Yes you can, all the data is in Joplin Cloud
Yes they can, however you can use encryption to ensure that only you can read the data. Without your encryption key the data is unusable.
As for the data retention policy please see here: Joplin Cloud - Help