While I feel it is morally OK for users to access the metadata of their own exchanges, there's something awry with that formulation, (not-)"stealing" is about more than just copyright or ToS.
For example, consider my browser cookies that authenticate me to HN right now. Nobody even wants to copyright them, but if you were to somehow acquire a copy I'd very much consider it "stealing."
Im not so worried about that. Im worried about somebody impersonating me or doing something bad and not authorized with the cookies
If someone acquired a copy of them by breaking into your device and stealing the files sure. If you consciously sent them out to every person who asked for them (even if in their encrypted form) well.. that's a choice you made.