@worik @strypey @reiver You're right; ActivityPub is encrypted from one end to the other.
The problem is data at rest. AP activities are stored on the sender's server and cached on the receiver's server in the clear. If your server admin, or mine, decides to go spelunking in their database, they can violate our privacy and read our messages.
This is no better or worse than unencrypted email. However, a lot of people on the Fediverse have accounts on servers they don't trust.