When you “sign in” with a pubkey, you don’t actually see the DM messages. You can see who someone DM’d but not the messages. You’re just able to see nostr from their viewpoint/relays, but the nsec secures the actual messages themselves.
Is that what your friend meant?
