You are correct on almost everything, except on the ability on using your access token to spread rate limiting : requests still depend on the application id, so every request will use the app id quota. This is why the Apollo developer basically said that the pricing changes would kill any chance of having the app financially viable.
Regarding why I'm asking everything upfront, I will (partially) blame the library I'm using to authenticate with reddit, django-allauth. It can be made to make user configurable scope requests, but the default adapter just takes a fixed list of scopes from the overall application setting.
I do understand that it would be better if I asked for the proper permissions on demand, but to be honest it was now just a matter of prioritizing new features over addressing valid-but-minor objections that people might have.