This. Don’t let the perfect be the enemy of the good.
I tend to think you can secure yourself some of the gains without rooting your phone, but it’s a lot of twiddling and an ecosystem swap.
I loathe apple, but if you’re not ready to dive in, your home devices are where I would start. Routers, modems, home PCs, learn how to set up encryption and redirection to put things behind. Ditch your roomba.
Edit; I did not mean to talk down, sounds like your on that train. Android is linux and adb is awesome (sometimes).
Keepassdx/xc and syncthing have been awesome, rise up has a decent free VPN client for public use in fdroid.
This is always a spectrum from how long it was since the last Debian stable release. So about 2 years max.
Modern release cadences make it crazy anywhere but Debian, but security patches are very timely. If you’re dealing with newer features, driver support or java/npm packages you’re probably also outside the typical defaults, but there’s generally some people working to keep the common ones up to date.
Still not my preferred way to handle updates and in some cases… kind of abusive to the maintainers who constantly haVE to deal with bug reports from “out of date” Debian users. The xscreensaver maintainer has some choice words. But it works, has for years with no sign of slowing.