Indeed, (encrypted) requests pass through SQS/SNS with credentials owned by us. We can see the amount of traffic, but not any of its contents or who sent it.
This would mean that the phone needs to be physically close in order to accomplish auth and I would think that's a good requirement based the premise of this app.
GitHub user agreement allows other users to view and make copies of your content on github but not for "free use" in general.
https://help.github.com/articles/github-terms-of-service/#5-...