It wasn't ever compromised.
Just keep in mind that open source does not mean invincible. There're many cases where open source app has bugs here and there. What you can guarantee is probably that the developer does not take your data (especially if you build the app from scratch on your own after checking all lines of the code). Don't fall for a false sense of security.