About the Windows gaming machine, you can surely build one just for gaming; just never put any personal data on it, never use it for surfing or doing anything that is not gaming, never give it any unfiltered access to your LAN, assume it contains malicious software then put it on dedicated Ethernet port on the firewall, setting up rules that allow only very restricted storage sharing so that it can't read or write anywhere but directories set up to contain exclusively what one would want to be readable/writeable by that machine.
Yes, it's a nightmare, but I don't see alternatives, save for giving Windows the middle finger for good also wrt gaming, which might end up easier than expected given the recent development with Proton and DXVK.