If you have a hardware wallet. You will pass the intent message (sending money, swap, etc) to Trezor. Trezor holds your private key. Signs the message with your private key. Hands the payload back to the client to be broadcasted to the network. This way your private key stays in the hardware wallet, and protected from a compromised computer.
If you use metamask instead. The private key here resides in the browser or your computer rather. I am unsure exactly where the signing happens but it will have to happen within the domain of your computer (at metamask or js) because that is where the key is. Gets back payload to be broadcasted.
Copy pasting private key (totally not recommended) is for cases where say you dont have a metamask or a hardware wallet. The signing is done probably using the js library included by the widget to obtain payload for broadcast.
Nothing should be passed on to a server. Only the signed message needs broadcasting into the ethereum network for the transaction to be included into a block.