Just to make clear, DMs are not crawlable.
They're also not easily accessible by the admin.
In theory a server owner could see them by looking at the database, but there's nothing in the Masto admin interface to allow this.
The privacy risk on DMs is that a technically proficient admin could in theory look directly at the database, but they'd have to go out of their way to do this. It's not a built-in function of the Masto software.