Humprygraphyn When I'm in the secondary profile using VPN, what kind of traffic is coming from the primary profile?
All the regular traffic that would be generated by the owner profile with your regular usage will continue to generate the same way while you're using your secondary profiles. Nothing changes. You're just putting your "owner phone" aside to use your "secondary phone". Will the generated owner traffic go through a VPN? If your owner VPN connection is connected while you're in secondary profile, then yes. If it's disconnected, then it will be transmitted using your regular ISP connection.
Humprygraphyn I'm asking about the primary profile, because even if it remains unused all the apps installed in different secondary profiles are there
Are you saying you have the same apps installed in both, owner and secondary profiles (i.e. installed in owner, then "pushed" into secondary via Settings -> System -> Users -> <secondary_profile_name> -> Install available Apps)? If this is the case and you installed these apps in owner just for the purpose to push them to secondary profiles and you don't use or need them in the owner, then you can safely Force Stop them (on App Info page) in the owner, so they won't run. If you want to be absolutely sure they won't run in the owner, you can Disable them (also, on App Info page). Force Stopped / Disabled in owner apps will continue to work in secondary profiles as usual.
Or thanks to GrapheneOS you can just revoke network permission from the apps you don't want to generate any traffic in the owner profile (keep in mind, depending on the apps and your threat model, Inter Process Communication may still be a thing, here's an example).
Hope this clarifies it. Feel free to ask more questions if needed.