I understand that privacy is point of differentiation but on Android you can still load any .apk file on any Android device on iOS devices not so much.
You can install any .ipa on a iOS device you just need to jump through a bunch of hoops to get it onto your device signed in a way that will make it valid.
As long as you have an existing developer certificate or jailbreak the phone you can. You could use something like isign. https://github.com/sauce-archives/isign
Or altstore https://altstore.io/ which is literally a locally run alternative App Store.
Effective privacy protection means that app developers need strong incentives to follow strict rules. I for one appreciate that Apple’s approach of enforcing strict rules is a choice available to me as a consumer.