I think I should be able to completely cut it off from the network and/or local storage; prevent it from running even though it is installed; and prevent it from having any personalizing information about me, my movements, my network connectivity status or patterns, my device usage (i.e. screen on versus locked, any proxy like battery state of charge), etc.
I am very reluctant to install apps because I see that the platform is designed for needs and a mindset that is not my own. I do not see it as essential or preferable that an app be able to monetize my usage or really gather any telemetry at all.
In terms for pure access to the data/permissions, GrapheneOS seems to be the main (only?) choice. The default permissions apps get in current day Android allow to group activities and tie them to a single user across apps/sites.
[0]https://f-droid.org/packages/net.kollnig.missioncontrol.fdro...