Aye, my proposal was a trade off between privacy and convenience for non technical users ( it’s only as bad as a non federated social media site).
The best balance here would be a client on the user device that manages the keys for you, and an API in lemmy for accepting and sending encrypted messages.
As a side note, I thing PGP is more or less superseded by AGE
It could be a vets I suppose. Still odd.