How legit is the concern that when you’re using a VPN instead of your ISP tracking everything you do instead the VPN provider that all your traffic is going through tracks you instead?

Idk, I used to care. When I did I had Proton VPN on the router, a Linux OS connected through Tor with a bridge and 100 digit passwords for everything that were encrypted to some key pair stored on some usb somewhere, and that key pair needed to be unencrypted by another key pair on another usb. And honestly idk if any of that even did anything But it did made doing everything way slower so I don’t do it anymore.

Do still use the Linux based OS though.