If I have public repls, does that mean people can access to view the code/private files (.env)?

no, they can't edit them, only view them or fork them. just another reason to get hacker plan.

that's advertising for ya!