A fair point, and one that's not really new either.
Don't want something to be public? Don't post it publicly. As I recall, when my employer at the time (mid 1990s) "federated" their email with the rest of the world, they sent out a memo which stated, in part, "don't put anything in an email that you wouldn't want to see on the front page of your local newspaper."
That was back when local newspapers were a thing, but I imagine you can see the parallels.
That said, I do get to control who sees my content -- by not making it public (i.e., I don't federate my AP instances and curate who can create accounts on them).
If you want something to be private, don't post it publicly. I'm not sure why that's such a foreign idea to some folks since, as I mentioned, it's not even close to being a new idea.