HOW ENHOVE WORKS

A private phone, connected to your own VPS.

Enhove combines a GrapheneOS-based Pixel setup with a dedicated VPS and private services configured for you. We call that environment your private cloud.

On this page

01 / SYSTEM

The system at a glance

Enhove is not one privacy app. The phone runs the privacy-focused mobile setup, while a dedicated VPS runs the supported private services behind it. Enhove configures both sides to work together.

Enhove prepares these supported pieces to work together. This does not mean that every internet connection is anonymous or that every application stops communicating with external services.

02 / THE PHONE

The phone

Enhove uses compatible Google Pixel hardware with a GrapheneOS-based phone setup. The goal is a familiar Android smartphone experience with stronger privacy boundaries, without requiring a personal Google account for the core Enhove experience.

BYOD

Bring your compatible Pixel

You keep custody of your phone and perform the guided setup using a PC and cable. Enhove supplies the required instructions and files, with support available if you need help. No shipping to Enhove is required.

READY-TO-USE

Choose an Enhove Phone

An Enhove Phone is compatible Pixel hardware prepared with the Enhove setup and delivered ready to use and connect. It is the prepared product experience—not proprietary smartphone hardware. Hardware is priced separately from the setup fee.

03 / PRIVATE CLOUD

Your private cloud

Your private cloud is a dedicated VPS and the private services configured on it for you. Enhove provisions that VPS for you through a supported third-party hosting provider; it is not a shared Enhove workspace.

01

Enhove provisions the VPS

Enhove arranges a dedicated VPS with a supported third-party hosting provider and prepares it for the supported services.

02

Two years of hosting are included

The Initial Setup includes the first two years of VPS hosting. Hosting must still be paid after that term; the renewal price will be confirmed before purchase.

03

Control is handed to you

You receive control of the hosting-provider account and the VPS root credentials. The handoff is intended to include credential rotation where needed so Enhove does not retain those privileged credentials afterward.

04

Enhove access stays separate

If you add management, Enhove uses a separate restricted administrative account. It is distinct from your provider/root credentials and can be revoked without deleting the VPS.

Technical status: the provider, secure handoff and credential-rotation flow, and exact restricted permissions are still being validated. The intended boundary is customer control of provider/root credentials and independently revocable Enhove access.

04 / CORE PRIVATE SERVICES

What runs in the private cloud

The initial Enhove setup includes four core private services. They run on or through the customer's dedicated VPS and connect to the phone where supported.

Private VPN

A VPN server runs on your VPS, with device-specific configuration on your phone. When you use it, traffic can leave through your VPS instead of a shared commercial VPN service, so no separate commercial VPN subscription is required. This is not a promise of anonymity.

Private Email

Your VPS can run the supported mail server for an address on your own domain, such as [email protected]. Enhove configures the supported mail stack and required DNS authentication records. Delivery still depends on domain and DNS configuration, provider restrictions, sending-IP reputation, and receiving mail providers.

Private Push

Enhove is developing and configuring a private Push compatibility layer for supported apps, intended to keep notifications practical without requiring a personal Google account for the core phone experience.

Learn how Private Push works

Private DNS

Your VPS runs AdGuard Home for filtering and policy, with Unbound performing recursive DNS resolution directly rather than forwarding your queries to Google, Cloudflare, or another public recursive DNS provider. DNSSEC validation is enabled, and supported block lists can stop known advertising and tracking domains at DNS level before connections to them are made.

Learn how Private DNS works

PRIVATE DNS ARCHITECTURE

How Private DNS works

Your own encrypted DNS infrastructure runs on your VPS. The phone reaches the same customer-specific DNS stack through one of two supported encrypted paths.

Private recursive resolution

There is no Google, Cloudflare, or other public recursive DNS provider sitting upstream of your resolver. Unbound performs the DNS recursion itself, communicating with root, top-level domain, and authoritative DNS servers as resolution requires.

Encrypted and fail-closed

DNS requests stay encrypted—through your VPN or strict DNS-over-TLS. With the supported strict Private DNS configuration, GrapheneOS does not silently fall back to plaintext DNS if the encrypted endpoint becomes unavailable. DNS resolution fails instead.

Filtering and DNSSEC

Known advertising and tracking domains can be blocked at DNS level before connections to them are made, using configurable supported block lists. DNSSEC validation helps detect forged or tampered responses for correctly signed domains. DNS filtering does not eliminate all advertising or tracking.

