Earlier quoted context omitted.
I'm guessing they used some framework and the libraries they used ask for a broad set of permissions because they offer access to their functions. But they're not necessarily used. Also considering they're asking for a permission for a protocol that was shut down 7 years ago, the framework must be quite old. Android permissions were less granular back then. I know someone in Germany and their covid tracking app tells…
It only tells you on which day you had "one" or "multiple" contacts with "low" or "high" risk. It's Bluetooth based, and the CoronaWarnApp doesn't even access location data. See https://www.bundesregierung.de/breg-de/themen/corona-warn-ap... "Data which can make a person identifiable, in particular location data, is not selected, used or stored."
Too bad I can't edit the original comment any more.
Never trust friends :)