The keyword is "your own machine".
I guess this is enough if you are uncle jim, you know your code, and other's know you, trust you.
But proving code on other machines would be a cool feature! Like proving websites running a certain service version. But that can also be a good target for osint. Hmm.
No, it's enough if you know what's running on your phone. You don't need to trust uncle Jim to protect your privacy with ecash.
Which docs do you suggest to read to come to this conclusion?
This is how blind signatures work. Check docs.cashu.space > Resources (mobile rn)