If I have public repls, does that mean people can access to view the code/private files (.env)?

people can view all your repls (except the .env files: but they can't edit any of your code. You can also have private repls (no one can even view it) if you get the hacker plan.