Datasapiens If I opened Facebook and posted all of my passwords, and the OS can't protect me from that, would it be fair to complain?
It's the same concept.
Play Services have no invasive access. If an app does not voluntarily share data to Play Services, then Play Services won't have access to that data.
If you don't want to be surveilled, don't voluntarily give untrustworthy apps sensitive data. GrapheneOS isn't going to magically make an untrustworthy app trustworthy like you seem to think it should. You have to actually choose services that are trustworthy.
If you're so concerned about a backdoored keyboard, then use the built in AOSP keyboard.