I suggest to add possibility to specify permissions for Private App to read and write only some specific custom object. For now I see only crm.objects.custom scope which works for the whole group of custom objects. It would be nice to be able to permit Private App to interract only with a specific custom object.