I don't like the bloat, but I don't see it as more privacy invading than any other system logs.
As this comes out-of-the-box by default, and is in fact a pain to switch off, I compare it to this new windows behavior.
Should we compare syslogd to the new Windows behaviour?
Zeitgeist itself runs with the users privilege (it's not a system daemon, it's started by the user's session), so that hypothetical application could simply log the data itself. There's no leak of information to underprivileged processes.
On similar note, I rememember someone arguing that the baloo/nepomuk db was a security threat, I guess since it makes slightly easier to search among the files on the system for a string like "password".
Both claims are technically true, and in neither case I believe they are practically relevant, neither for security nor for privacy. I was nitpicking, I guess.
Syslogd can be compared to windows event logs.
Ubuntu, on the other hand, does not have such a commitment to free software, and has included Amazon ads in the Unity dash in the past.
[0]: https://www.debian.org/social_contract