Honestly I’m not technically knowledgeable enough to answer, you can have a read of their FAQs. But my understanding is that the sandbox allows some google services to be used, but without privileged access to the rest of the system. As opposed to blocking them entirely, which would mean you couldn’t use those services at all. https://grapheneos.org/usage#sandboxed-google-play
I had an NC100. I used to write BASIC games on it. Fun device, very limited obviously but super cute with a nice keyboard. Good times