I have also only been skimming the info but the issues seem to be:
1) Recall takes snapshots of user’s activity and then copilot analyses it and keep the info in a plain text database.
2) The database is accessible to other accounts in the same computer.
3) The database is kept very small in order to save storage space. The trouble is that it is so small that it takes no time at all to upload it. One researcher infected his machine with a know piece of malware. By the time the AV software recognized it the database had already been sent.
4) Oncenthe database is in hand it is trivial to see whatever the person was working on and what information was involved. Apparently you can literally see some things.
So yeah, collecting large amounts of sensitive data makes for a very juicy target.