GOS's intended audience are those who are in danger of being hacked or persecuted, not privacy conscious users trying to escape surveillance. Google, for all their faults, is pretty unlikely to hack your phone and reveal your secrets.
There's many privacy features that work to allow users to use anti-privacy apps like WhatsApp with more privacy. Contact scopes, storage scopes, sensors permission, network permission, VPN leaks fixed and enhanced secondary profiles.
Plenty of less scrupulous surveillance companies like Facebook take advantage of security flaws for their surveillance so it's important to start from a secure baseline to guard against this threat.
They (GrapheneOS development team) live and breathe the principled stance you seem to be describing.
They are staunchly against authoritarianism and mechanisms that are vulnerable to government coercion which is why they promote Android IAR and criticise Play App Signing for being mandatory.
I have understood their position to be that software is not automatically secure because it is open source, but being open source is one of the best ways to ensure to maximise attack resiliency (they believe in kerchoff's principle, shallow bugs, collaboration as a pragmatic help to get there not taken for granted or a guarantee). You'd probably be interested to know the founder once proclaimed publicly that they would never work on proprietary software.
Don't pay too much heed to how community members frame things, they are human and get things wrong in service of trying to reduce conversation to specific facts and technical assurances instead of discussing the bigger picture.