Also your argument about a user inspecting and editing application files feels like a strawman argument. For example many spyware use malicious links to infect the devices, not malicious apps.
Also you are misrepresenting the threat model. The problem is not an app deleting it's own legitimate data.
P.S. On GrapheneOS you can block apps from getting Internet access to limit their bad ideas.
Also your argument about a user inspecting and editing application files feels like a strawman argument. For example many spyware use malicious links to infect the devices, not malicious apps.