overpass
Your other questions really do depend on what your threat model is. I do not know how extreme yours is but in general my opinion I would
Use Vanadium browser to log into what I need for as much as possible without depending on installing apps. There is even a PWA (progressive web apps) option to have icons on your home screen.
If you absolutely most install an app try the Aurora Store. Maybe even the official webpage download in some rare cases for instance to have IVPN apps option of utilizing the Facebook and Google blocking Hardcore mode DNS. The play store variation of IVPN does not include this for reasons that might be obvious. Also another example is Signal apps notifications that can work without google frameworks services. There are pros and cons to choosing between aurora store and official website as well. Play store (aurora store) has their own security checks for apps I have read.
If google is not your threat model you could even use playstore however I personally dislike account IDs and seems like you might as well.
I don't use f-droid and probably won't in the future
I recommend the below read to get familiarized.
https://wonderfall.dev/fdroid-issues/
As far as the no sim in the phone is concerned, perhaps keep your phone in airplane mode and only use WiFi/Ethernet depending on severity. Maybe get an LTE portable router to put a new more private sim into it when you are out traveling to keep your phones IMEI from pairing to a sim. Also use a trusted always on VPN of course to mitigate a little of the other stuff.