Its not really meant for privacy. Its a great rom for keeping an old phone up and going but you should consider divestos or grapheneos if privacy is your main concern.
This is for security concerns, because all the firmware and driver are maintained by first party, so once the first party stopped maintaining firmware, there is no way for graphene to make the device as secure as a phone that is still in its support period.
At that point, you can try to switch to lineage to increase the life of your device.
That being said, graphene do offer extended support for some devices like pixel 4(XL) is still supported right now, but it made it very clear that it is "extended support", and it exist only to help user transition to their next device.
It is good for privacy as long you do not install Google Play Services and also do not download any apps that is bad for your privacy. However GrapheneOS is a better option which additional security benefits.
Yes, this is the crux of LineageOS. There is a fork called DivestOS that is more libré and reduces dependence on Google services, as well as having bootloader re-locking for some devices.
It's more like a way to make your devices insecure by unlocking your bootloader, disabling Verified boot and letting all kinds of malware persist on your device as well as allowing anyone with physical access to your device to modify the system partition and load malware onto it.
Those things could happen. ..maybe, or you could of course cut out the middleman and let Google install a rootkit they call Google play services and guarantee a lack of privacy and security.
You can't rely install that. There can be microg (not sure if it's in the distributed rom), but there is no system integration with microg, so G apps cannot work. Neither a lot of apps based on play services.
Microg however offers a modified LineageOs rom where they have installed the system integration for micro G. On that rom, the G apps and apps requiring G services do work.
Maybe it could be a bit more privacy friendly than using the direct Google services, but it still connects to Google to get some services for some apps.
It's pretty good for privacy, the main issues with LineageOS is that it's often less secure than the stock OS, as long as the stock OS is getting updates.
It's only less secure in a rare circumstance that a bootloader compromise happens by theft or advanced malware. If you're not doing stupid stuff on your phone you probably won't get advanced malware on it, and most thieves probably don't even know what a bootloader is, so IMO the security is good enough.
So the practical benefits of improved privacy and removal of bloatware etc are a much more significant benefit over stock android. I won't use a phone with stock android at all after getting used to Lineage and Graphene
From what I get, if your phone is anything other than a Pixel still within supported lifetime, then LOS is decent. At that point it's mostly a hardware tradeoff (use a phone that all of has active lifetime support, is bootloader-relockable and has Custom ROM support) than a software one.
It's good as long as you don't install Goole play services but doesn't have some of the extras privacy centric roms people will recommend you (only usable on a Google Pixel) have.