Google is like a feudal lord. In exchange for owning you, they'll protect you from everyone weaker than they are. Google doesn't want to break into your office computer as long as they can shovel ads down your throat. And their reputation for security is much higher than a small startup regardless of the startup's competence and intentions. See e.g. Project Zero or Chrome vulnerabilities vs Firefox.
The best part is that I don't really need to trust Purism, I can choose to trust the community instead to whistleblow if Purism breaks the community's trust. Their target demographic is exactly the type that will be watching over their shoulder to make sure nothing fishy is going on.