People see this as an act of either carelessness or malevolence which both is unacceptable in an application that collects and stores very personal data on a large scale.
Apart from that the official (indeed publicly funded) Corona-Warn-App did a much better job at this. (They actually did follow all the recent best practices in software-develoment + it's (mostly) run as a free software project, taking community contributions seriously, reacting to feedback and issues, etc.)