They take pains to say:
> your device downloads the current model, improves it by learning from data on your phone, and then summarizes the changes as a small focused update. Only this update to the model is sent to the cloud, using encrypted communication, where it is immediately averaged with other user updates to improve the shared model. All the training data remains on your device, and no individual updates are stored in the cloud.
(my emphasis on the word stored)
Now there are lots of scholarly articles on reverse-engineering and rule-extraction from neural nets.
So Google, having the diff can actually get some idea what it is you are trying to teach the net.
They just promise not to.
Google makes the OS and the keyboard. If they wanted to run a keylogger on every device against the express wish of users they could.
So I think the more important question is if someone else could steal or "legally" request that data from Google and recover my keystrokes.
Well, that's my fallible summary anyway, go read the paper. :-)
Plus this would seem a computationally expensive way of conducting mass surveillance