"When Private Relay is in use, the user’s device opens up a connection to the first internet relay (also known as the “ingress proxy”).
As the user browses, their original IP address is visible to the first internet relay and to the network they are connected to. However, the website names requested by the user are encrypted and cannot be seen by either party.
The second internet relay (also known as the “egress proxy”) has the role of assigning the Relay IP address they’ll use for the session, decrypting the website name the user has requested and completing the connection.
The second internet relay has no knowledge of the user’s original IP address and receives only enough location information to assign them a Relay IP address that maps to the region they are connecting from, conforming to the IP Address Location preference they selected in Private Relay settings."
[1] https://www.apple.com/privacy/docs/iCloud_Private_Relay_Over...