This. This phone is a joke. I appreciate the effort in trying to patch up that raging security disaster we call Android, but the real problem in any phone is the propietary baseband running on some RTOS with little in the way of process isolation (or security conscious programming, for that) connected to a high bandwidth, always on wireless communication interface speaking complex protocols designed by a committee with an endpoint run by companies that have been happily complying with mass-scale surveillance, mere packets away from direct access to the microphone and GPS chip, possibly a DMA directly into the application processor.
Oh, and that neat little micro SIM you put into it? It runs fucking Java and has carrier push support for new "applications" builtin, in the meantime it stores and generates the crypto keys used by the baseband.
This is the state of mobile security. Unless you are running osmocomBB on a crusty old Motorola brick with a logger between the phone and SIM to check for anomalous activity, don't touch it with a 3m pole.