I think there is a difference here between "expectation" and "assumption".
Without the ability to do a third-party audit I agree the only reasonable assumption to make is that everyone is in on the secret and when dealing with sensitive information it should always be the assumption you go with.
However, as an expectation, I expect SaaS and social network providers (and by extension most of the HN crowd) to be better.
[1] Of course, since you don't know who the individuals are, you still have to place your trust in every single agent that works for the entity you chose to entrust. As such, nothing is gained by restricting access. It remains that if it is important that it be private with only one or a few, you must go to those individuals you trust directly. Granting them private information by proxy will always be subject to man-in-the-middle-ing.
Applied here, the expected and right thing to do is follow the principles of least access. However, we must assume google is not doing this, because there is insufficient evidence that they are, and there is actual evidence that they don't have sufficient controls to limit who is able to see information.
However, you make a fair point that it is reasonable to assume that entities you trust are willing to go above and beyond, for various reasons.
To clarify, I am the second person here telling you that that is not the expectation. The expectation, and/or the right thing to do, and/or "the standard we expect them to meet", is that Google follows the standard security principle of least privileged access, meaning each employee can only access data they need to see, with proper permission acquired beforehand, auditing during, and abuse-detection & alerting afterwards.
Unfortunately, they don't meet this expectation that we have of them. Your own expectations and/or standards might be lower, like you described.
Your question of "why" boils down to asking, What is to be gained by employing the principles of least privileged access, as well as proper authorization, auditing, and alerting? The answer to that question is beyond the scope of this post, but I trust that you understand or can understand the benefits of these principles.
Yes, the expectation is that Google, and therefore its agents, are trustworthy. You would not give them your information otherwise. Who happens to working at Google at some moment in time is irrelevant. You have chosen to entrust an entity with a revolving door of individuals. Absolutely no expectation of who will access the information is defined, fundamentally. If that is important, you must go to the individuals directly.
You might assume that Google will "do the right thing" by working to keep the information away from those who don't need it, but that is entirely up to them. Hell, they might even do that, but then cycle all of their agents through positions where access is needed... In the end, if they choose not to, nothing about the trust expectation has changed.
That is your expectation, not the expectation. 2 people have told you what the expectation is. You, 1 person, have shared that you have a different expectation. This is okay, but you aren't speaking for us, or for the majority here, only yourself.*
The expectation is the one that we have cited, nothing less. It's great if they meet your expectations, but that's not good enough for us.*
Speaking only for myself here, I believe there's a reason that the principles I cited exist, rather than 'the company lets any employee access anything with no permission or record of it'.
* – paragraphs void and I am wrong when majority changes: I've gotta listen to the people, too! ;)
Furthermore, getting back to the topic at hand, expectations in an exchange cannot be defined by an individual. They must be defined and agreed upon by all acting entities. Google has made its end of the exchange clear with no evidence of wavering just for Nintendo, implying that Nintendo shared in the standard list of expectations.
It's unclear, but you appear to be accusing myself and at least 1 other poster of being "software", presumably some sort of insult about how our posts are somehow similar to chatgpt output?
I think now is a good time for me to disengage.
There was nothing about the quality of that output or an attempt to insult the software. By what mechanism could software even be insulted?