As per @mjk I would not recommend using free, public wifi either.
One core security assumption of Umbrel is that the local network you use is secure. From the github repo:
Assuming the local network is secure
Umbrel currently makes the assumption that the local network is secure. This means local network communication is unencrypted using plain text HTTP. (Remote access via Tor is encrypted)
Anybody that uses the same wifi will be able to access ‘umbrel.local’ to try guess your password or SSH into your Umbrel device.