I'm using onyx devices myself. I'm sure they're not secure, but on my leaf2, I have it rooted, and I whitelist apps through afwall+. So no apps can send stuff out except when I want them to. I basically only have termux on the whitelist, so I can run my sync script for the koreader folder.
On my Ultra C Pro, I don't have it rooted, but I have rethink on it with a similar strategy: Everything has to be whitelisted by me. I use ironfox for web surfing and termux for syncing again. Rest is pretty much denied.
The only issue with this is that you can't update them. And since onyx stopped releasing firmware as zips on their homepage, I would not recommend getting them at all.
If you're serious about a nice ebook reader, I'd recommend something like a kobo libra 2, and directly flash koreader on it. I think you should be fine like that.