It should be self-evident that neither of these is "secure" for some level of "security", but they might be perfectly fine for the level of threat that you face, which is not likely to be particularly high. But I don't know you, so maybe you face a higher-than-average level of threat, in which case, yes, a sufficiently long password/passphrase that you memorise is probably the best option for your mobile device.
Eventually they may become easy to copy, then their utility as secrets will be gone.
If your goal is not having the punk who grabs your phone be able to get access to your banking info or personal data, any competent biometric system is a huge win if it means that the average person keeps their device locked rather than unlocked because it's too much trouble.
If you're worried about mass surveillance-style attacks, a fingerprint sensor or advanced face scanner is likely better than a password because it's significantly harder to harvest using a camera in a public place.
If you're being targeted, all of those trade-offs change, almost completely if state-level resources are involved.
That's always been the case. The main promise of biometric security was not "better security", but better convenience. The best argument for it would be that it makes average security better, in the sense that more people use it than not use anything at all or re-using passwords, but it's not the best way to secure your devices.
Password manager + U2F token is the most secure way to lock your accounts.
Someone could just hold a gun to your head or to your partner/child and then it's irrelevant what the security mechanism is. You are going to hand over the credential since your privacy is not more important than your life.
The issue is convenience together with good enough security
In the real world, effective biometrics are the most secure login tokens we have.
PS: I read that some community firmware images allow this mode, the only thing that stops me from using them is lack of camera drivers for unofficial firmware.