for...in, Object.keys(), values(), entries(), getOwnPropertyNames() and JSON.stringify() skip symbol keys, which makes symbols safe for tagging objects you do not own. They are not private: in, Object.hasOwn(), Object.getOwnPropertySymbols(), Reflect.ownKeys() and spread still see them.
const id = Symbol('id');
const o = { name: 'Ada', [id]: 7 };
console.log(Object.keys(o), JSON.stringify(o), { ...o });
console.log(id in o, Object.getOwnPropertySymbols(o), Reflect.ownKeys(o));[ 'name' ] {"name":"Ada"} { name: 'Ada', Symbol(id): 7 }
true [ Symbol(id) ] [ 'name', Symbol(id) ]