

Both signal and molly are considered safe, a lot of apps use the same protocol as signal, most risk come from messages leaks before the encryprion happens.
Unfortunately, I’m not aware if they did external audits, but both codes are available in github.
I’m surprised that people consider Aurora store inferior to PlayStore. I’m not familiar with k-anonimity, but you can run aurora through a proxy.