I have a similar setup. In addition:
Notifications - Off
Wifi Data Usage - Off
App Battery Usage - Off
(for apps that can install apps --Accrescent and Vanadium) Install Unknown Apps - Off
Extended Virtual Address Space - On
Webview JIT - Off
Dynamic Code Loading via Memory - Off
Dynamic Code Loading via Storage - Off
However some apps crash with the DCL turned off. So, for the ones that crash I turn back on.
Under "Security & Privacy"
Device Unlock
I use a password to unlock instead of a fingerprint for main profile. Other profiles I add finger print for quick unlock.
More Security & Privacy
Notifications on Lock Screen - Off
Show Media on Lock Screen - Off
Allow Sensors - Off
Save Screenshot timestamp to EXIF - Off
Wallpaper is black
I use a mobile router w/VPN
For the GliNet Mudi mobile routers there is a certain configuration that I add into the router. Which gets rid of useless packages.
I run the following command: opkg remove gl-bigdata gl-cloud-ui gl-ddns gl-gps gl-mqtt gl-rtty gl-s2s gl-siderouter gl-tertf \ gl-traffic gl-upload mqtt rtty-openssl
Vanadium
Clipboard and Your Device Use are set to Ask First
Everything is blocked except Sound.
I have exceptions written for JavaScript for websites I need access to.
Also, "On-Device Site Data" turned off gives me issues with sign on with some websites. So I turn that on as needed.