android spyware is largely embedded in the google play services
sensors, contacts, app info, hardware info, etcetc
it collects these with elevated privileges in stock android, it cannot be disabled and telemetry cannot be disabled no matter what you do
graphene ships without e down for the friction you can direct install some apk's (signal does this), use f-droid for foss apps, and use progressive web apps (pwa's) to fill the gaps
if you want play store apps, you can sandbox the play store; giving it the same authority as any other app w tight controls over what it can access and when. apps installed thru sandboxed play store must request permission up the chain:
app -> play store -> graphene -> you
data flow starts and stops with you.
play wants your location? seethe.
play wants your hardware ids? mald.
play wants your contacts? pound sand.
is the pixel-only constraint problematic?
is immigration reform on stolen land problematic?
yea, it is.
you get the cards you get.
at least in the former case, graphene & motorola are partnering to further open access to an os that still gives a shit about privacy
do not let these ppl black pill you, friend
you dont have to live on the backfoot with your data on your device