The best place for the user has been to cache to the SD card, or the internal storage partition setup to look like an SD card. There are even many root required hacks to move app data to there and similar. The storage permission is needed to access the SD card, however.
Even in non-rooted Android things are changing, however. Apps that accept certain limitations, like no reliable background services, can be set to be installed to SD card. The latest versions do away with mounting as an SD card entirely and should help unify the storage, although everyone hates the new MTP protocol being used to access data from the PC when the phone is plugging in now.
Pictures are stored on the SD card, so the app could read all your pictures, upload them, then delete them. Newer devices have more internal storage, so hopefully applications will gradually move away from using this permission. Apparently, the next version of Android will introduce a new permission for reading the SD card too -- at present, any application may read from the SD card.
"Read[ing] all my personal data" depends on what you count as personal data -- security-sensitive info should not be on the SD card (things like phone number (although the phone state and identity permission gives access to this), contacts, account details), but anything that is on the SD card may be read by any application. That means pictures and music, at least.
I wonder if it might be useful to always list all of the common permissions, to make it easier to see which ones an application doesn't have. I've installed enough Android apps to have a reasonable idea of what's available (and by extension, what any given app can't do) but it's reasonable to assume I'm in a small minority.
And I think there should be a notion of "secure/private/encrypted storage". So when I tell an app to store some item there, I can be absolutely certain that no other app will ever be able to access it, regardless of any permissions.