DoublingHelpful Could I confidently tell an adversary that a certain app is indeed installed on a separate profile, but I don't know the password to that profile and haven't used it in a long time?
Personally I would not assume anything like that -- I would want to do a fair amount of experimentation and analysis. Offhand I don't think inodes are encrypted, which may mean it's possible to tell when files in a user profile were last updated.
I think it's important to keep in mind that Google's implementation of user profiles does not appear to focus on protecting secondary profiles from the owner profile, and does not provide strong privacy guarantees.
It is clear that people would like stealth profiles, partial duress PINs, and hermetically sealed user profiles, but none of those things are easy to get right, and so far the GrapheneOS project has been opposed to implementing privacy measures that work only against weak adversaries and thus may confuse people into taking unprotected risks.