Don't operate something you've sold to someone remotely for your own benefit with explicit opt in that is difficult to do without understanding. Full stop. Don't mine their device for data. Don't harvest anything at all from it without an explicit interaction or intentional manually configured automation.
So far, far, far away from where google/apple/ms have drawn it.
This feels like a really loose interpretation of operating something remotely. If they have a backdoor to your phone that lets them flip a switch, that's one thing... I think in this case it's turned on through a software update, which is in the control of the people using the device. That's another feature that is opt-out, by the way. Why? Because requiring input from users to update their phones results in most people not updating their phone, which is a security risk.
It's not so cut and dry and being that dogmatic about it in one direction when there's clear and significant downsides to doing that way is shortsighted. Even if you prompt the user asking for permission for every single thing going on on their device, what do you think the outcome of that will be? Most people I know have tons of notifications from every app they install on their phone because they don't even look at the popup after the first couple times it appears.
So far, far, far away from where google/apple/ms have drawn it.