If you were super-concerned about telemetry, you would want to disable automatic updates - because by doing updates you are telling Purism exactly what packages you specifically have installed and what versions etc.
However obviously that is a major security trade-off. If it makes it less likely that you have all the latest security patches then what you may gain in privacy from Purism, you may lose in privacy to some hacker.