According to the statement on their website, the privacy policy relates to future settings that are not yet in the software.
So for example, in the future you might want to mark a playlist with a photo on your device, e.g. a friend's face for their favourite music. And you might want to search to see if any friends in your contacts also use Spotify.
My understanding is that those features aren't in the software yet, so you can't opt-out right now, and even when they are in Spotify are saying that you'll have to select that particular option for it to use that capability, but they've taken the opportunity to update their privacy policy. Problem is that the policy is quite generic, rather than saying 'if you want to upload a photo from your phone, you can, and we will then store that particular photograph'.
IMO the policy should have been clearer, but I'm sure they're far from the only company to have done this, and it seems they've been a bit unfortunate. Especially at a time when Apple is trying to destroy them.