The code is open source, the build process is open on GitHub actions and it’s hosted on GitHub pages so you also see compiled site easily. The password never leaves your browser apart from going to the instance you chose when logging in. The password also is not saved, only the access token.
I tried my best at making it as transparent as possible.
Just added TOTP support in https://github.com/stirante/lemmy-discover/commit/e590c6a5cff366060e3fb6202031442b8bfe7fc8