# Shelter for Android: Work Profile Isolation, Install and Limits

> Shelter is a GPL-3.0 Android app that uses the Work Profile to isolate or clone apps. This review covers how to install it, how the profile mechanism works, and why the project is in maintenance mode.

**PeterCxy/Shelter** — This repository is a mirror of https://gitea.angry.im/PeterCxy/Shelter. For bug reports, use https://lists.sr.ht/~petercxy/shelter

- Repository: https://github.com/PeterCxy/Shelter
- Website: https://gitea.angry.im/PeterCxy/Shelter
- Stars: 3,635 · Forks: 264
- Language: Java
- License: GPL-3.0
- Published: 2026-09-23 · Updated: 2026-09-23 · Language: en
- Canonical page: https://hysenlabs.com/projects/petercxy-shelter

## What Shelter Actually Solves on Android

Shelter is a Free and Open-Source app that uses the Android Work Profile to create an isolated space where you can install or clone apps. The README lists three capabilities: installing apps inside a work profile for isolation, freezing apps inside that profile so they cannot run or be woken when you are not using them, and installing two copies of the same app on one device. The intended user is someone who wants a second install space without root or adb. The README states the project does not intend to use or abuse adb privileges, so every feature has to come from the unprivileged Work Profile APIs that Android exposes. That single design decision explains both what Shelter can do and what it will never do.

## How the Work Profile Becomes an Isolation Boundary

Android work profiles are managed profiles: a separate user space with its own copy of installed apps and its own storage, managed by a device policy controller. Shelter acts as that controller and gives you a UI to move or clone apps into the managed side. Because the profile is a real Android user, isolation is enforced by the OS, not by Shelter. The README is direct about the consequence: Shelter is only as safe as the Work Profile implementation of the Android OS you are using, and it links to Google's own work profile documentation for details. The freeze feature is the second half of the mechanism. Freezing stops an app in the work profile from running or being woken, which matters for apps that register background jobs or push receivers. Both features are thin wrappers over platform behaviour, which is why the README says the app can only implement a strict subset of the exposed unprivileged APIs.

## Installing Shelter from F-Droid or the Custom Repository

The README gives two distribution channels. The stable build is on F-Droid, signed by F-Droid. A custom F-Droid repository signed by PeterCxy carries the latest development versions. If you add the custom repository on the phone, the README supplies a deep link:

```bash
fdroidrepos://fdroid.typeblog.net/repo/?fingerprint=1A7E446C491C80BC2F83844A26387887990F97F2F379AE7B109679FEAE3DBC8C
```

The same repository can be added manually in F-Droid with the URL https://fdroid.typeblog.net/repo and the fingerprint 1A 7E 44 6C 49 1C 80 BC 2F 83 84 4A 26 38 78 87 99 0F 97 F2 F3 79 AE 7B 10 96 79 FE AE 3D BC 8C. One constraint is stated plainly: you cannot switch between versions with different signatures without uninstalling Shelter first. That means moving from the F-Droid build to the PeterCxy-signed build, or back, costs you the app's state, so pick a channel before you set anything up. After install, open Shelter and read the setup wizard text carefully. The README points to that wizard as the place where caveats and known issues are discussed, and it is the only onboarding documentation the project offers. No command-line install exists; this is an Android app, not a CLI tool.

## Where Shelter Fails or Is the Wrong Tool

The most honest limitation is in the README itself: Shelter is only as safe as the Work Profile implementation of the Android OS you are running. On devices where the OEM has modified or restricted managed profiles, the isolation you get is whatever that implementation provides, and Shelter cannot compensate. The second limitation is scope. Since the project will not use adb privileges, its features can only be a strict subset of the unprivileged work profile APIs. Anything that would need elevated access is out of reach by design, not by backlog. Third, the README states the project does not intend to add many new features unless work profile APIs change substantially. If you are choosing a tool because you expect a growing feature set, that expectation is not supported. Finally, uninstalling has an order: delete the work profile first in Settings, Accounts, then uninstall the Shelter app normally. Skipping the first step leaves the managed profile behind.

## Shelter Compared with Island and Root-Based Sandboxes

Island is the closest alternative in the same category: another Android app that builds on the Work Profile to isolate apps. Both projects sit on the same platform API, so the difference is not the isolation model but the implementation and distribution. Shelter is GPL-3.0, distributed through F-Droid and a PeterCxy-signed custom repository, and its README describes an effective maintenance mode with a commitment to adapting to new Android releases rather than adding features. A root-based sandbox such as a container or a Magisk module takes a different route entirely: it gets more control because it runs with elevated privileges, and it pays for that with root, a modified boot image, and a wider attack surface. Shelter's refusal to use adb privileges is exactly what makes it installable on a stock device and exactly what caps its capability. If you cannot or will not root, the Work Profile route is the available option, and Shelter is one of two well-known implementations of it.

## Maintenance, Releases and Upgrade Cost

The README describes Shelter as being in effective maintenance mode. The last push to the repository was on 2026-06-02, and the most recent listed release is 1.6 from 2020-09-29. Those two dates tell a consistent story: the app is not shipping frequent versioned releases, but the repository has seen work more recently than the last release, which fits the stated commitment to adapt Shelter to new Android versions, including target SDK bumps, new restrictions, and dependency updates. The author states he relies on Shelter daily and that it will not become abandonware in the foreseeable future. For an adopter, the upgrade cost is mostly the signature rule: you cannot switch between differently signed builds without uninstalling first, so an upgrade path that crosses channels wipes the app. Within a channel, normal Android app updates apply. The licence is GPL-3.0. That matters if you plan to redistribute a modified build: GPL-3.0 carries source disclosure obligations for distributed derivatives, and the repository also contains a repackage directory and metadata, which suggests the build and F-Droid packaging are part of the tree. This is a description of the licence, not legal advice; check the full text in the LICENSE file for your own situation.

## Conclusion

Shelter suits Android users who want a second, isolated install space without adb or root, and who accept that features are capped by the Work Profile APIs. If you need app-level sandboxing on a device whose OEM implements Work Profile poorly, or you want an actively expanding feature set, Shelter is the wrong pick. Before installing, confirm your Android version and OEM work profile behaviour, and note that switching between the F-Droid build and the PeterCxy-signed custom repository build requires uninstalling Shelter first.

## FAQ

### How do I install Shelter on Android?

Install it from F-Droid, where the build is signed by F-Droid, or add the custom F-Droid repository signed by PeterCxy to get the latest development versions. The README gives the repository URL https://fdroid.typeblog.net/repo and a fingerprint for manual setup, plus an fdroidrepos:// link for adding it from the phone.

### How do I use the Shelter app?

Open Shelter after installing and read the setup wizard text carefully, since the README says caveats and known issues are discussed there. From the app you install or clone apps into the work profile, and you can freeze apps inside that profile so they cannot run or be woken when you are not using them.

### What can Shelter help with?

Shelter provides an isolated space for installing or cloning apps, lets you freeze apps in the work profile to stop them running or being woken, and lets you install two copies of the same app on one device. All of this comes from Android's unprivileged Work Profile APIs.

## Sources

- [License: GPL-3.0](https://github.com/PeterCxy/Shelter/blob/master/LICENSE)
- [PeterCxy/Shelter on GitHub](https://github.com/PeterCxy/Shelter)
- [Project website](https://gitea.angry.im/PeterCxy/Shelter)
- [README](https://github.com/PeterCxy/Shelter/blob/master/README.md)
- [Releases](https://github.com/PeterCxy/Shelter/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/petercxy-shelter
