Nostr privacy 101:
1) Use a reputable VPN or Tor as every node knows the IP address associated with every event you publish.
2) Use a separate lightning wallet for your zapping. Zaps associate your lightning address with your pubkey.
3) event Metadata may indicate what client you are using. A client shared with a hot wallet (eg Umbrel) could introduce a threat vector, especially if you ignore #1
Nostriches, What would you add or change?
#[1]