I think the key for me is that, at least under the original Presidential Surveillance Program, the providers that participated were not compelled to share their user's metadata. They shared it willingly, regularly, and in bulk. There is reference to a service provider backing out of this agreement a few years later, telling the NSA they would feel more comfortable sharing the data if it were compelled.
It's not clear if this has changed since 2013. But assuming Mozilla, or Mullvad, isn't compelled to share _all of their data_ it seems unlikely that they would willingly give that up to a government surveillance program.
I think ISPs have demonstrated they aren't trustworthy. For most people in the U.S., it seems, finding someone more trustworthy than their ISP is literally anyone who isn't admitting that they collect and share their private data. I would be surprised if Mozilla doesn't clear this bar.
This is the explicit danger of VPN providers. Even if the provider is not complicit (which I believe applies to the likes of Mozilla), it still creates a centralized aggregation site for collection.
I'm not even sure a US-based VPN provider is safe. GCHQ just conducts the interception and would share the data with NSA. At that point, you are at the mercy of the NSAs locators being good enough to flag your tunneled traffic as "reasonably a US person" so it gets excluded.
Oh, I am sure that it is not safe, thanks to the PATRIOT Act. Even if they were not storing any metadata, VPN providers can be compelled to 1) share all data about their subscribers, which will include you, then 2) silently wiretap and decrypt everything. US courts will rubber-stamp, as they've consistently done in the past, and "that's all, folks".
Sadly it's not like you'll be much safer elsewhere: as soon as you step outside of the US, one of the strongest cybersec agencies on the planet (NSA) will have free reign on your traffic. But you can resist the legal attack (in some countries) and at least try to make it challenging on a technical level.
I hope Mozilla want to bring some innovation to the table that will make VPNs somehow more resistant to legal attack (not just in the US) but I doubt it.
From write-ups of the 2013 leaks, we saw references to violations of the legal theory used to justify the Presidential Surveillance Program. One of those violations was them unintentionally collecting the wrong data, due to how the ISP was bundling packets or something like that, which constituted a warrantless search, and they supposedly took that very seriously because it jeopardized the whole program.
My take on the surveillance program is that they try very hard to be law abiding, even if they have to stretch what the law means to justify the program. If you are worried they have a warrant for your communication, a VPN isn't going to help you. If they don't have a warrant, they will avoid U.S. citizen's content like the plague for fear of compromising the whole program.
Thus we only have to establish that the VPN provider is at least as trustworthy as my ISP. That's a pretty low bar to clear in many places. I have no doubt some VPNs are operated by nefarious actors (no better way to collect high quality data), but I don't think that's a concern with Mozilla.
Write-ups of the 2013 leaks revealed they did not compel ISPs to correlate traffic to subscriber information. It doesn't seem like they had any subscriber information in their database, only enough metadata about the communications to later compel a ISP to provide the subscriber information _postmortem_ (i.e. who did this cellphone number belong to on this date?).
ISPs weren't even compelled to share that metadata. It was a voluntary program. Some ISPs said no. Others said yes and then later backed out. In the end something like 80% of the traffic the NSA was after was able to be collected through the ISPs that voluntarily shared their data.
But, again, this was 2013. 2013 was forever ago, things may have changed.
Yes, now the NSA have a single point where data can be collected that would be much more interesting than at your ISP.
Even if you don't have a static IP, I suspect the entropy of your /24 (IPv4) is also a lot smaller when over VPN.