I have read that blog entry and some of its references. The evidence provided for this strong claim seems to be very weak. I would not judge anything based on the listed talking points. Now, knowthing is impossible and such services are sure in the interest of governments around the world. I also want to remind people on the Swiss Crypto AG which sold compromised analog encryption machines for decades.
KDEconnect from FDroid also go similar warnings. Might be related or OPs app might really be fake. https://twitter.com/albertvaka/status/1712954968477401478
In theory you can willingly and securely share your data with an entity to track you. In practice GOS recommends to use Vanadium because it is more secure. But it doesn’t have the same possibilities regarding add-ons and cookie handling as Mull. GOS recommends to use the sandboxed PlayStore because it is more secure than F-Droid. But how do I get then some privacy respecting app alternatives like NewPipe. Also things like giving Seedvault less permissions make it more secure but less useful for a complete backup. Or not to implement a unified location provider (using privacy respecting local and Mozzilla backends) makes it harder to determine your location indoors.
I was reading somewhere Android is not encrypting the storage whit lockdown, only biometrics are disabled.