What you should not forget is that: public posts are public, private posts may still be public if sent to dishonest servers, DMs are not protected by encryption and rely on both involved instance's honesty.
If you allow everyone to follow you your data may get mined just as on the commercial platforms.
If you have a commercial bot (in disguise) in your followers, it will see and mine those toots.
Just being a federation is no silver bullet to the privacy issue. But ou aren't the product anymore.
@phryk There's not a good solution to this. As a commercial entity might build up fake identities and get them connected or buy accounts.
It's COINTELPRO all over again but this time with a capitalistic twist.