The API/protocol is a good way of implementing the idea in a privacy-friendly way although I think everyone should have been clear that it is not as private as simply disabling Bluetooth or not carrying a phone. It is pretty benign. But being honest about that is important if for no other reason than to build trust.
However, the apps built on top of the API have (at least in some instances) clearly fallen victim of scope creep - eg the UK app came with venue check-in functionality (which then suddenly became legally mandated and there was no separate check-in app so you were out of luck if your phone didn't support the API or you didn't want to enable Bluetooth) and a function which tells you how "risky" your postcode is which you can't switch off. There was even brief talk about it being extended to include "vaccine passport" type functionality.
This was, sadly, predictable, and is why many people simply won't trust it.
The other issue with the app-based approach is that it sadly appears to be pretty useless. At least the UK app appears to notify for far too many contacts, large numbers of which are false alarms of one sort or another (neighbours, people sat in different offices, etc). While using Bluetooth proximity was a good idea, I think it's fair to say at this point that in the real world it just hasn't worked.