I think this is only correct if you use the VPN in GrapheneOS' default (non-stock) settings where "always-on VPN" and "block connections without VPN" is enabled.
Of you use split tunneling, you need to disable the second option, traffic will not go through the VPN, or at least the app will not tunnel it through the (mostly Wireguard) tunnel.
Not sure if the traffic then goes through the insecure DNS server advertized by your local router.