A transaction is public by default, which means it can be seen by anyone with access to the folder in which the transaction is stored. It is possible to limit the transaction access to the transaction creator and member with admin rights only, by switching the transaction into private mode.
Note that you can only set private mode for live transactions (draft, paused or in progress).
Note that you can set transactions to be created privately by default on your worksapce. For more details visit Workspace preferences.