The most important security for normal person is keeping the device offline. You can have ten diffenent locks on your door, does that make you feeling safer?
If you can prove that the expensive Trezor has higher industry standard than popular phones, then you win.
Exactly! You can have 10 locks on a device that has the ability to connect and it eventually will connect. Bither lock can't protect you. Only the device that can't leak keys by design can keep private keys inside.
You are right that people trust their phones with some personal data. The security of a phone is good enough to store your FB password, but I won't trust it with my live savings.
How does your app get in the phone if the phone never connects to anything? How do you update your app? If the phone was infected before your app was installed, how can you be sure that it is not communicating?
Security expert can verify simple single purpose communication protocol of Trezor and its code base. No single person can verify Anroid.