I'll either have root xor GrapheneOS, in case any suggestions depend on that. Which phone I buy depends on whether @GrapheneOS can be useful here
Btw, DNS blocking (e.g. hosts file) isn't a good option because:
- That can't be done per app, and some apps require access to Google APIs where others (like Signal) don't
- I assume many trackers will just fall back to IP addresses since it's trivial to do