You can test how private #NOSTR is by entering your *public* key instead of the *private* key when setting up an account, or use someone else's public key, I it is usually on their profile page.
You can see who and when people are communicating via DMs but not read the message contents.
I was shocked the first time I tried it.
#privacy