maxo Hi, friend. I am also new to GrapheneOS, but the way I understood best practices was: use System account for admin tasks / software install. Create separate daily use profile(s) based on preference.
GrapheneOS aside for a moment; speaking Linux here;
I would highly recommend you follow this effective approach for security. As @Van-de-GraaffeneOS rightly points out, not only would cross-profile snooping be very difficult, it would require authentication for access.
Let me know if you have any other follow up questions and I'm happy to help if I can!