App distribution can be totally different from API access to my device. No matter where i get the app from, when accessing certain APIs i would get notified about that, or would have to explicitly enable that functionality in OS settings.
This must be handled correctly as it can this also lead to privacy violation.
Question is will this be ethical .. I will not be comfortable using a device that logs every API an app on it is calling.