a vpn doesn’t protect you if an app is compromised. vpn is just putting your device into another person’s or organization’s Network.
I am not really familiar with how android sandboxes apps but I wouldn’t trust my phone not being compromised after installing a potentially compromised app.
bitwarden/vaultwarden. currently the best experience for me. and youncan self host it