What used to be a five minute "put tcpdump on the access point / router to work" job pre-HTTPS everywhere now is a many days worth job of messing around - out of reach for all but the really dedicated, and as a result it is very hard for an user to have actual visibility over where their data flows.
Doing the same on our mobile devices is much more tougher, because we've let feature phones become walled gardens.
Not if the app uses certificate pinning, ships its own version of a SSL library and uses code-signing and obfuscation to prevent you messing around with it.
As for the walled garden part: I agree with the general sentiment, but on the other hand I also see the lengths malware authors go to gather data from people. There really is no one-fits-all solution here, because anything that allows the user to intercept and monitor SSL communication can automatically be used by an attacker! :(
Are there desktop apps that behave this way? Atleast in my experience - I haven't come across anything like this on Linux.
And I seriously hope cert pinning gets adopted by more applications.
As for data being sent from your device to 3rd parties, again, if you don't trust the app's developer not do to that, you also won't trust them not to be sharing it from their end where you have no way to look at the traffic.