Which OS for private secure internet browsing PC?

Native packages and Snaps are fine. Flatpaks not. Flatpaks block the namespace+chroot/pivot_root sandbox layer.

Brave recommends against using their own Flatpak version:

We currently recommend that users who are able to use our official package repositories do so instead of using the Flatpak.

Modern browsers have a multi-process architecture, with sandboxing around the important processes, for example renderer sandboxes, gpu sandbox, extension sandbox and so on. This way you can make these sandboxes much more tailored and thus stricter than you would be able to do around the browser as whole.

Install them not as a flatpak. That’s independent of distros and doable on immutable ones, too.