IT guy here, the NFC thing isn’t really a concern (NFC doesn’t work that way) or for that matter, any other wireless technology, as it’ll need to authenticate with your phone somehow. If you can somehow simply scan data from a phone without any form of authentication, that would be a massive security hole - something that would be patched by the vendors real quick. Also, if something like that were possible then the TSA/FBI wouldn’t have any issues pulling data from locked phones. Think of all the times you’ve had to put your phone thru the xray machines at the airports. Also see the case of FBI vs Apple for instance.
The other issues you’ve mentioned are valid though. Heck my Galaxy Fold won’t even fit in that slot.
… for now. They’ve already replaced the old Notepad with a bloated UWP version, so it probably won’t be long before it starts sending telemetry as well.