

Not an expert, but I’ve been looking into this and it seems like grapheneOS is the way to go if you really want control and security on a modern phone with timely updates (you would have to switch devices). The timely-ness of updates/patches on other platforms is a big criticism that I saw brought up a lot in disussions online. Not sure how much of a problem that truly is, if at all, but it is something to look into before committing to a big change.
Also one thing to look into before doing anything drastic would be taking advantage of shizuku with something like Canta. As I understand it, shizuku is like an inter-app request mediator that is able to abuse wireless debugging access to grant root-like permissions to linked applications without requiring root access or an unlocked bootloader. This should allow you to do some serious debloating.
From what I have read, living without google play services is possible to an extent (using FOSS alternative), but can be difficult / not 100% due to how google has positioned the bundled play services specifically as an authority in modern android













You can still download the old gui version for free. I use it to run a second simultaneous instance of AmScope software on a device at work. (Two microscope feeds on same screen for x y viewing)
I’m not totally clear on how sandboxie plus comes into play as one or both versions are open source