Good catch — you're right that a static treasury address paying out repeatedly creates a public payment graph that maps node activity over time, even without direct identity binding. That's a real privacy leak we hadn't scoped yet; config-level separation solves "which wallet" but not "how much traffic flows through it."
Adding a privacy note to RFC-0016's payout section: rotating LNURL/BOLT12 offers per payout cycle instead of one static address, plus considering batched payouts (already proposed for fee reasons) as a side benefit for reducing graph resolution. Not solved yet, but now tracked — thanks for flagging the actual mechanism instead of just the principle.