Earlier quoted context omitted.
Consider this (by Graphene OS): https://discuss.grapheneos.org/d/24134-devices-lacking-stand... /e/OS community talking about it: https://community.e.foundation/t/article-from-grapheneos-abo... And then maybe this: https://eylenburg.github.io/android_comparison.htm Hope that helps.
I like GrapheneOS but they fail to understand in this post that the #1 security concern an android user face is the lack of privacy. Sure they have hardened everything but realistically, that's not the main threat for your average user. Their top contribution to android is the sandboxed Google Play, by far.
GrapheneOS does care about both, quite obviously. And GrapheneOS tends to say that if your security is bad, then it is affecting your privacy too. Whereas others say "sure, we break the Android security model by unlocking the bootloader and signing our system with the Google test keys, but your apps will contact Google through microG instead of the Play Services, so it's more private". Which is worth what it is worth...