I think this is less a bait and switch and more just a legal liability shield. They're not saying you 'cant' use it that way. They just don't recommend you do, and they won't support you at all for doing so. Which I think is completely fair. Also, these two things aren't in contradiction. Deploying on prem does offer more security, but then it's up to you to use it correctly.
This actually makes me wonder if cal.com has had a security breach in their hosted offering that they are not disclosing.
It being open source also allows you to actually have a read of the software and guarantee things yourself, which is the harder better path anyway.