There may be holes in this but:
1. |Router| -> Wireguard / OpenVPN -> |VPS|
2. |Device| -> Wifi -> |Router|
3. |Device| -> app -> |Mullvad|
= |Device| -> |VPS| -> |Mullvad| -> Internet
Can do various mixing and matching if you have more than one VPS. Again, it rearranges rather than removing the vulnerabilities, and it's pure window dressing against an organised, financed actor.
I've done this as an intellectual challenge more than anything else.