I just don't buy this argument that Apple maintaining control over iOS is necessary for privacy. I think it's a false dichotomy. If you build a good OS, with good strong APIs, you can achieve both privacy and a more open ecosystem.
So I could write an app that interrogates the cellular network and other sources to implement location tracking (cruder than GPS but good enough for many purposes), snoops local wifi networks for information about connected devices. Even if it couldn't run in the background, it could snoop network traffic from iOS built in background services while it was running. If it had a built-in browser function it could track whatever browsing activity it liked. I'm sure there are plenty of other snooping activities that could be implemented that I can't think of in 5 minutes.
So there are plenty of ways such an app could violate your privacy, and you would never know. Right now, such apps have to pass App Store Review and such activity can be detected and the App kicked out. So side-loading potentially bypasses a lot of controls that can't really be implemented directly in the OS.
Users like yourself might assume that Apple could prevent these things in the OS, might think that even with side loading this is Apple's responsibility to protect you from it, as you seem to do. That a "good OS" as you put it would not allow these things to happen even in side loaded apps, therefore iOS can't be a "good OS" if side loaded apps break your privacy in ways you hadn't anticipated. But it's not all about the OS. This is the sort of reputational damage Apple is trying to avoid.