Let's be honest this is how it actually usually plays out:
-
Be a huge company
-
Make your employees sign an NDA
-
Make your code closed source
-
Use GPL code and not give a shit because you're a huge company with a legal team bigger than your Dev team
And not just the instance admins would be at risk as well. Any time you view an image your device is making a local copy of it. Meaning every person who viewed the image even accidentally is at risk as well.