There's no way this thing has the power to do adequate voice recognition on device for arbitray speakers and queries, even given a limited domain. It's sending everything to Amazon for processing. The only thing it probably recognizes by itself is "Alexa."
Right, so it sends the commands that you give it only after it recognizes a pre-programmed word. It will likely not send up casual conversation surrounding the command, as there would not be a non-nefarious reason to do that.
False positives... But yeah they're probably rare. The real risk is that it could be hacked or national security lettered to listen permanently. The FBI has form in this regard.
I'm guessing it's Android under the covers, and I believe that Google voice recognition is now processed on the device - so it might well be powerful enough to do the voice recognition without the cloud.