I believe, a reasonable person, would expect the limits of the access grant to end with the purpose of the app (a quiz) and not extend any further.
Most contracts/agreements have limits and this one is implicit in the working of the app. It is in no way clear that the app is earning it's money by selling/manipulating the data you're giving access to.
Additionally, it's disingenuous to ignore that a subversive app will make up/add features in no way benefiting the end user but for the sole purpose of scraping messages.
Intent is important, for some of these apps it is clear the only intent was to harvest data en masse.
Yes the user agreed to grant some permissions so a quiz could be taken. It cannot and should not be ignored that the app developer purposefully did not disclose the true nature of the app. This wasn't an accident. They didn't trip and fall into the data. They made something appear benign when it was really cancerous.