For your points 2 and 3 specifically: if you go the Icecast route (AzuraCast also uses Icecast under the hood), Icecast can require a username and password per mount point, so the stream URL alone is useless to anyone who stumbles on it, and you can give the mount a bland name. Put it behind HTTPS on your reverse proxy so the password isn’t sent in clear text.
For point 4 (genres at certain times), AzuraCast’s playlist scheduling handles that from the web UI. If you build it yourself instead, Liquidsoap can switch playlists by time of day, but it’s a scripting language with a learning curve.
If what you really want is your own library rather than one stream everyone hears at the same time, the Navidrome suggestion is simpler: separate logins and plenty of Subsonic apps on Android.
The phone-shop detail is the most alarming part for anyone at risk there: a device compromised before you even switch it on defeats most of the usual advice. For journalists and activists in that position, the practical baseline is buying devices from a large retailer or outside the country rather than a local shop, keeping the OS fully updated, and on iPhone turning on Lockdown Mode, which was built for exactly this kind of targeting.
Amnesty’s Security Lab also maintains the open-source Mobile Verification Toolkit (MVT) for checking phones, and Access Now runs a free digital security helpline for civil society if someone suspects they’ve been targeted.