I should've been more clear: they don't necessarily do the same thing for squeezing value out of open source users that they do out of Play Store users.
F-Droid makes sure they can build the code themselves, but I don't think they vet everything the code does. And Android permission model doesn't control network use well.