They do, and this is a legitimate concern. I thought about it and decided I didn't care so much.
An alternative is to self host the same set of services.
That's correct. It's encrypted in transit, but the endpoint bridges decrypt messages then reencrypt them. IIRC you can run the bridges yourself on your own servers - Element just offers this service as well.
Yeah, but they are also working on an alternate solution where the bridging happens in the client, which doesn't have this issue.