It's pretty common for companies like that to advertise that their app is 100% open source, but then stop short of guaranteeing anything beyond that. In PIA's case, I would point out that their infrastructure (the servers that they use to route your traffic) are closed, so they could be doing literally anything in there. Their desktop client being open source doesn't actually do much to guarantee your privacy.
If you want real transparency, Mullvad is the only real option: https://mullvad.net/en/help/open-source
Having said that, I personally use PIA because it's cheaper and I don't care enough.