User profiles can be fully encrypted at rest while the primary profile is at use.
Isolating certain usage you do not want decrypted, like for example running Blockstream Green to interface with a hardware wallet, makes a lot of sense.
Even if you were apprehended and your phone was on, and somehow they could get into the running primary profile, the user profile would be protected by strong encryption.