How to make sure a used custom-ROM phone isn’t malicious?
I am (hypothetically!) thinking about buying a used phone for sustainability reasons. I am also thinking about this being a non-Google phone for ethical reasons. There are some people in my country selling non-Google Android phones, most of them are somewhat custom flashed.
What would I need to do to be sure that such a phone doesn't siphon off my data and interactions?