A threat model answers four questions: What am I protecting? Who am I protecting it from? How likely is a threat? What are the consequences if protection fails? The answers determine which tools you use, how much effort you invest in OPSEC, and where you can reasonably accept risk.
Without a threat model, people either do too little (using Tor Browser but logging into their real Facebook account) or too much (using Tails on an air-gapped computer to browse cooking recipes). Both extremes are counterproductive - the first provides false confidence, and the second creates friction that leads to abandoning security practices entirely.
Your threat model is personal and contextual. A journalist in a democratic country has different threats than an activist in an authoritarian regime. A whistleblower has different threats than someone who simply wants to avoid targeted advertising. Build your model based on your specific situation, not on generic advice.