"The recaptcha, when it shows up (in rare situations), is sandboxed so that it doesn't send any data to Google. We are also in the process of replacing it with hcaptcha."
Not sure what possible sandboxing they could be referring to - if they load the captcha in an iframe from a different origin then it is true that Google's javascript can't access things on the Protonmail origin, but the concern seems to be that your data is sent to Google (which is still happening even with sandboxing, their tweet cannot be correct), not that Google's recaptcha javascript would have done something malicious on the Protonmail origin (which seems unlikely).
In any case, at least they're moving to hcaptcha.
[1]: https://twitter.com/ProtonMail/status/1398657423913668614