I stumbled across something wild on Xianyu while looking for completely unrelated chips. Turns out there are ready-made tools for bypassing STM32 RDP1 on F0/F1/F2/F4. Had to try one. https://carlossless.io/stm32-rdp1-decryptor/
carlossless - An Interesting Find: STM32 RDP1 "Decryptor"

Buying and trying a cheap STM32 flash reader that bypasses Read-Out Protection Level 1