We are in agreement for the most part except #2, using Tor Browser Bundle in Whonix is probably enough for most threat models and using your own browser might actually harm your anonymity by making your browser fingerprint more unique.
Monero is more private than Bitcoin, and ProtonMail is sufficient for most use cases in my opinion