With sandboxed google play services installed, the app compatibility should be nearly on par with stock Pixel OS, except some Banking apps and a few other apps enforcing strong play integrity. Many apps will also run fine completely without Play Services, but YMMV.
The apps you install, for example Instagram and Spotify, can still track you through their algorithm, the files you upload or give them acces to, IP address (unless used with VPN or TOR), etc., but thanks to features like storage scopes and contact scopes you can better limit what files and contacts on your device the app has access to. Also through the extensive security hardening the GrapheneOS devs implemented, you will benefit from running such apps on a GrapheneOS device no matter what.
Regarding android auto I can't speak from first hand experience since I never used it, but as far as I'm aware it should mostly work with sandboxed google play services (with the exception of few cars that use a non-standard implementation I think. You'll likely find better answers to this by searching for "android auto" on this forum).