False (except for less packages, that's true), false, the amazon incident was a honest mistake and only applied to the search bar in unity (even more specifically the amazon lense), and no data is being collected unless you enable it during the install. https://youtu.be/rdPt8WB1lZw
Also are you serious? A rolling release distro with automated package builds being more secure? Last time I checked Tumbleweed got affected by the XZ exploit.
It's sad because it's a genuinely good distro. Linux wouldn't be anywhere without it yet all I hear is people parroting the same misinformation they heard.