Conversation

Wipe and rotate hardware-backed keys rather than data: reddit.com/r/GrapheneOS/c Factory reset or profile deletion is the right way to prevent future access to data. Clearing app data or uninstalling works on a per-app basis if the app encrypts data with the keystore like Signal.
2
19
Replying to
Unfortunately, not aware of apps bothering to do either. Signal uses the hardware-backed keystore to encrypt the database but doesn't split it into what's needed when locked vs. unlocked so it can't set the property on the key. Haven't seen apps do key rotation for expiry either.
1
7