We were just looking into this app package to decide where to go. So the app itself works well, however only in MQTT mode and here without encryption.
Further there is some concept of users and auth, but it realies on account duplication between nginx (for basic auth) and mosquitto. On top of this the actual frontend (the UI where you can see users and their devices) needs to be also protected. For that only the proxy auth in front of it is there, however that adds another layer of accounts (the accounts on cloudron) on top of the other accounts.
On top of all this, if device location wants to be shared between users, those have to share their password/secret or new sets of secrets have to be generated per "view". A view is a separate html frontend tailored to show ownly selected devices.
Given that there is also no UI for any of this, we will probably not publish the app. Too easy to get wrong and too many sets of user/passwords involved to be more than a geeky tool in my opinion.