Data privacy using hugging face models

Is there a risk of my data getting leaked via nefarious code being added to a model repo, or by being sent to Hugging face when using the transformers library?