Nice video here: http://www.youtube.com/watch?v=pzviQLCPCG4
An application can read the unique ID of the device (which is used for session persistence between service calls) but not access any other information unless allowed to.
Effectively there is no way for it to steal all the data in that list unless you physically tell it that it's ok to do it.
It's the mobile platform that scares the shit out of me the least. They did good here.