Earlier quoted context omitted.
Not saying much. Same is true about any e2e encrypted messaging (Telegram, Signal, etc.) There's no way to tell if they are intercepting your messages clientside, and you'd have to monitor all the network traffic (which would be encrypted with their keys) to detect exfiltration.
No. Signal is not redownloaded from Signal each time you launch the app, unlike javascript web apps.
Or the ability to execute arbitrary external code?