This isn't really true. Zcash isn't private by default, which weakens the concept for anyone who wants to use the privacy features. If not many people are using them then analysis of the transactions that are meant to be private becomes easier.
Zcash is also not trustless because it requires the trusted setup. You have to trust that the developers completely deleted the "toxic waste" during the setup, and that their machines were not compromised (which is totally possible given Meltdown, etc). Recovery of this toxic waste can lead to unlimited coin minting. Another problem with this is that future changes to some properties of the currency require another trusted setup.