The nice part is that we don't have to share our dropbox folder with other users, so we don't. to utilize copy_ref we just need separate access to each of the accounts to do the API call. We have special dropbox accounts that are only used by the servers. Like anything, we take serious effort to ensure that this information isn't compromised.
As Eric mentioned, we have an email to Dropbox to see if we can permanently delete through the API. Until then, we will have to rely on keeping the login information to these accounts safe, which is saved in the same high level of encryption as our user account information.
I am not sure that I follow how a small bug could cause your files to be accessed. All access to the user accounts are kept completely separate. We take all concerns with user data and security very seriously.