Analytics packages generally rely on either the application's terms of service or the platform's overarching terms of service, so I wouldn't say 'explicit permission' in all cases. The user likely 'agreed' without reading it.
That said, there's a complete difference between what's actually done with this sort of data and what this guy (or the WSJ) thinks is being done with the data.
In the case of analytics software, things like the phone's location and language settings are used to produce an aggregated breakdown of usage by country, useful for localizing your content and staffing customer support. The phone ID, after being run through a one-way hashing function, is used to provide an aggregated unique user number - since the correlation between downloads and actual active users is pretty weak. There's no user-level records and best practices around data retention are followed.
Oh, the horror.