I think it will work well for verifying DB changes and optimizing SQL on real data.
This seems like a great tool to eliminate the risk of database-related downtime.
You are absolutely right. Depending on the current environment, you should think about the protection of sensitive data (for example, data masking and obfuscation, access control).