It's even more irresponsible of this dev WHO WORKS AT GITHUB to take this fact to lightly. Read AND write access to both my public AND private repos is an insane amount of trust to put in another person. I'm sure this person is a stand up individual. But does he/she write secure code? How easy is it to gain access to his database of access tokens?
In this world of Yahoo/Sony/You-name-it hacks that we live in, I'm honestly surprised there haven't been a hack yet where someone got a hold on a whole bunch of access tokens to private repos. You could do A LOT of damage with this. I'll never sign up for a service such as this and the author should be ashamed to even suggest it.
Instead he/she should focus their time on fixing this issue at GitHub instead of making apps like this.