Its a compromise. You trust a nostr relay to keep something from others on your behalf.
Best case, you only auth on your own server. That is pretty good privacy.
Encryption is obviously the peak, but some things can't be encrypted: metadata, access logs, maybe private messages that can't be encrypted for some reason.
That's the stuff you want auth for.
To be fair, most nostriches treat a relay's ability to perform AUTH as a signal that it is trustworthy. We should probably use some other metric for trustworthiness and culturally make it popular.
