After a quit scan of the protocol and API outlined by Apple and Google: it looks privacy & technically sound to me.
I would remove the Android FAILED_REJECTED_OPT_IN status code (https://www.blog.google/documents/55/Android_Contact_Tracing...).
I cannot find it in the Apple API specs, but maybe it's not defined in there yet.