Policy and access boundaries

When the Enhove VPN is active, common direct plaintext DNS, DNS-over-TLS, and DNS-over-QUIC bypass paths are blocked so the configured policy remains the default path for normal DNS traffic. This is not a claim that every application-specific resolver can be intercepted. The DNS administration interface is accessible only through your private VPN.

Tested operating behavior: the setup automatically renews its TLS certificate, survives VPS reboots, and includes basic request-rate protection. Enhove provisions and configures the DNS infrastructure; if you choose optional management, Enhove can also maintain the supported configuration.

05 / PRIVATE PUSH

How Push works

Push notifications are one of the hidden dependencies of modern Android apps. Many mainstream applications rely on Google's Firebase Cloud Messaging to deliver notifications in the background. A privacy-focused Android setup can run those applications, but convenient push delivery can still leave the phone dependent on Google infrastructure.

Enhove wants the phone to remain practical for everyday apps, so Private Push is intended to preserve normal notification behavior for supported applications while reducing unnecessary dependence on a personal Google account and default platform services.

WHAT WE'RE TRYING TO PROVIDE
  • Practical background notifications for supported apps
  • No personal Google account required for the core Enhove experience
  • Reduced dependency on default Google services where technically possible
  • A Push layer integrated with the customer's private environment
WHAT WE DON'T PROMISE
  • Compatibility with every Android application
  • Zero communication with all Google-operated infrastructure
  • Complete elimination of third-party infrastructure
  • A final Push architecture before the remaining PoC and R&D are validated

Technical status: the exact compatibility path is still being validated and may differ by application. Some paths may still interact with Google infrastructure; implementation details are not presented here as shipped architecture.

06 / ONE-TIME SETUP

What Enhove sets up

The current Personal validation price is approximately $500 one-time setup for preparing the supported phone-and-VPS system.

  • Dedicated VPS + 2 years hostingA VPS is provisioned for your private environment and its first two years of hosting are included in the Initial Setup.
  • Baseline VPS configurationThe supported infrastructure and security baseline are prepared.
  • Private VPN, Email, Push and DNS configuration
  • Phone and private-environment integration
  • Initial verification of the supported environment

For BYOD, Enhove prepares the VPS and supported services while the customer performs the guided phone installation. Ready-to-use Pixel hardware is priced separately. The setup fee does not include hosting forever, perpetual administration, unlimited storage, or unlimited support.

07 / OPTIONAL MANAGEMENT

Optional ongoing management

For approximately $30/month, Enhove can provide updates, maintenance, health monitoring, operational support, and backup and recovery support for the supported private environment.

01

Self-manage

Use your provider and root credentials to operate the supported environment yourself.

02

Another administrator

Give a separate administrator access without transferring your provider/root control.

03

Enhove management

Add the optional service through a separate restricted administrative account.

Your provider and root credentials remain under your control. If management ends, the Enhove administrative account can be revoked without deleting the VPS or transferring those privileged credentials. Exact permissions, backup scope, and recovery procedures will be documented before purchase.

08 / RESPONSIBILITY

Who controls what

The customer remains the center of the model while responsibility for ongoing administration can be chosen.

ComponentControl / responsibility
Pixel hardwareCustomer
Phone / GrapheneOS-based setupRuns on the customer's device
VPS hosting-provider accountCustomer
VPS root/privileged credentialsCustomer
VPN / Email / Push / DNSCustomer's VPS/private environment
Optional Enhove admin accountEnhove, only when management is enabled
Ongoing administrationCustomer, another administrator, or Enhove

09 / CLAIM BOUNDARIES

What Enhove does not claim

Privacy claims should be verifiable. Enhove describes the intended product precisely rather than turning unfinished technical work into a promise.

Complete anonymity

Private infrastructure is not the same as anonymity.

Zero third-party network interaction

Some apps and compatibility mechanisms can still interact with external infrastructure.

Zero Google infrastructure interaction

The core experience does not require a personal Google account, but supported apps or compatibility layers may still interact with Google infrastructure.

Proprietary phone hardware

Enhove Phone uses compatible Pixel hardware prepared as the Enhove experience.

Permanent Enhove dependency

Ongoing Enhove management is optional.

EARLY ACCESS

Want to see if Enhove fits your setup?

Tell us what you're looking for and help us shape early access.

Get early access