Mastodon's a cool place, but it's private like a local coffee shop, not a home bathroom.
Remember that the admin of your instance can see EVERYTHING you post, including direct posts. They can even disable 2 factor authentication, if you have it enabled (and you should. No really, enable that stuff now.)
Bottom line: Find an instance where you feel you can trust your admin, and don't send direct toots unless you trust the admin at the recipient's instance as well.