I don't download apps, and I make a point of never entering google account credentials into an Android phone. I don't trust Google, and I don't trust app developers; the whole ecosystem seems designed more to exploit than to serve the end-user. So I just use my phone for SMS, and for killing time browsing the web while I wait for a bus or whatever.
Baseband aside (a big "aside"), isn't the mobile permissions system much more satisfactory than the desktop? unprivileged user-per-app vs everything-as-one-user-and-sometimes-we-ask-for-root
It's a step in the right direction; it just isn't much of a step. Ultimately I think we need a fine-grained capability system, where every process runs in a sandbox which can only see the resources I choose to grant it. Access to the specific hosts ought to be resources... and I should be able to provide dummy resources so that recalcitrant apps which refuse to run without the ability to call home can be run in an environment equivalent to a "hellban".