Cache only responses that the intended visitors are allowed to share. A public product description and a signed-in customer's account page have different requirements.
See how a leak can happen
Imagine Alice requests /account and Nginx stores her response under that URL. If Bob later receives the same cached response, he sees Alice's data. The problem is that a shared cache was used for a private result.
Start with explicitly public routes. The cache key, which names the stored response, must distinguish relevant variants such as host, path, query and language.
