http://red.ngntfwmwovvku6eqi7dzzgzv2wzlvq2cqtqha7ccgzub2xnivsuxnuyd.onion/r/privacy
This is very important in my opinion, because on github this isn't true at all. So I don't really understand the constant dunking on fdroid. If a surveillance body wanted to, say, gain access to people's text messages on signal, I'd expect them to inject malicious code in the app repository, not hack fdroid's servers.