Whether it's good local privacy laws in your country or a good privacy-respecting TOS from a company, both are basically worthless when a bigger entity comes barging into the picture. So your government collects biometric data but passes laws promising not to misuse it... you may very well find that those promises are worth less than dirt when a country with leverage over your own starts making demands that your gove…
This is very correct. However, I would amend your solution: the solution is modern encryption and open source. These two in conjunction allow you to verify trust. ToS is like HR: they both exist to protect only the company.
Not when it comes to server-based software.