Some sort of cross-domain request blocking could then prevent the app from stealing your data.
The key difference is that instead of companies storing, owning and exploiting your data, the user maintains their own data store and companies can then access and exploit it.
It's decentralised in the way where the data lives and is controlled by, not in how or where the data is used.
There is the problem where companies could continue to use your data when you no longer let them access to your data store - but that in effect is at worse unethical and at best not legal these days.
Of course, it is not impossible for the client-side app to send the data back up to the server. Even if encrypted somehow once decrypted in the client for display to humans then its hard to protect that plain-text data. There were also some other open questions like if my distributed data is distributed, how can I "take it back?" I dont think there is a mechanism for that yet - some sort of TTL might work there though, if you can somehow bake it into the data/hash itself to avoid bad clients from ignoring TTL values before deleting/archiving.
https://www.nytimes.com/2017/06/23/technology/gmail-ads.html https://www.engadget.com/2017/06/23/google-wont-scan-your-gm... https://www.wired.co.uk/article/google-reading-personal-emai...
Many more sourcews just a short duckduckgo search away.