Hello!
Black list enabled: all traffic inside the VPN tunnel except the traffic of the black listed applications which goes outside the tunnel.
White list enabled: all traffic outside the VPN tunnel except the traffic of the white listed applications which goes inside the tunnel.
When you define a whitelist with a single app for per-app traffic splitting purposes, only that app traffic will be tunneled. The system process traffic will not be tunneled, and any other non-white listed app traffic will not be tunneled. So the behavior you observe seems just fine, but please feel free to elaborate if we misunderstood.
Kind regards