It's a falsifiable assumption. Audit the binaries if you want to convince yourself. You will see code to generate and use keys locally, with no mechanism to fetch or share keys from a server.
If you want to go beyond generic concerns, there are plenty of academic papers that have looked at Facebook Secret Conversations, found actual issues, and helped get them fixed: https://link.springer.com/article/10.1007/s00145-020-09360-1 https://link.springer.com/chapter/10.1007/978-3-319-63697-9_... https://link.springer.com/chapter/10.1007/978-3-319-96884-1_...