This looks great. I was looking at Watchtower again a few days ago, but I don't want to auto update my containers, just get notified for updates. I usually just keep the RSS feed of the project in my feed reader, but diun looks like a proper solution. Thanks!
The same way that all other 3rd party services do it: keep your systems up to date, do not expose unnecessary things to the outside, use strong passwords and SSH keys.
But why would you as a user stay on that instance?
If you start seeing ads and you don't want to, you move to another instance. If all instances start to serve ads and you don't want to see ads, you have to start your own instance.
Rock and stone!