---
Like, right now.
---
I also use a personal monorepo for all my projects, including an "experimental" directory for one-off things. However, I am (and you should be) much more careful about what gets committed.
One of my rules is that credentials never belong in the same directory tree as the repository. Entries in .gitignore are not sufficient to prevent accidentally committing sensitive info to the repo. Occasionally this rule takes a little effort -- e.g., some project templates default to using ".env" files for secrets, and to uphold my rule, I need to understand the tool well enough to configure a secure alternative.
Another thing that I find helpful for managing a large number of throwaway projects: a global .gitignore with defaults like "node_modules/", "target/" etc.