I consider my IP address to be sensitive information, so I wouldn't host a VPN on my home network, and there are advantages in numbers to using a popular service, since you can blend in at least a tiny bit.
I use a 3rd-party VPN (PIA). This is obviously not perfect privacy, since they could be lying about what data they store. That being said, I'm not trying to hide from a government, I'm trying to hide from advertisers, stalkers, and criminals. So even if I can't personally validate that PIA isn't storing any of my data, having my data accessible to a warrant is still better than having it accessible to hundreds of different sites and companies that I 100% already know I don't trust.
I validate actual implementation security by regularly checking what information shows up in requests when I visit sites. There are a couple of tools that help with that online.
Being strict about what data goes where is part of the reason why my data usage is low. It turns out that if you block network access for most apps on a phone by default, data usage just goes down a lot. Apps like Uber and Lyft make a lot of requests, because they are constantly tracking you, so blocking their network access if you have them installed is just a strict all-around win. Even apps that should be good about this like Google Music will sometimes just randomly decide to download things.
Obviously the librem phone is still kind of up in the air, but my game plan assuming it's not a complete disaster is to migrate over to that and fill in any gaps of functionality by just programming whatever features I need. I dunno how voice calls will work. The idea of switching to something more secure than the existing phone system is attractive, but I mentioned above, I'm not sure what it would do to data usage -- I just don't have any basis to make an educated guess.
In general I want my phone to be a very specialized device -- not a dumb phone, but a phone that only ever does what I tell it to.
So a successful migration for me would look like a company:
- with good coverage
- without any horrible terms like arbitration agreements or stealth charges
- that does not sell data, and that is supportive of low data-usage
- that is at least not actively unethical :)
on a device that:
- gives me root access
- makes calls, texts, and browses the web in a secure way
- that is highly geared towards offline availability and low data-usage
- and that doesn't run extra software or do things behind my back
Librem is my hope for the second part, I guess if it crashes and burns I'll look into custom Android roms. I haven't made a list of carriers yet, but from what you say, it sounds like Community Phone should be high up on that list?