In my experience, apps can figure out a lot more about the user, than a Web site.
I just reported a game to Apple, that, after the app has been resident for 24 hours, pops up an unescapable modal to sign into their Web site. I am sure the 24-hour delay, is so they don't get caught by the App Store folks. I suspect that what happens, during this "daily checkin," is that the app sends a bunch of encrypted data that it got from your device, to the servers in China.
Basically, they can learn more about you from the app, than from the Web site.
I generally avoid apps, where the Web site will do. I won't install banking apps, at all.
What information do you think they got from your device other than what you gave them permission to have? If you actually have any info on how apps can break Apple's sandbox to leak your personal info, you should share it.
Have a great day!