Sadly, I am not sure you will find a default private environment. There are many things you can do to improve your privacy, but almost all of them require action rather than selection. "Hardening" is probably the right search term.
Given what you have said, I think any Linux environment will be fine for you and will result in immediate, significant privacy gains. All security is a trade off for convenience. If you want a more secure environment, you should expect a less convenient environment. I would choose a popular Linux environment. All of them are probably the right tradeoff.
That being said:
Without focusing on observability first, you end up with a lot of unknown unknowns. You might not think installing a home brew package on MacOS as something that violates your privacy, yet many will reach out to google for various artifacts, if not directly reporting analytics themselves.
You will not get (good) privacy without a whitelist rather than blacklist environment.
Paradoxically, modifications you make to your environment or using more bespoke environments can make you more easily identifiable. Eff runs a great website breaking down how finger-printable your browser is:
https://coveryourtracks.eff.org/
As for priorities.
A good OS choice will help you most from nation-state actors. So if your threat model is a government (as opposed to capitalists or hackers or scammers etc.), then Linux is the best choice.
Tuned Firefox is probably the best browser choice. You will want to find a guide on how to "unfuck" the default settings. uBlock is non negotiable. PrivacyBadger and Decentraleyes are good plugins as well.
After Firefox setting up a PiHole will offer a lot of privacy protection for minimal investment by essentially being a DNS firewall.
A RaspberryPi is cheap and a fun tool. I totally recommend setting a RaspberryPi up with PiHole. After PiHole I imagine you could install MITMproxy on it or other interesting tools that would build in observability.
> I don't agree with this statement.
User data being used to power features is generally not what people would consider telemetry.
While you are absolutely correct about how search suggestions etc work, that is not what I would consider telemetry. Telemetry is specifically data like crash reports, which can and sometimes will upload memory dumps that can contain plain text passwords or private keys that were loaded into memory.
I promise you telemetry helps reduce downtime significantly. Telemetry itself is not evil, it is companies and how they use it that can be evil. If no one submitted telemetry it would make running stable services much harder. In a sense, the people who do submit telemetry are subsidizing you. I also almost universally shut off telemetry, but if everyone did that, it would definitely be problematic.
Siri (or alexa, etc.) learning from your apps, sucks in just about everything you do on your phone, letting siri run wild likely greatly breaks privacy. Your phone keyboard can remember things you've typed or proper nouns you've used. Spotlight (or other file search features) will open and "understand" every file on your computer then index them so they are searchable. Virus scanners hash every file on your computer, then check to see if the hash is in their "evil" database. It doesn't take much imagination to see how, for example russia's kaspersky virus scanner could abuse that (or any other).
> I don't currently have the tools (much less the money or equipment to set up an off device firewall)
Buy a RaspberryPi and set up a PiHole. Something like this:
https://www.adafruit.com/product/3775?src=raspberrypi
Amazon has kits that provide the power cords and a nice looking protective case for probably $50 usd.
It does not take much power at all to run firewalls/piholes/etc.
I am sure there are plenty of approachable guides.
> This is something the average person simply cannot do.
I think it will have challenging moments but ultimately be much easier than you expect.
Summary:
Any linux distro, choose what feels best to use
Firefox, follow a privacy guide to configure "about:config", install uBlock, PrivacyBadger, Decentraleyes
Buy a RaspberryPi, set up PiHole
(bonus) Set up a sane firewall on your linux machine or on a different machine
(bonus) Consider setting up mitmproxy
(bonus) Follow OpenSnitch (https://github.com/evilsocket/opensnitch) and consider trying it when you feel it is mature enough