Its not really meant for privacy. Its a great rom for keeping an old phone up and going but you should consider divestos or grapheneos if privacy is your main concern.
This is for security concerns, because all the firmware and driver are maintained by first party, so once the first party stopped maintaining firmware, there is no way for graphene to make the device as secure as a phone that is still in its support period.
At that point, you can try to switch to lineage to increase the life of your device.
That being said, graphene do offer extended support for some devices like pixel 4(XL) is still supported right now, but it made it very clear that it is "extended support", and it exist only to help user transition to their next device.
It is okay for privacy, especially if you dont have google app installed, but it is not security and privacy focused.
If you have google app installed I imagine it is probably as private as stock os on a pixel, but less secure. Graphene/calyx will definitely have better security and privacy than lineage with or without gapps.
But I understand there is other tradeoffs besides just security and privacy, like minimizng ewaste, cost, availability, etc.