Note however this is only partially true for single user devices, where lack of admin rights does prevent some attacker persistence, and is not at all true for multi user devices e.g. the shared family PC.
Persistence is easy enough with startup shortcuts or scheduled tasks in each profile.
Also, I’m not saying these apps have some kind of hidden malware, I’m saying they are operating as designed, and usually offer features in exchange for letting them do things like upload your address book, etc.