scope=user-read-private+user-read-birthdate+user-read-email+user-library-modify+user-library-read+user-read-recently-played+user-follow-read+user-follow-modify+user-top-read+playlist-modify-public+playlist-read-private+playlist-modify-private
(Those are the requested OAuth scopes from the Spotify login URL that the "Follow for download" button redirected me to.)
Why would they need to have permission to, among other things:
- Read your recently listened-to songs
- Read your top artists and tracks
- Read your private playlists
- Modify your playlists (private or public)