Not a misunderstanding, a requirement. If the developers cannot have that data (legal reasons? Secrets?) it must be deleted.
Probably has to be done outside git, though. Maybe one of the corporate virus scanners will let you definite a local signature.