VanillaOS is pretty neat. It has an immutable (kind of) OS, lets you choose which package formats you want to use (flatpak, snap, appimage, etc) and leverages containers (a la Distrobox) and their package manager Apx to give you seamless access to packages on other distros. It’s Ubuntu-based right now but the next release is switching to debian.
To be fair, I don’t have much time on it. My daily drivers are a chromebook and a steamdeck, but I did dust off an old laptop just to check it out for a little bit.
It’s mostly true, but not entirely. The data “on the internet” has to live somewhere. For instance, when you DM someone on a social media network-- would you consider that private? I assure you the content of those messages can be read by the website’s admin-users.
If you’re hosting your own non-social web service (like, personal cloud storage or something), then that is arguably private for you, but if you let someone else also use it, then it is not private for them, because you can almost certainly see their file content, having access to the server directly.
Encryption can throw all of this off; a service like Signal is private-- the admin-users of Signal can’t see your messages. Generally speaking any service that warns you that all your data will be lost if you forget your password is probably private. If they can recover your data, they have access to your data.
Edit: Better word choices.