There is no way—even with open source software—to prove that and app isn't sending data to a third party. Unless you are going to build all of your hardware from raw materials, and build your own software by hand, using a bootstrapped compiler that you wrote yourself. In machine code.
Given the above, it's obvious that there has to be a level of trust involved at some point in the process. The majority of people using open-source software aren't building it themselves, and so the trust issue would still be there if the software was open. Who's to say they wouldn't provide a binary that shipped your data off, without including that code in the open release?
IOW, your predictable shallow response adds precisely zero value to the discussion about how to ensure privacy in software.
Besides which, you can verify what servers it connects to in such a trivial way (1 minute tops) that digging through source code would be stupid.
I trust them not to include a mail-stealing backdoor (which would likely be noticed quickly), but I don't trust them to secure my mail on their servers.
People doing this sort of thing tend to get caught, and besides, these guys seem to be in the app business, not in the service business.