The data you post here lives on a server that the Grimoire.Social team runs. They promise that they won't look at your private data. You are just going to have to trust them on this.
This is, however, an ActivityPub federated server. This means that other people on other federated servers can find you, send you messages, etc. This also means that any information you put in posts, whether they are public or private, might end up "federated" -- basically, a copy of your post gets put on any server that reads your post.
If you want decent privacy (the info doesn't leave this server), the only way to do that is to set your account to private, only accept friend requests from other grimoire.social users, and only ever use our "local-only" posting mode which you learned about in your onboarding. Once you start talking to people on other servers, all bets are off. Any private message you send to someone on another server could be looked at by the admin of a different server. This is kind of like email: if you are on a private email server, and you send an unencrypted email to a gmail account, congrats, Google now has the content of that email. But also, you do this every day, so, hey. The internet!
License
This privacy policy was adapted by one written wholly by Darius Kazemi. He provided the original under a Creative Commons Zero License, meaning the contents are in the public domain.