Comments can be used for anything, but in some cases, like the one you cite, they give extra info about the program. The purpose of this in the normal use case is it allows people to know what PGP programs their friends are using. So if there's a security vulnerability in that program, they can warn their friends. In our use case, it's mostly harmless, although it does reduce your anonymity set, because we are divided into groups of people who use PGP program X, Y, Z. I say it's mostly harmless because if LE has confiscated your computer and can look at your PGP program, you are probably fucked already. They can find your public key with the key ID and confirm that you are person X that they were communicating with online, for example. Correlating your PGP program with the version string of person X online adds little to what they can find out about you if they seize your computer.