Conversation

Replying to
If it insists on being granted permissions, install it in a user profile (ideal) or work profile. Profiles have their own instances of apps, app data and shared data so when you grant it access to photos, contacts, etc. it won't actually get access to your actual data that way.
1
4
AOSP / stock Pixel OS have an unnecessarily low limit on the number of user profiles you can create but you can still have a decent amount (4) and each of them can optionally have a nested work profile. Work profile doesn't have quite as much isolation but it fairly similar.
1
1
Replying to
User profiles also have the neat property of each having their own encryption keys based on their lock methods. It's quite a useful feature. AOSP / stock Pixel OS doesn't expose a lot of the neat features outside enterprise use like 'end session' for purging keys without reboot.
1
1