How to Use Shelter to Create a Work Profile and Isolate Apps on Android (No Root)
15 min read
Step‑by‑step guide to install Shelter, set up a work profile, move apps into it, and keep personal data separate without rooting your Android device.
September 27, 2026 21:00
Why isolate apps without rooting?
Many Android users want to keep certain apps—social media, finance, or experimental tools—separate from their personal data. A work profile gives you a sandboxed space that behaves like a second device on the same hardware. It prevents apps in the profile from accessing contacts, photos, or other personal files unless you explicitly share them. Unlike rooting, a work profile does not break the device’s warranty, does not expose the system to malware, and can be removed cleanly at any time.
What Shelter does
Shelter is an open‑source app that leverages Android’s ManagedProfile APIs to create a work profile without needing a corporate device‑owner. It works on Android 5.0 (Lollipop) and newer, and it is available from the Google Play Store and F‑Droid. Because it uses the official work‑profile mechanism, the isolation is enforced by the OS, not by a third‑party sandbox.
Before you start
- Android version: 5.0 or later. Newer versions (Android 10+) provide tighter privacy controls, but Shelter works across the range.
- Internet connection: Required to download Shelter and any apps you plan to move.
- Backup your data: While Shelter does not touch your primary profile, creating a work profile modifies system settings. A recent
Google Drive backup or a manual adb backup is recommended.
- Battery level: Keep the device above 40 % or plug it in to avoid interruptions.
- Device admin permission: Shelter will ask to become a device administrator; this is safe and can be revoked later.
Step 1 – Install Shelter
- Open the Google Play Store (or F‑Droid if you prefer open‑source builds).
- Search for
Shelter – Android Sandbox and tap Install.
- Wait for the download to finish; the app size is under 10 MB, so it should complete quickly on most connections.
- Once installed, open Shelter. The first screen explains the concept of a work profile; tap Next to continue.
If you use F‑Droid, the app may be signed with a different key. In that case, Android will ask you to allow installation from unknown sources. Navigate to Settings → Security → Install unknown apps, select your browser or file manager, and toggle Allow from this source. Then return to Shelter and tap Install again.
Step 2 – Grant Device Administrator rights
- Shelter will request Device administrator permission. This is required to create the managed profile.
- Tap Activate. Android opens the device‑admin screen:
Settings → Security → Device admin apps.
- Check the box next to
Shelter and confirm.
Granting this permission does not give Shelter root access; it merely allows the app to ask the OS to create and manage a work profile.
Step 3 – Create the work profile
- Back in the Shelter main screen, tap the Create work profile button.
- The system will display a short animation while Android sets up the profile. You’ll notice a new icon in the notification shade that looks like a briefcase.
- When the profile is ready, you’ll see a separate app drawer labeled Shelter with only the apps you have moved.
If the device reports “Unable to create work profile”, check the Device admin status again and ensure the manufacturer has not disabled managed profiles (some custom ROMs do).
Step 4 – Move apps into the work profile
Shelter can import apps from the personal side or install fresh copies from the Play Store within the profile.
- In Shelter, tap Add apps. You’ll see two tabs: From Play Store and From installed apps.
- To clone an already installed app, select the From installed apps tab, find the app (e.g.,
Telegram), and tap the Clone button.
- For a brand‑new app, switch to the From Play Store tab, search for the app, and install it directly into the work profile.
- Repeat for each app you want isolated (e.g., banking, social, testing tools).
Cloned apps retain their data only within the work profile. If you uninstall the profile later, that data disappears without affecting the personal version of the app.
Step 5 – Configure permissions and storage
Android’s permission model applies separately inside the work profile. This means you can grant a less‑privileged set of permissions to the same app in the sandbox.
- Open the work‑profile version of the app.
- When the permission dialog appears, grant only what the app truly needs. For example, a finance app may not need Location access.
- To adjust permissions later, go to
Settings → Apps → [App name] → Permissions while the work profile is active (you’ll see a briefcase icon in the top‑right of Settings).
- Storage access works similarly: the work profile sees its own isolated
/storage/emulated/0/ directory. Files you download inside the profile stay hidden from the personal side unless you manually share them.
To share a file, use the Share button and choose the personal profile as the target. Android will copy the file across the profile boundary instead of moving it.
Step 6 – Back up the work profile
Because the work profile is a managed profile, Android’s built‑in backup service can store its data in your Google account, but only if you enable it.
- Open the work‑profile Settings (tap the briefcase icon in the notification shade, then Settings).
- Navigate to
System → Backup and toggle Back up to Google Drive on.
- Ensure the same Google account used for your personal backup is selected.
