Lineage is more about convenience and longevity rather than security and privacy. As another commenter said, Graphene is most suitable for this task if it's a major concern.
Take a random device like Google Pixel [1] it runs on a 4.4 kernel, long outdated and no longer maintained by Google. You can explore the code [2] however you are not going to be getting critical security updates (such as those issued by Qualcommm or any closed source blobs/firmware etc, and those released as per the pixel/android security bulletins).
Lineage is more about 'hacking' a kernel and making it work with the latest AOSP when the official software support ends. It's more vulnerable to exploits than a continuously supported device (although even devices that are 'in support' by the OEMs can often be depressingly behind things like patches etc).
Google is trying to fix this within the ecosystem (GKI, Apex etc) but at least as far as custom ROMs go...yeah, don't store state secrets on such a device ;)
[1]: https://wiki.lineageos.org/devices/sailfish/
[2]: https://github.com/LineageOS/android_kernel_google_marlin