-snip- but does this mean anyone using QT as their wallet is leaking info about their transactions, or this is limited to “light clients” which Sparrow acts as on top of your node?
Not particular to GUI clients, it's due to how SPV wallet works.
Sparrow for example, has an option to connect to public Electrum servers if you haven't set it to connect to your own server or Bitcoin client.
Since those are owned by a third-party, you wouldn't know if they're spying on your addresses and transactions.
But not all light clients have terrible privacy, those that are utilizing BIP-158 (
Compact Block Filters) should have a pretty good privacy,
although not as good as using your own server/node.
BTW, you can directly connect your Sparrow to your Bitcoin Core if you don't prefer setting-up an Electrum server.
The options in Sparrow's network setting should be self-explanatory.