Well, that's what they say, but being closed source it's reasonable to think there might be backdoors somewhere. Besides, WhatsApp is not p2p, but client server based. Nobody knows for sure if the NSA Prism program still exists, but it does, Facebook would probably be part of it.
I thought you generated the key pair on your device and never sent the private key, not even to WhatsApp? Isn't that the idea behind the Signal protocol, which WhatsApp uses?