Yes, I was wondering about that - I guess that pgp encryption composes with the encryption to the recipient pubkey.
Still, this feels like a case where one can realistically keep the encrypted events off public relays, so one might as well just do it.
