I mean if I write something in the code:
NSString *myKey = @\"this is my private key\";
Will someone be able to trace back the string
Yes, it's likely. An IPA is just a zip file. You can extract it to get the application binary. You can usually run strings over an application binary to see string literals.
strings