KDEconnect from FDroid also go similar warnings. Might be related or OPs app might really be fake. https://twitter.com/albertvaka/status/1712954968477401478
In theory you can willingly and securely share your data with an entity to track you. In practice GOS recommends to use Vanadium because it is more secure. But it doesn’t have the same possibilities regarding add-ons and cookie handling as Mull. GOS recommends to use the sandboxed PlayStore because it is more secure than F-Droid. But how do I get then some privacy respecting app alternatives like NewPipe. Also things like giving Seedvault less permissions make it more secure but less useful for a complete backup. Or not to implement a unified location provider (using privacy respecting local and Mozzilla backends) makes it harder to determine your location indoors.
That was interesting to read. I think privacy is a continuum, you can reach a lot with relative easy steps but it is very hard to reach 100%. So don’t get annoyed by the extremist views here.