The truth, at least the part of it that you can see for yourself. You freely admit that you don't know if there even are actually audit logs, or if the measures in place are simply big warnings (that have no teeth behind them). Even if there are audit logs, they're useless if there's no system in place that flags suspicious use for a human to check up on... or lacking that, someone whose job it is to regularly read through the audit logs and verify that each access of personal info is legit. You seem like an ethical person, so you're unlikely to find out if there are consequences to looking at customer data without good reason, so you don't know what -- if anything -- is triggered if you click on something sensitive.
I know you want to believe that what you're saying is true, but it sounds like you have no hard evidence to back that up to yourself, let alone evidence you can present to someone outside such as the HN readers reading this thread.
You may trust that Uber takes the security of customer info seriously, but from the outside we have no frame of reference, except for reports of past wrong-doing. A statement to the effect of "it was bad in the past but it's better now" unfortunately isn't all that reassuring, and I hope you can see it from our side of the fence and understand why.