Seems like the first point ("Once you have pushed a commit to GitHub, you should consider any data it contains to be compromised.") supersedes that — even if you and GitHub both erase any trace of it, there's a nonzero chance that some kind of automated system, malicious or not, has a copy of it already.