- Edited
After a fair amount of reading (both on this forum as well as reddit privacy and other random articles) as well as watching videos from folks like The Hated One, Techlore, etc... I am fairly confused about the privacy (or lack thereof) of my iPhone and I'm considering a move to Graphene OS.
I'll summarize my situation as currently using an iPhone with a physical SIM card along with a couple of VOIP options (mysudo and google voice throwaways) to try and segment my phone numbers similar to how people use email aliases. Practically all of my friends/family/coworkers use an iPhone and therefore iMessage is their preferred method of communication (which I understand is E2EE). A couple use Signal and Whatsapp, but the vast majority use iMessage.
I do not use iCloud at all, I leave location services turned off except when I need it, use Apple maps (not google maps), use the brave browser and minimize the apps on my phone. I do not use any apple apps for things like notes, podcasts, music, etc... but rather other apps from the app store.
Now to the crux of my question. My understanding is that Apple does collect a fair amount of telemetry that they allegedly only use for their internal advertisement network and for "improving the experience". I have also heard that they are tapped into the PRISM program (per snowden), have tried to (but ultimately did not) roll out photo scanning in the name of "CSAM prevention", along with countless other allegations such as they can track all your browsing activity, any devices within close proximity of your iphone, any devices on the same wifi as your phone, etc...
I don't know how believable all of this is and if it is reality or just fear mongering. I also assume since it is all closed source, there may not be an easy way for someone to verify the truth behind such allegations? Ultimately, if this is true, I can see the value in making the switch to GrapheneOS despite losing E2EE messaging with the vast majority of my contacts. My threat model is nothing extreme, but I don't like the idea of Apple (and their partners) getting access to so much of my intimate data. From what I understand, using a program like mysudo may also be challenging on grapheneos as it seems to require installing google play services if you want call/message notifications (which I would need) as well as a secondary ios/android device from which to make payments and maintain the account.
Thanks in advance for any guidance!