Yeah, ActivityPub sysadmins can see all the activity of their users, just like centralized services.
ActivityPub beats nostr in account recovery. Passwords can be reset. That feature being exploited depends on the server (big instances are very similar to centralized services, small instsnces are more likely to do a better job at sniffing out the scammers).
User responsibility (low). Typically excellent support from your instance as well as the community.
ActivityPub's interoperability matches nostr
It doesn't have a single point of failure, but it's not as resilliant as nostr, so in the middle on that one.
And I think nostr probably wins on everything else.
Moving servers requires the server's cooperation to keep your followers. So, it's possible unless your instance shuts down unexpectedly. Your old posts don't move with you (but they continue to exist on the old server until it shuts down). If your instance is down you can't post nor see your feed. Posts are not cryptographically signed.
Your instance is not a central authority. You can use the same account for Pixelfed (Instagram clone), Mastodon (Twitter clone), Lemmy (Reddit clone) and so on. But your account is usually tied to an email address. It's not strictly required, but it's so common I would say it's fair to say you have to give your instance admin a functional email address.