschadbank)Works. On first setup the first two logins after the PIN hung on loading; the third passed.PrivSec, Pixel 8, 27 November 2024
KredoBankWorks.PrivSec, Pixel 9, 24 December 2025
Sense SuperApp (Sense Bank)Fully working. Does not start without Google services.PrivSec, Pixel 7, 2 June 2026
MyRaif (Raiffeisen Bank)Fully working.Tested by GemiGuard, April 2026

Diia

Diia 4.34.3 works on Pixel 8a, 9 and 10a, confirmed by several independent sources in July and August 2026, under two conditions.

First: it is installed from the Play Store, under a registered Google account, in the profile with sandboxed Google Play. Installed through the Aurora Store, Diia closes immediately after launch without any message, because the app checks where it was installed from.

Second: exploit protection is relaxed for Diia. The working recipe: in the app’s settings turn off every protection option except the hardened memory allocator, allow verified links, and grant the phone, nearby devices, network and notifications permissions. This applies to Diia alone; the rest of the system stays in its normal mode.

Diia.Signature, the qualified electronic signature, is unconfirmed as of September 2026: by users’ observations its passport number recognition relies on Google ML Kit modules distributed only through the official Play Store.

Reserv+

Reserv+ 2.3.2 works, confirmed on Pixel 9 and Pixel 8a in July 2026, and in the strictest configuration: a separate profile without Google services and without the Play Store, installed through Aurora, every exploit protection option on. No Play Integrity dependency was observed.

That agrees with what the Reserv+ developers announced in April 2026: the app received stronger protection and no longer works on devices with administrator (root) rights. GrapheneOS gives no root, and the bootloader is locked again with GrapheneOS keys after installation, so to Reserv+ it is an ordinary phone.

NFC and paying by phone

The NFC chip on a Pixel with GrapheneOS works: it is switched on in the connection settings, it reads tags and chipped documents, and apps with their own contactless wallet pay through it. In Europe Curve Pay works that way; in Australia the Commonwealth Bank app pays with its own function.

Tap-to-pay through Google Wallet is unavailable on GrapheneOS, and that is Google’s decision, not a GrapheneOS limitation. Google Wallet’s help page: the wallet does not run on phones that “are rooted, run a custom ROM, or have modified factory software”, “have an unlocked bootloader” or “are untested and haven’t been approved by Google”; Google advises reinstalling the original operating system in that case.

Ukrainian banks run tap-to-pay through Google Pay: PrivatBank links the card to Google Pay from the Privat24 app, monobank adds the card to Google Pay from its app or through Google Wallet. Neither bank currently offers its own NFC wallet inside the app, so on GrapheneOS tap-to-pay through these banks is unavailable. You pay with the card, or with a watch that has its own wallet: Google Wallet on a Wear OS watch paired with a GrapheneOS Pixel pays, and PrivatBank, for example, supports Garmin Pay and SwatchPay, which do not depend on the phone’s system.

Binance and other crypto exchanges

Binance works with sandboxed Google Play: repeated confirmations on the GrapheneOS forum from 2022 through 2025 and a PrivSec report from November 2024. The app asks for the Play Integrity API now and then and carries on working. By contrast, since September 2025 the Play Store on GrapheneOS refuses to install Coinbase as “not compatible”, although the directly installed APK runs.

Updates

What works today may stop working tomorrow, and the reverse: compatibility moves with app updates, not with the system. A Pixel with GrapheneOS remains a very secure device. Signal, Molly, Threema and SimpleX work.

