I just gave up on smartphones altogether. It is much easier to make a laptop/desktop private instead and limit your private messaging and activities to it.
I have a separate KeepassXC database for 2FA. I guess my life experience is limited, but I am yet to encounter cases when this would be outright required. The closest one was Steam, but I used an Android VM for this.