#Twitter, #Facebook, #Reddit, #Minecraft direct messages can be read by any super-user (administrators, server operators & so on).
On #Mastodon happens to be the same. Your instance admin can read all your DMs.
Mastodon already implemented most of the server-side bits, but several challenges remain to implement the feature in clients.
Keep this in mind and choose your media wisely when communicating sensitive data.