In June 2026, Yoti sent a support email stating it “automatically flags…any devices running GrapheneOS” and that “these instances are automatically reported both to the authorities and our security team,” but no law‑e... The detection works through standard Android attestation APIs that can identify GrapheneOS boot...

Create a landscape editorial hero image for this Studio Global article: What happened when a GrapheneOS user claimed Yoti flagged his device and reported him to police solely for using that operating system, how. Article summary: Here is the full breakdown of the incident, Yoti's response, and the broader privacy tensions it highlights.. Topic tags: general, government, general web, user generated. Reference image context from search candidates: Reference image 1: visual subject "# Yoti Reportedly Flagged a GrapheneOS User to Authorities for Using a Privacy OS During PlayStation Age Verification. June 7, 2026 GrapheneOS Yoti PlayStation Privacy Age Verifica" source context "Yoti Reportedly Flagged a GrapheneOS User to Authorities for Using a Privacy OS During PlayStation Age Verification" Reference image 2: visual subject "# Yoti Reportedly Flagged a GrapheneOS User to Authorities for Us
In early June 2026, a user trying to complete Sony Playstation Network’s age verification through Yoti on a GrapheneOS device received a support message that ignited a firestorm across privacy communities. The email claimed Yoti automatically flags “any devices running GrapheneOS” and reports those cases “both to the authorities and our security team.”
The claim was remarkable for two reasons. First, GrapheneOS is a legitimate, open‑source Android fork designed explicitly for privacy and security—it is not malware and its use is not illegal. Second, the email appeared to confirm that a third‑party age‑check provider was not only detecting a user’s operating system but also reporting that choice to external bodies. The backlash was immediate, surfacing on Reddit, Hacker News, the GrapheneOS forum, and news sites that cover the intersection of privacy and digital identity.
What actually happened is more nuanced than the viral headline suggested, but the underlying infrastructure that enabled the detection is real, already deployed, and expanding. Here is what the sources show.
The user shared a screenshot of an email ostensibly from Yoti support that read:
“Due to past security concerns, Yoti automatically flags multiple verification attempts and any devices running GrapheneOS. These instances are automatically reported both to the authorities and our security team.”
Several observers pointed out what looked like a contradiction in the message. The email also said the user’s account was flagged “as multiple attempts were made from this specific device.” That wording suggests the system may only flag repeated verification attempts from a GrapheneOS device—not a single use—and that the “and” could be a poorly written conjunction rather than a standalone policy of reporting every GrapheneOS user.
Crucially, no public evidence has emerged that Yoti actually transmitted a report to a law‑enforcement agency. The GrapheneOS project’s official position was that the “reported to authorities” claim was “nearly certainly…fearmongering from a rogue support agent” aimed at closing a ticket rather than describing a real external report. That view is shared by several privacy‑focused analysts who reviewed the incident.
Yoti has not issued a public corporate statement clarifying what “reported to authorities” means in the context of the email, whether it referred to an internal security flag, or whether the company’s standard workflow generates automatic external reports at all. The available reports contain the email and the resulting community discussion but no official walk‑back or clarification from Yoti management.
Even if the “reported to authorities” line was a support‑agent overstatement, the technology that identified the user’s operating system is not disputed. Apps can detect GrapheneOS using Android’s Hardware Attestation API. The app requests an attestation and matches the verifiedBootKey against the known GrapheneOS boot keys.
This mechanism means an age‑verification flow can quietly double as an operating‑system check. A user who chooses GrapheneOS for stronger privacy can be treated as suspicious—or even blocked—without any visible notice about what triggered the flag. The Playstation incident shows that the plumbing for OS‑level discrimination is already present in at least one major age‑verification deployment.
The GrapheneOS episode landed in a tense regulatory environment for Yoti. In November 2025, Spain’s data protection authority, the AEPD, imposed a total fine of €950,000 on Yoti Ltd for three GDPR violations related to its Digital ID app and age‑estimation technology :
Yoti has strongly rejected the AEPD’s decision, stated that no personal data was breached, and filed an appeal in the Spanish High Court. The company’s CEO emphasized that the ruling concerns only the Yoti Digital ID app in Spain and does not relate to services Yoti provides as a processor for its business clients.
The parliamentary question E‑001251/2026, tabled in the European Parliament in April 2026, explicitly cites the Spanish GDPR action and asks the Commission whether it will act to prevent age‑verification tools from putting user data at risk. The question notes that Yoti’s services are used by Meta, TikTok, and pornographic sites such as Pornhub—underscoring how widely the biometric‑processing questions extend.
Governments and regulators are rapidly expanding online age‑verification mandates, from the UK’s Online Safety Act to state‑level laws in the US and EU frameworks. These laws create a growing market for companies like Yoti, but they also force a collision between two goals: protecting children from age‑inappropriate content and preserving the privacy and anonymity of adult users.
The GrapheneOS incident is a symptom of that collision. An age‑check flow designed to confirm a user is over 18 ended up fingerprinting the user’s operating system, treating a privacy choice as a trust‑and‑safety signal, and allegedly threatening law‑enforcement involvement.
What remains unresolved is whether this was a one‑off support error or a preview of how age‑verification pipelines will treat devices that resist fingerprinting. The detection infrastructure is confirmed to exist. The public‑policy debate is now about whether regulators will require transparency about what these systems actually check—and what happens when a user’s operating system becomes the basis for a “suspicious activity” flag.
Studio Global AI
Use this topic as a starting point for a fresh source-backed answer, then compare citations before you share it.
In June 2026, Yoti sent a support email stating it “automatically flags…any devices running GrapheneOS” and that “these instances are automatically reported both to the authorities and our security team,” but no law‑e...
In June 2026, Yoti sent a support email stating it “automatically flags…any devices running GrapheneOS” and that “these instances are automatically reported both to the authorities and our security team,” but no law‑e... The detection works through standard Android attestation APIs that can identify GrapheneOS boot keys—meaning the infrastructure for discriminating against privacy‑focused operating systems is already built into age‑ch...
This incident landed just months after Spain fined Yoti €950,000 for unlawful biometric processing, invalid consent, and excessive retention of geolocation data, fueling broader parliamentary and regulatory questions...