If you append to a merkle-dag then yes it's immutable, but you can always do the equivalent of a git rebase -- effectively removing a portion of the tree and then selectively re-applying the parts that you want to keep. That creates a new DAG, one that diverges from the DAG that was shared before. For example, if you accidentally commit a database password into your git repository and push it to github, you can go back, edit the git history to exclude that commit, and force-push the new tree to github. This completely removes the info from your git repository. Of course, if someone has already pulled that old code from github, they already have your password -- you can't change that!