Yes the admins can read your DMs thing is absolutely true on any platform w/o E2E encryption but the scale and structure of the fediverse does make it more feasible for a bad admin to read *all* the DMs on their server. Also there are no real consequences to doing so.
So I would stick to just exchanging alternative contact details by DM ๐
Lazy me also has not checked to see if E2EE DMs are in the works for ActivityPub.