I get your point, but in my experience it is more common to land on a website with a malicious ad than intentionally download an untrusted app.
If others read the section on Bluetooth it outlines how poor native protections are.
Full integration of web app settings into the OS is essential for users to be able to control their privacy.
When I create a document locally, or copy a photo from my camera to my computer, I'm responsible for how far it leaks, and it's fairly easy to manage and understand.
When I create similar data in a web app, I have no control over what happens to it.
How is "privacy worse on native"?
I think the key here is "trusted". That's the bit that needs work. Vendors need to work on their trust; our industry needs to work on its architectures and business models.