The Play Store provides many services used by apps including Play Asset Delivery, Play Feature Delivery, in-app purchases and license checks for paid apps. The Play Store app is also the most secure way to install and update apps from the Play Store.
Source: https://grapheneos.org/usage#sandboxed-google-play-installation
You trust GrapheneOS by using it then might aswell trust them when they say that Play Store is the most secure way of installing apps. If you create anonymous/throaway account with VPN or Orbot then it can be private too.