The title rhymes!
If you’re begrudgingly using Aurora Store because you need it for whatever reason, there’s a small thing you might want to be aware of to increase your privacy.
When selecting anonymous account, you’re still sending some metadata to Google. As F-Droid warns on the Aurora Store page:
By default, the apps list and system details are sent to Google Play servers, which is likely enough data to fingerprint the device.
In other words - here be dragons.
If you’re gonna do it though, along with the obvious precautions, you can use Tor strictly for the connection to Aurora Store. Here’s how: download Orbot, go to orbot settings, general, enable power user mode. Go back to the main menu and note the Socks Port number (default 9050), click connect. Go into Aurora Store, settings, networking, click on proxy Url and enter
socks://127.0.0.1:9050
or whatever your socks port was. You can also type localhost rather than that IP most of the time (but I’ve seen the app bug out randomly).
Now you’re connected through Tor without having it on system wide.
You’re still giving valuable data to Google, but at least you’re mixing yourself in with the pool of Tor users. Whether this can truly stop Google, who knows.
VPN is basically always blocked so if you’re also using that, you’ll need to enable split tunneling for Aurora Store (note this is technically a privacy risk).
Even still, Google will block Tor from time to time. You can play around with Orbot a bit to try making it less common, but Aurora Store is buggy at the best of times.
But I know people will use it anyways, so you might as well make things a bit more private. When possible, use Obtanium or F-Droid instead. F-Droid has built in Tor as well. There’s probably a bunch of other stuff you can do, but this was the least documented bit I came across personally.


I appreciate you taking the time to do this write-up, OP. Unfortunately, I believe it will not do what you hope it does, i.e.: “make you a it more private”.
Think of this in terms of data points Google gets on you. As per the warning on FDroid, they get:
That alone is very likely enough to identify you, particularly if you
Let’s say you’re running GrapheneOS on a Pixel 7a and have apps installed for Swiss Rail, Bern public transport, the UBS banking app and Signal. How many people will have this particular setup? I’d wager this would already narrow the pool down to a single-digit number of users, if not “one”, and any additional app off the Play Store will narrow it down even further.
While using your native public IP will give them yet another data point to identify you, so will the use of TOR or a VPN, because, again, only a fraction of Aurora store users will do that.
On the other side of the equation, the only “threat” I can think of is: “Google will know that I use these apps”. Outside of a targeted attack (i.e. Google sending you - specifically you - an update with malicious code injected into the APK), I cannot see any truly harmful scenarios arising from this.
All in all, I don’t think there’s much to be gained here: both the effect (if it works at all) and the threat (if you don’t do anything) seem so miniscule that it’s hardly worth the time to set this up.
Instead, this time is probably spent better on this here:
The only way not to be tracked by Google is not to get involved with Google. The only way to truly win the game is not to play it.
I believe you are right.
Which cuts to something else. I do not think most ppl have an intuition, for just how little info is sufficient to ID them. It isn’t much! That unfortuntely, makes life hard for we who value privacy. And easy for those who attack privacy.
Mathematically it isn’t an impossible fight for us. But it is an up hill fight.
If you only interact with Aurora Store via Tor and don’t use Play Services to prevent potential IPC data leaks and block network of apps with firebase analytics then it helps a decent chunk more.
Of course we can go down the rabbit hole of privacy 'till whatever point suits us. If somebody is determined to use Aurora or is going to use Google in some way or another, then they’re gonna use it.
I don’t see a negative aspect to throwing Tor in the mix at the very least.
If you know there’s a better solution (there is), then you’re probably not the target audience for the post. I mean that in a nice way, I hate Google with a fiery passion too.