Through #ActivityPub, #Mastodon privacy settings rely on voluntary cooperation. You *request* that instances only share your content with the audience you specify, but there is no real way to enforce that.
This comes as a surprise to many users.
Me, I think I'd change the UI to call it "suggested broadcast"' rather than anything related to privacy so that users are more aware of where their content might end up.
@volkris The only thing I can think of to mitigate this problem is some sort of E2EE like Matrix, although that is far more complex.