For the cats saying they don't use the app and all, that's all good. Continue to swipe, insert or use cash. Nothing wrong with that (we can argue the pro/cons of cash & swipe in another thread).
But at the end of the day, if my credit card gets hacked using Android pay (unlikely, but you never know), then I'd alert the cc issuer of fraudulent purchases and go from there. New card gets issued, and I'm back to square one. No harm on my end because the credit was never my money to begin with (The onus is on the banks).
However, there's no actual data (cc data) being transmitted when using the app since they use a virtual account number. Therefore, if home Depot gets hacked again, your info is safe. Phone gets lost, cool. Remote wipe my phone via a Web browser. Can't remote wipe a lost wallet.