They take pains to say:
> your device downloads the current model, improves it by learning from data on your phone, and then summarizes the changes as a small focused update. Only this update to the model is sent to the cloud, using encrypted communication, where it is immediately averaged with other user updates to improve the shared model. All the training data remains on your device, and no individual updates are stored in the cloud.
(my emphasis on the word stored)
Now there are lots of scholarly articles on reverse-engineering and rule-extraction from neural nets.
So Google, having the diff can actually get some idea what it is you are trying to teach the net.
They just promise not to.