Proton has opened sourced everything so far and I would expect them to do that here. They have whole pages written on why they open source everything and why that helps privacy.
Nothing is mentioned other than "proprietary system". Probably meaning that both ends are closed source. I don't see how I can verify whether it respects my privacy or not. I don't see a reason to implement this instead of mCAPTCHA, which is fully FOSS.