> By default, Calyx is privacy-preserving, because it doesn't connect automatically to WiFi. You choose to connect to WiFi only if you want to.
Going to simply interpret this as unhelpful sarcasm.
> My point is that the comment I'm answering touts the sandboxed Google Play Services.
Sandboxed Google Play isn't included in GrapheneOS. Users can choose to install apps which include Google's libraries and use the Google Play SDK. Regardless of whether people use sandboxed Google Play or microG, they're using the Google Play code inside each app using it. The whole point of sandboxed Google Play is that users can optionally choose to install Play services and the Play Store in the user/work profile(s) of their choice with it receiving ZERO additional access or privileges compared to the Google libraries / Play SDK within each app using it. GrapheneOS does not include Google Play and has no special sandbox for Google Play. It includes a compatibility layer for users to run it in the full, strictest API 32 app sandbox with all the standard GrapheneOS enhancements. It does not receive any special access or privileges. It can't do anything the Google libraries within apps can't already do themselves. The Sandboxed Google Play compatibility layer also includes the ability to redirect APIs like location services to the OS implementation. By default, location services are redirected to the OS implementation, so users don't need to give Location access to Play services. Of course, if users grant Location to apps using Google Play, they're trusting the app and all the included libraries, and any app using Google Play is using Google Play libraries.
You can see for yourself that the full featured Google Maps app completely works without Google Play, and that their Ads SDK and other libraries work without it. Their libraries can do everything that sandboxed Google Play can do on their own without it. That's the whole point. Google Play is not required to contact Google services. Apps can do that on their own, and Google's libraries within those apps are fully capable of doing it. They largely choose not to implement fallbacks for features, but in some cases they clearly do as you can see from Google Maps and the Ads SDK. Only apps using the Lite variant of the Ads SDK need Google Play services for it to work. And again, sandboxed Google Play is not included in GrapheneOS. CalyxOS includes microG as part of the OS and encourages using it through the setup wizard. That uses Google's proprietary services and code. The Play code in each app is not replaced. It has a bunch of serious privacy and security issues from not implementing all the expected security checks, in some cases because microG is ideologically against enforcing the security model for things like location services.
CalyxOS doesn't simply include microG with users encouraged to use it. They use Google services by default, with no way to turn them off. They significantly roll back the security model of the OS. They recently went almost 4 months without shipping the browser or Android security updates, including multiple vulnerabilities caught being exploited in the wild and announced as such in bulletins. How are users supposed to get privacy and security from an OS which lacks consistent security updates and has no problem rolling back or bypassing the standard OS privacy and security model? It isn't simply not a hardened OS. It's a dangerously insecure one.