It’s their servers, they can do whatever they want with them. What are you going to do about it they have physical access, you have an API key. Suggestion, if you want to secure your data don’t put it on other peoples computers, and for fucks sake don’t store your crypto keys on someone else’s computer.
That is a really false statement. This is why contracts, audits,... exists and they define what each party can and can't do. When in violation this could result in huge fines, loss of business,... You can also securely storage your data on other servers by using client-side encryption. Not every business/person has the means or knowledge to have their own datacenter.
Hey but you have audits, contracts, why would you need that? You are effectively saying the same thing that parent comment is. You're just offering a more practical solution.