Das Problem mit Binaries ist, dass Deltas schwierig sind. Heißt bei git commits von Binaries mit kleinen Änderungen wird bei vanilla git trotzdem die gesamte Binary erneut hochgeladen. Das kann bei x Updates für y Kunden schon schnell aus dem Ruder laufen.
Gibt aber diverse Möglichkeiten, das Problem zu mitigieren. Hier eine kleine Übersicht.
Oder auf oldschool ne schnöde SQL-Datenbank mit nem optionalen buntem Interface. Da hast du das Problem mit Duplikaten bei korrektem Design nicht, alle Anforderungen abgedeckt und ist im Zweifel auch schnell selbst gebaut.
Mullvad certifiably doesn't log. Their VPN infrastructure even transitioned to RAM-only a few months back. They've been raided by the police and nothing was confiscated because there was nothing to confiscate. Obviously they have a list of registered accounts and payments, but without any connection to - well, connections.
I get what you mean though and mostly agree: There are only a few providers I trust enough to shift said trust from the ISP to them.
As mentioned in the comment you replied to: Yes, trusting a third party is a compromise. But you are also trusting a third party when renting a server for a private VPN endpoint, as well. A third party provider with probably a lot more logging going on than a trusted service such as Mullvad. While being way more exposed.
Since TOR isn't feasible for most users 24/7, trusted commercial VPNs are the next best thing when the alternative is your ISP logging everything you do.