Nostr is transparent about the exchange of notes between npubs but the content can only be read by each npub.
The big risk is if the npub you're exchanging information with loses exclusive access to their nsec. Then everything that was ever discussed with them is revealed.
I still prefer this model as it pushes the risk out to the edges rather than centralising it on a server.