The recording is local, on the hard disk. I think people are worried that by producing the files, there is just one layer of bug (accidental upload) keeping them private.
I agree. The data should not even be generated if the analytics are not opted-in-to.
I do give them credit for making the system opt-in. They deserve that.
Not really. I wasn't aware of this. The only thing I found on reddit regarding the situation was the link I sent above which didn't have any controversy.