Oh devs would absolutely avoid distributing through the App Store if they want to run any code that would fail App Store Review, such as the abuse of private low-level APIs to gather more user data than the app needs, which all businesses have a profit incentive to do.
There are many other possible scenarios: devs forcing users to authenticate with unsecure methods, gather and unsecurely store credit card information, gather passwords, upload contacts, read SMSes, etc. The value that a third-party dev can derive from private user info is far greater than alternately offering a different version of the app that will pass App Store reviews.