Not just your (user X) data, but your friend's (user Y) data. What if the API had sent user Y a confirmation, like "User X just installed CAapp and wants to access your information. Allow or Deny?"

If you take the "social" part serious frind's data is essential. When playing a game it should compare to your friends on the high score list. When using a birthday calendar you want to see birthdays.

Having to ask the friends for approval doesn't scale.

There is the fundamental conflict between a social network platform and privacy.

