I'd treat it like any other clearnet site. Lemmy doesn't go out of its way to log your info (the admins certainly aren't interested in that), but it still runs on an nginx server and is subject to whatever that entails.
I follow Eugen's advice from mastodon: fedi apps are not inherently privacy-centric or encrypted, so it's unwise to treat them as though they are. Since posts are public it's very easy for outsiders to scrape data.