Fair enough "if" data are not being sent to Apple server. But for a hackers perspective, this is a point of vulnerability and attack. If a hacker can find a way to capture the data in memory or by any other means then they can create an app that does not request location services but still can access your location data. And this is a much more dangerous type of attack because user are confident that there location are not being accessed by third party app but the truth is they are dead wrong.