- Trigger an immediate backup by tapping Back up now.
If you prefer a local backup, Shelter includes an Export feature that creates a .tar.gz of the work‑profile app data. Open Shelter, tap the three‑dot menu, choose Export profile, and follow the prompts. Store the archive on a secure cloud service or external SD card.
Step 7 – Managing notifications and UI separation
By default, Android mixes notifications from both profiles, which can defeat the privacy goal. Shelter offers a simple switch:
- In Shelter’s main screen, toggle Hide work profile notifications.
- When enabled, notifications from apps inside the work profile appear only in the separate Shelter notification shade, accessible by pulling down twice.
You can also set a distinct wallpaper for the work profile (Settings → Display → Wallpaper) to give a visual cue that you are operating inside the sandbox.
Step 8 – Removing apps or deleting the work profile
If you no longer need an isolated app, you can delete it without affecting the personal copy.
- Open Shelter, locate the app, and tap the Delete (trash) icon.
- Confirm the removal. The app and its data are erased from the work profile only.
- To remove the entire work profile, go to Shelter’s Settings (three‑dot menu → Profile settings) and select Delete work profile. Android will ask for confirmation; proceed only if you have backed up any needed data.
After deletion, the briefcase icon disappears, and the device returns to a single‑profile state.
Troubleshooting common issues
1. Work profile fails to create
- Cause: Device admin not enabled or manufacturer disables managed profiles.
- Fix: Re‑enable the admin permission (Settings → Security → Device admin apps). If the device is from a brand that blocks work profiles (e.g., some Chinese OEMs), you may need to flash a stock ROM or use a different device.
2. Cloned app crashes immediately
- Cause: The app uses a signature‑based licensing check that fails when duplicated.
- Fix: Install the app directly from the Play Store inside the work profile instead of cloning. Some games and streaming apps do not support work‑profile installations.
3. Backup does not include work‑profile data
- Cause: Android backup is disabled for the profile.
- Fix: Open work‑profile Settings → System → Backup and ensure the toggle is on. Verify that the same Google account is selected.
4. Excessive battery drain after enabling Shelter
- Cause: Background sync of apps inside the profile.
- Fix: Open each app’s battery settings (Settings → Battery → [App]) and restrict background activity where appropriate. Also, consider disabling the Hide work profile notifications toggle if you notice a constant polling service.
Edge cases and manufacturer quirks
While Shelter works on the vast majority of AOSP‑based devices, a few manufacturers implement custom restrictions:
- Huawei / Honor: EMUI may hide the
ManagedProfile APIs on older Android versions. Updating to EMUI 10+ usually restores compatibility.
- Samsung: If you already have Samsung Secure Folder enabled, Shelter will detect the existing work profile and refuse to create a second one. You can either use Secure Folder or uninstall it before proceeding.
- Android Go devices: Limited storage can make the
.tar.gz export fail. Use the built‑in Google backup instead.
Security considerations
Even though Shelter isolates apps, the host OS still controls the hardware. Keep these points in mind:
- Device admin rights: Revoking Shelter’s admin status removes the work profile. Do this only after you have deleted the profile, otherwise the profile may become orphaned.
- Network separation: Apps inside the work profile share the same network interface as the personal side. If you need network isolation (e.g., a VPN only for work apps), configure a per‑app VPN in Android 10+ or use a third‑party VPN that supports split tunneling.
- Data leakage via shared storage: Copying files from the work profile to the personal side creates a duplicate; the original remains in the sandbox. Review shared files regularly to avoid accidental exposure.
Advanced tip: Using ADB to script profile management
For power users, Android’s pm (package manager) and dpm (device policy manager) commands let you automate profile creation and app installation. Example:
# Create a work profile (requires device owner; Shelter sets this automatically)
adb shell dpm set-profile-owner com.jakewharton.shelter/.ProfileOwnerReceiver
# Install an app into the work profile
adb shell pm install-create --user 10 /sdcard/Download/app.apk
Replace 10 with the user ID of your work profile (you can find it via adb shell pm list users). This method is optional and primarily useful for developers or IT admins who need to provision many devices.
Wrapping up
Using Shelter gives you a fully functional work profile without ever rooting your phone. You gain:
- Strong data isolation for selected apps.
- Separate backup and restore cycles.
- Fine‑grained permission control per app copy.
- The ability to delete the sandbox cleanly when you’re done.
Because the solution relies on Android’s native managed‑profile framework, it works across most devices, respects manufacturer security policies, and can be removed without leaving traces. Follow the steps above, keep a backup of any important work‑profile data, and you’ll have a privacy‑first environment ready in under ten minutes.