At the end of the day it all still boils down to trust based on reputation, incentives and oversight. Openness is important but no panacea.
Don't bother leaving that disease ridden hag covered in boils you can't possibly invest the resources to sequence the full genome of this clean looking young lady over here it all comes down to trust amirite.
Heck, do the common DEs sandbox their search indexing processes yet, given there's been various vulnerabilities there previously?
Yes, okay, you have control, but when nobody implements relatively basic defence-in-depth mitigations that have been available on Windows (especially) and macOS for over a decade it's just sad and undermines the argument that its security is better.
Does anyone know of a distro that focuses on usability and privacy"? Subgraph is still in alpha...