Capital-P "privacy" is absolutely incompatible with publishing networks. Telling people that Mastodon is any better in this regard is at best wishful thinking and at worst irresponsible.
We *might* make it work with AP if we have better C2S implementations where end users control the keys and allow for E2EE, but if your threat model involves 3LAs and corporations building your profile, the best solution is to avoid any social network and stick with Signal/Matrix/XMPP.