Buy a Pixel with GrapheneOS: models

Sources

GrapheneOS documentation

  • GrapheneOS, usage guide, sections “Sandboxed Google Play” and “Banking apps”. — grapheneos.org
  • GrapheneOS, attestation compatibility guide for developers. — grapheneos.org
  • GrapheneOS, statement on the Play Integrity API, 10 May 2026. — grapheneos.social

Compatibility reports

  • PrivSec, banking app compatibility with GrapheneOS, the “Ukraine” section, and reports 124 (Privat24), 323 (monobank), 539 (Oschad), 839 (KredoBank), 999 (Sense SuperApp), 1000 (MyRaif), 536 (Binance). — privsec.dev
  • GrapheneOS forum, “Does Diia app work for anyone?”, March to August 2026. — discuss.grapheneos.org
  • GrapheneOS forum, “Ukrainian gov. apps (Diia, Rezerv+) and contactless payments”, July to August 2026. — discuss.grapheneos.org
  • GrapheneOS forum, “NFC payments on graphene”, 2025 to 2026. — discuss.grapheneos.org
  • GrapheneOS forum, “Google Wallet NFC payments on WearOS Watch with GrapheneOS on the phone”, May 2025. — discuss.grapheneos.org
  • GrapheneOS forum, “Crypto exchange apps working on GrapheneOS”, 2022 to 2026. — discuss.grapheneos.org

Google, the banks and the state apps

  • Google Wallet Help, “Fix problems with tap to pay transactions”. — support.google.com
  • Reserv+, the chatbot’s notice on rooted devices, quoted on 24 April 2026. — 7eminar.ua
  • PrivatBank, “PrivatBank with Google Pay”. — privatbank.ua

Frequently asked questions

Does monobank work on GrapheneOS?

Yes. monobank works on a Pixel with GrapheneOS with sandboxed Google Play: a PrivSec report from November 2023 and our own test in April 2026. The app cannot add a card to Google Pay, because Google Pay is unavailable on GrapheneOS, and every other function works.

Does Privat24 work on GrapheneOS?

Yes. Privat24 works in full; now and then it asks for the SMS permission for Google services, and the codes arrive without it. Tested by GemiGuard in April 2026.

Does Diia work on GrapheneOS?

Yes, under two conditions: Diia is installed from the Play Store under a separate Google account in the profile with sandboxed Google Play, and exploit protection is relaxed for that one app. Confirmed on Pixel 8a, 9 and 10a in July and August 2026. Diia.Signature is unconfirmed as of September 2026.

Does Reserv+ work on GrapheneOS?

Yes. Reserv+ 2.3.2 works even in a profile without Google services and without the Play Store, with every protection option on. The Reserv+ developers block rooted devices; GrapheneOS gives no root and locks the bootloader.

Can a GrapheneOS phone pay with Google Pay tap-to-pay?

Tap-to-pay through Google Wallet and Google Pay is unavailable on GrapheneOS: Google permits it only on operating systems it has certified itself. The NFC chip works, so you pay with the physical card or with a watch that has its own NFC wallet.

Does Binance work on GrapheneOS?

Yes. Binance works with sandboxed Google Play: a PrivSec report from November 2024 and confirmations on the GrapheneOS forum in 2022 and 2025. The app asks for the Play Integrity API now and then and carries on working.

VPN · PIXEL · GRAPHENEOS

VPN on a GrapheneOS Pixel: why an app on the handset does not cover all traffic

Enforcement in Android applies to application identifiers, and system identifiers are exempt from it at the level of the networking subsystem. Which categories Google confirms are outside the tunnel, why tethered traffic never enters it, where DNS leaks come from, and the one configuration — cellular off, Wi-Fi only, tunnel on the router — that leaks nothing.

IMEI · PIXEL · GRAPHENEOS

The IMEI on a Google Pixel: where it is stored and what changing it takes

Where the IMEI physically lives on a Tensor Pixel, the three layers that hold it in place, why it is an integrity check inside signed modem firmware rather than a hardware fuse, what IMEI spoofing modules actually change, and why none of it buys anonymity on a cellular network.

GUARDDO · ENCROCHAT · SKY ECC · ANOM

GuardDo Pixel: how to verify a secure phone

In September 2026 every check we could run on GuardDo Pixel gave the same result: its security claims come with no evidence a customer can verify. A claim that cannot be checked has to be taken on trust. Owners of EncroChat, Sky ECC and ANOM phones took the same kind of promise on trust.

Get in touch through a channel that suits you

Tell us which Pixel model you need — and get the price, lead time and delivery confirmed right in Telegram.