In fact, it requires attestation: even if you install Google Play on some Android in an emulator/container/VM, on an alternative Android distro or in a rooted device, the app will not accept it.
Wth. Does it at least have the decency to use aosp attestation? Or are they just happy to give the keys to the kingdom to Google and require Play Protect?
GrapheneOS guy went on a very extensive rant on Mastodon when someone wanted to create an independent, European, list that could be used by apps to verify attestation. They want apps to hardcode theirs specifically.
Which makes sense for them - after all, that makes their competitors break and their ROM doens't.