It's not exactly that hard to imagine. I've thought about a solution like this for 2 separate products across 2 different companies, and it was separately rejected for ethics concerns both times. You'd be surprised what company decided to reject it in the first case. This is an abuse of web APIs to achieve targeted data monitoring of users and probably a severe violation of GDPR.
Any European residents want to confirm this is happening with them?
You should use the Euro judicial framework to get resolution for this 100%.
Americans like to complain about European legislation but this is a perfect example of government powers done right! (I'm a dual American/French citizen living in the US).
Can you kindly opine? I am not in France at the moment so I'd love to learn what issues you are facing. Sorry to waste your time but I think this is a critically important topic if we want to preserve our data, privacy, and related rights into the future.
Any European residents want to confirm this is happening with them?