It's a decent smartwatch and works quite well with GrapheneOS via the Gadgetbridge app.
The operating system it runs is called Infinitime and is based on FreeRTOS which is an OS designed for the SUPER low powered processors in devices like the PineTime. It's so low powered that it is nowhere near being able to run anything like Android or GrapheneOS. The advantage is that the super small battery lasts almost a week.
As far as privacy/security is concerned, it's all open source and community developed, so neither it nor the companion app Gadgetbridge is going to be doing any weird spying/data collection. However, it's important to note that since it is a Bluetooth device, it broadcasts it's Bluetooth MAC address (which is not changeable on this device,) so in public you could be tracked by Bluetooth beacons. It's a personal decision on whether the privacy risk is worth it, but if you're going to use a smartwatch anyway, it's a good one.