You're not really trusting them with any info that isn't hanging out in public already:
"This app uses public APIs to fetch potential people you can follow on Mastodon. In fact, it only does inauthenticated network requests to various Mastodon instances."
I'd imagine there are probably lots of people out there trying to scrape various instances and build up giant social graphs of Mastodon users, this one just lets you see your own.