It's good to be skeptical. Verify. The apps are open-source and the protocol is open-source
I built my own client and relay so I know the CIA isn't involved in that. You could build your own too.
GitHub
GitHub - nostr-protocol/nips: Nostr Implementation Possibilities
Nostr Implementation Possibilities. Contribute to nostr-protocol/nips development by creating an account on GitHub.