Nothing, absolutely nothing prevents from doing open-source surveillance. Specially server-side and where the package manager (f-droid application) fetches from the same server and that android devices are easily fingerprintable (most will happily tell you the model in the user-agent for example).
@lanodan@Tommy meanwhile mentioned aurora store just provides anonymous access to Play Store(that's probably forbidden by Google's ToS but who care?)
It's opensource. But it's a client to a proprietary services. And yes, nothing stops to archive an access logs even in full FOSS. I guess they call it... "telemetry"? :)