This used to be an ideological stance but increasingly recently it's the only pragmatic thing to do from a stance of security and safety. The playing field is increasingly hostile and if someone asks you to install their software on you machine and let it record your face and voice but refuse to show what it actually does, that is a red flag. Reasonable exceptions could include video games (which run on dedicated untrusted devices and IMO the IP aspect makes the closed-source stance more understandable there). On the other hand, this app is inherently sensitive and trusted because of its function. I don't see the reason why it needs to be closed-source.
Malware is commonly distrubuted in all app stores. I reported some obviously pretty bad stuff that is still up a year later on Play Store, for example. Google simply doesnt bother if the case is too messy.
> hmm not sure yet on the open source thing
You could start with just go source-available by sharing the source with your users without going full Open Source, if you want to take the time and think about what license to use.
sure thing, just gotta download and execute it.... WAIT A MINUTE. YOU ALMOST GOT ME! YOU SOB
> you can also view the source code easily
can just as easily throw it on github, if your intentions were legit
Although I personally deplore it and try to stay away from software that requires it, or even opts me in, I nonetheless think that it's reasonable for a developer to impose telemetry as a requirement for people to make use of their freely available software.
It is a straightforward set of rules written in simple language and it’s not very long either. It’s not necessary to rely on third party readings or interpretations of it. Just go ahead and read it yourself and you will be well equipped to apply and argue about it.
Everyone --- even German newspapers --- flouts this rule. "Consent or pay" is a common strategy.