What about Potentially Unwanted Applications? I've downloaded a few through Playstore that looked legitimate until Bitdefender warned me about it after installing.
I have also on numerous occasions download apps from the Playstore for which Bitdefender warned me that the app leaks personal information, like phone number, device ID, email address etc.
If there is one anti virus app that I will always use on my phone then it's Bitdefender.
I always read user reviews before installing an app and the rating must be over 4.
If the apps are harmful, Google will remotely uninstall it - you cannot stop it.
It's very difficult nowadays not to give some information to an app requesting it, like Facebook or Google+. At the bare minimum, they have your Google email account. But I always comfort myself that if the app has been installed by more than 20 million people, it's a bit difficult to sift through all that data - you will have to employ a lot of people and the risk that people will stop using your app if they find out you're using their personal information.
There are actually security companies, including Google themselves, who constantly monitor apps for using excessive permissions. I think it's actually flagged when the app requests a lot of personal information.
I have never installed any anti-virus app on any Linux machine I've used before, including Android, as I feel these companies apps actually want to get you to install their app on your computer as well, and then pay a subscription.
Also, their app has access to most/all of your information - what if they start using it?