I'm not sure what you want privacy.com to do differently.
This seems like a larger security/privacy surface area than the latter approach.
Privacy.com don't have to use Onfido, there are other options out there. There could be a myriad of reasons why they chose Onfido over the competition but the TOS bind the privacy.com users and they don't offer any alternative.
For a company leaning on "privacy" as their primary marketing tool, this is a double standard. It doesn't mean Privacy.com is a bad company with horrible people building a terrible product. They're just calling out a company for doing something seemingly opposite to their marketing, and saying that's why they personally aren't using the product.
You can disagree with OP but doesn't make their point wrong, invalid, or stupid.