The issue seems a bit misrepresented by the dev.
The mentioned section of the privacy policy is true only for the logged in users that have agreed to voluntarily share their data.
Without logging in they don’t even store a single cookie on my device.
People being excited about getting spam from a scammer.
What a time to be alive…