Not the sort of safety issues I think you mean, but there have been some rather questionable behaviours from the current owners in the last year or so. A quick search for Audacity here or elsewhere will find the details.
especially if it's opt-in (which is provable since the project is entirely open-source) -- can people simply _not_ opt-in if they disagree with telemetry?