Wanted to amend my response since I've looked into this a bit more.
I still don't see the data collection as egregious, but the update cadence (lagging behind Google's LTS release) does seem to be cause for concern. The OS being mostly open source is a plus, but the Android container being proprietary, while feasibly necessary from a business standpoint, does raise concern given the size of the attack surface there. Also, lacking secure boot (for the sake of hardware compatibility, perhaps?) makes a difference.
Ideally, I'd love to see these points addressed as the OS was fun to use and fits my use case.