Apparently getting served injected ads by one public WiFi hotspot was what it took for me to set up a WireGuard endpoint on one of my VPSes and configure my phone to use it when on untrusted WiFi.

