

I’m no lawyer, but this seems like at least grounds for a class action lawsuit, I would think. Like, it seems like privacy and security is implied (however ironic for an app like this) when requiring users to upload their PII.
Also, I assume their privacy policy didn’t mention that they were just gonna publish their users’ PII.
I don’t disagree with your main point, but I’m not sure it’s really even “stealing”, as that means to take without permission. In this case, the storage permissions were configured so that the files were publicly available to everyone, so everyone had permission to access them.
Semantics though. It’s still unethical to access that data, even if it’s not technically stealing.