

It really depend on your threat model, Proton Pass is fine. Of course a self-hosted or local solution will be more privacy friendly but at the cost of being responsable for security and good backups (3,2 1 rule).
There is no black or white regarding privacy. You want to ask yourself what you want to protect from and is the investment worth being sovereign ?
Install GrapheneOS (consider this device as insecure as Google dropped support) and some minimalist launcher such as Olauncher, Unlauncher or mLauncher through Droid-ify (or another F-Droid client of your choice) or directly from source. You can also install digital wellbeing apps such as Mindful, DigiPaws, GreaseMilkyWay or Regain (that last one is proprietary and is available on PlayStore (or AuroraStore)) to help you have better control over app such as YouTube.
For YouTube you can also install some FOSS client such as NewPipe, Tubular or PipePipe etc…