Theme 1: False positive detection
GrapheneOS is often flagged as “rooted” or non‑compliant due to indirect checks (custom ROM detection, Play Integrity) rather than actual root access.
“Well I haven't rooted my device. It's just normal grapheneos” – leumon
“These days, root is mostly flagged via indirect indicators rather than detecting the root binary itself. For instance, detecting custom ROMs is a common clue.” – therealmarv
Theme 2: Workarounds and technical fixes
Users report that disabling specific GrapheneOS security features (e.g., “Secure app spawning”) or using exploit‑protection compatibility mode lets PayPal work, or they fall back to the web version.
“But disabling 'Secure app spawning' seems to fix it for now.” – leumon
“I've been using it in the browser with GOS no problem.” – Schnittbrot
Theme 3: Corporate motives / security theater
Many commenters argue the blocks stem from liability concerns, compliance checkboxes, or a desire to avoid supporting niche OSes—not genuine security improvements.
“From a Paypal security POV … this inconsistency is very clearly not about PayPal's security. IMHO it's about two other things: 1. marketing … 2. compliance/politics BS.” – dathinab
“This is arguably the most irritating thing with just about every largecorp developer: 'os that hasn't been updated in 6 years? Sure boss!'. Os that is built specifically around security and privacy with daily updates: 'No, you can't do that'.” – axegon_
Theme 4: Community response and alternatives
The community advocates contacting companies, leaving reviews, growing the user base, and exploring alternatives like Wero or SEPA transfers.
“We have to make ourselves get heard. It's a social problem after all. Technical workarounds are great … but we have to fix the social issue at the root.” – basiliku
“The best approach to combat this is to cause as much headache as possible: bombard them with 1‑star reviews, contact news sites, post this on social media …” – Itoldmyselfso
“Switched to Wero and haven't looked back.” – aabdelhafez