It's open source, and by default notes are stored locally on device only. Neither Joplin devs nor anyone else for that matter can access your notes, unless your phone is hacked. They will only leave your device if you set up syncing, and that is end-to-end encrypted. You can set up the app to need biometric auth to open.