That's incorrect, the verification happens fully locally. The check app occasionally has to update trusted certificates but otherwise it runs locally. No personal data is sent to any kind of server.
If it even matches the source as is. Play Store and App Store are non reproducible.
Obviously there's a risk that the person scanning the QR code does shady things with it but it's rather unlikely the app itself will. It would be caught really quickly.