That depends on if the author has manually integrated Mapbox (via issuing their own HTTP requests) or just used their SDK in which case the SDK may do whatever the sandbox allows.
And has been mentioned a few times in the thread - even if one app author goes out of their way to reimplement the API in a privacy-preserving way, all it takes is one that doesn't to reasonably link all the other requests based on other data points. (IP would be more than sufficient - but since it's a location service, even if all the apps run the requests through a proxy, location-at-time and location/destination pairs are also useful to help link.)
In the end I don't think there's anything privacy-conscious app developers can do other than eschew external services as much as possible, clearly inform users when external services are used, and push for stronger regulation (from phone / OS manufacturers and the government) about data privacy.