Regarding point 2, I don't trust my data being safe running inference on model creators api, but neither do I trust US providers. Both use it for their own benefit, the only difference is the country of origin. The US has a lot more legal safeguards for this but I don't trust they don't do it regardless.
legal safeguards only make sense only when they’re enforced. With how “move fast and break things” Silicon Valley is law is always playing catch up (at your expense)