@mattblaze I would say since ActivityPub activities travel over HTTPS, PMs are encrypted on the wire but not at rest.
So your main danger is from your server admin and your correspondent's server admin. If you both run your own servers, or you use a server from someone you trust, like your family or your employer (maybe), it's probably less of an issue.
I think they're about as private as email without PGP.