Isn't privacy a concern? How do consumers ensure that data is not going to captured in a future update without it being open source or having third party security audits?
Disagreed. It's not concerned with all apps, because most commercial applications have legal entities explaining how they use collected data. In this particular case, this is something called 'Refine', and it's not a legal entity, therefore, questioning its data privacy approach is fully legitimate.
Perhaps this type of software could be either open-source with full code accessibility, or proprietary but from a highly trustworthy entity responsible for privacy both legally and reputationally. Currently, both approaches are missing.