Just my own opinion, but at this point I think it's prudent to assume that pretty much anything you send out into the digital network world is public. If it's not something you would want the world knowing you said, don't put it out there. Security breaches happen. Bugs happen. Sometimes law enforcement just comes by and says, "Give me everything that user X has ever done." In short, sh!t happens. "Everything I do on…
The result of this is the attitude that we shouldn’t even bother trying to make services and products more secure. Why send tweets over HTTPS? It’s all public anyway. Why should WhatsApp use end-to-end encryption given Facebook’s hostility to user privacy?
That said, I don't really know of a better way to phrase it; describing this sort of stuff to non-technical users is a bit of a minefield, so I can certainly relate to the solution of "just assume the worst and nothing can go wrong", because if followed, it's unarguably the safest thing to do.
It's a solution in the same sense as "teaching abstinence to teenagers to avoid unwanted pregnancies" is, which is to say that it's largely ineffective at solving the problem, despite being the most effective of all options.