No. But could they prove it with the standard FB app either? I mean, you are typing your user name and password on that phone, if you assume the manufacturer is outright malicious, then official API access doesn't really matter one way or the other. An API used to create a third party client is generally a good thing and doesn't actually change this (unless I am missing something here).
You could, however, with some trouble, check which data is going where on your own device, as long as that API isn't meant for direct connection between FB servers and those of a third party.