The other article on their blog introduces a systemd module that not only collects all hardware information, but also signs it with TPM before transmission [0].
I'm not even sure it makes much sense in datacenter conditions. And once it gets onto computers of the regular users, it would be very easy to repurpose it for spyware.
[0]: https://amutable.com/blog/it-starts-upstream-systemd-report
It’s no different than a Prometheus stat exporter. If you don’t want it then don’t enable it.
Also, most consumer computers don’t have a TPM.