I don't understand the Android permissions system well enough here, but I would be especially curious about which API version this is targeting as I don't know how far back you can still go currently to avoid some of the stricter file access permissions newer versions added. As far as I can tell the most problematic storage-related permission in modern Android would be "MANAGE_EXTERNAL_STORAGE" meant for apps like file browsers. And if the app actually requests this permission (or intentionally uses an older API level to get equivalent access) that would be a very clear and specific overreach.
But I would also not be surprised at all if this kind of app asks for excessive permissions, and then provides a lot of telemetry and analytics and sends them somewhere. And in a country where e.g. homosexuality is illegal this kind of stuff presents additional dangers beyond compromising your privacy.