Not all third-parties are the same.
Not all third-parties are the same.
These tools are increasingly developing new features that allow them to act more like a "CDP", essentially allowing you to send data from the tool to something else.
Want to send data from Amplitude to Facebook? That's easy https://amplitude.com/blog/amplitude-customer-data-platform
Certain termination reports do contain small memory dumps and/or register values, so theoretically could could contain decodable PII. This is something the OS vendor provides, not the developer of the app or the crash reporter.
Pseudonymous information always has a high risk of being abused for fingerprinting and thus denonymising. I feel that there needs to be a trade-off though: on public datasets, people should be very careful with pseudonymous identifiers. On things like crash diagnostics that are never meant to be shared I feel they're perfectly fine. That's why I dislike a general discussion where all PII is bad and evil without context.
Do you mean monitoring and analytics in general don't improve products? Or that "product improvement" is a commonly used excuse to harvest user data?