That describes the system backwards. An AirTag does not transmit its owner’s identity, GPS position, or location history to every nearby phone. It emits a Bluetooth Low Energy beacon containing a rotating cryptographic public key—not a stable ID tied to you.
A nearby Find My-capable device may observe that beacon, take its own approximate location, encrypt that location report to the AirTag’s current public key, and upload the ciphertext. The phone owner does not learn whose tag it was; the AirTag owner does not learn which phone submitted the report; and Apple operates the relay/storage service but cannot decrypt the location payload. Only the AirTag owner’s devices, which possess the corresponding private keys, can turn the report into a map location.
The identifiers also rotate roughly every 15 minutes. That prevents a passive observer from treating one Bluetooth identifier as a durable “this is the same tag/person” handle. It is specifically designed so the successive broadcasts cannot readily be linked to the same device.
So yes, it is a crowdsourced location network—but “crowdsourced” is not the same as “nearby strangers and Apple can see where you are.” The relay device contributes an encrypted observation without being identified to the tag owner, and the owner gets no information about the relay device.
The legitimate privacy concern is misuse by the tag owner, not surveillance by the phones that relay reports or Apple reading everyone’s movements. A malicious person can try to hide a tracker with someone else’s property, which is why iOS and Android provide cross-platform unknown-tracker alerts and the tag can be made to play a sound. Apple also can associate a tag’s serial number with the owner account in response to lawful process. That risk is real, but it’s materially different from the network being a general-purpose location-data vacuum.