IIRC, ideally, dump main from diags and diags from main (to make sure the source partition is unmounted when dumping).
c.f.,
this trusty old wiki page for examples.
In terms of sensitive data, the rootfs partition themselves should be safe enough, IIRC, only varlocal & the userstore can potentially contain user/device secrets.