In what form? The private keys never leave the nodes, hence there shouldn't by any access per se (see https://tailscale.com/security/). Of course TS has insights into your networks, i.e. what servers it is installed on, what you connect to - so metadata.
But it still seems like they could flip that feature off if they got compromised. To remedy that, feels like they could support a preshared secret that they don't control / see being shared as a first step: https://tailscale.com/kb/1099/device-authorization/#generate...
Since Headscale exists, though, this problem is solved quite neatly.
Nothing in the Tailscale design has ever pointed to features that would guard your infrastructure from them.
Maybe headscale could run at home, served over a tunnel[1] to a VPS. But honestly, if I ever lost confidence in the trustworthiness of Tailscale the company, I would just connect my devices with some other overlay network like Yggdrasil[2] or Tor.
[1]: https://github.com/anderspitman/awesome-tunneling [2]: https://yggdrasil-network.github.io/
I also believe that traffic inside homes should be secured regardless since routers can be hacked. So in my case, I didn't consider it a duplicated effort. I had my traffic already encrypted and authenticated when I started using Tailscale.