Your Google apps may be sandboxed but unless proper permission control is employed, it doesn't stop them from doing what they are designed to do.
Also any app employing Google libraries (and other trackers along with IPC and network access) for that purpose should be deemed as privacy unsafe.
And although GrapheneOS have have gone a looong way to address many issues, there are still many to tie and more appear by the day.
The more you restrict your working environment, the better for you. Sound impractical, but very effective and powerful.