Maybe the open source apps could be lying about their source code? For an example, put a version without trackers while the one they use have trackers?