Well “they” can technically “read” anything your user can.
Apps installed via the MAS have sandboxing applied to them, so this isn't really true.
Apps installed via the MAS have sandboxing applied to them, so this isn't really true.