Firefox automatically updates to install new privacy-abusing features like this one: https://news.ycombinator.com/item?id=40974112. So getting all the settings right once isn’t enough—you need to be constantly vigilant.
Like you said, a fork is a much better option, since they take care of stripping out the user-hostile nonsense for you. I like Librewolf.
I’m not sure of the specific case numbers but searching brings up many sources, e.g. https://www.cnet.com/news/privacy/fbi-taps-cell-phone-mic-as-eavesdropping-tool/ (2006)
Matrix and XMPP don’t hide metadata (who you’re talking to, when, and how often). This is OK if your users are all on the same private server that you self-host/trust. But in practice most users will be on the Matrix equivalent of Gmail, and you’ll be sending this metadata to the largest server in plaintext for every conversation involving one of those users.
I also have trouble where iOS “instant” notifications in SimpleX aren’t delivered–hopefully this gets fixed.
K-9 mail is literally Thunderbird. It’s been rebranded and taken over by Mozilla. They’re keeping the k-9 branding as its own (otherwise identical) app as a nostalgia token for the people that have used it for a long time.