To elaborate on the lack of E2EE, this doesn't mean your ISP or so can see the content (the traffic between you and the server is encrypted as part of HTTPS), but your instance admin or anybody else with access to the server could.
In addition to what others have already pointed out, please also note that mentioning any other account in a "private" message chain will allow that account to retroactively see all the messages in the chain.