You've done nothing to refute my point and so it still stands.
I pay GitHub / Microsoft to host my code, and that's all I expect them to do with it, host it, as securely as possible. It sounds like Microsoft are doing more than this so what's your actual deal...if you have one?
I did, what did I miss? I just re-read it and it's full of statements which are totally inline with what I expected:
GitHub considers the contents of private repositories to be confidential to you. GitHub will protect the contents of private repositories from unauthorized use, access, or disclosure in the same manner that we would use to protect our own confidential information of a similar nature and in no event with less than a reasonable degree of care.