That's not how I would characterize it. Per the link above, they've provided a way for developers to declare the reasons their app uses API categories that can be used for fingerprinting.
> Data saved there is already scoped to the app itself, not to other apps or system information
Per the link, it appears that bad actors are somehow using it to violate App Store anti-fingerprinting policies: "This reason does not permit reading information that was written by other apps or the system, or writing information that can be accessed by other apps."
Is that considered fingerprinting? I really don't care who it is, I'm just trying to make sure the features I'm building are actually being used.
The author of Overcast, Marco Arment, did that specifically so he wouldn’t have to store usernames, passwords and emails on his server - increasing privacy.
You can add a username and password to your account if you need to log in to the website. But he really wants to get rid of that requirement too.
With some exceptions (such as social media apps) I don’t think it’s generally first party devs who are doing this, but rather third party SDKs that are popular with devs, e.g. Google Analytics, Firebase, Facebook SDK, etc.
To help this along the app can do things like kick the user out to their main browser to do some routine thing, where cookies can be accessed. The user doesn’t need to deep link back to the app in that case, the app can pull down whatever tracking info was harvested during the page visit and persist it.
I don't think Apple are aiming to change that with this
There is something about the way it’s presented (or maybe a bug in my brain) that keeps reading it as the age of the app.
(And IMHO that would be a lot more useful thing to show in that prominent position too)