We have a clear privacy policy https://kde.org/privacypolicy-apps/ and privacy is something we really care about. See for example initiative to develop kde itinerary to be able to track your travel in a privacy councious way or all the work on gpg/autocrypt in kmail wnd kleopatra.
Software is easy enough to patch. If it wasn't built-in, it'd be easy enough to add. It'd also be one update away.
IT-sort of people on the internet: "Security is very important. We dont want to get hacked"
Also IT-sort of poeple on the internet: "Why are you paranoid of a tech company is collecting your data? You really think they are gonna hack you?"
Also others in the field: We need Intrusion Prevention Software, IDS, pfSence firewall, etc... So we can be safe from hackers while our machines host extra automated services we dont need, among reasons.
KDE e.V. is a registered non-profit, I don't think this would be legal for them.
> You think KDE doesn't have people who do this?
No, because it's not a commercial company. I do think they have an interest in collecting metrics because really it can be very hard to get useful information otherwise. In something of the scale of KDE it's going to be hard to determine which parts of it get the most use, and what crashes in some particularly weird circumstances.
In fact for instance I recall KDE upset quite a few people when at one point Kate lost the project functionality -- apparently the KDE devs didn't realize that the function was actually quite widely used. If you don't have data on this kind of thing it can be hard to figure out a good way forward.
Thanks for mentioning this.
XFCE is what ill stick with