1) their software logs all keystrokes. 2) their software sends all keystrokes to their servers. 3) they denied it did so.
Those don't add up to reasonable doubt any way I can see it. If they were using that information for understanding crashes, dropped calls, etc, then they would have seen that it was recording everything, and would have seen it many many many times. It can't have slipped past their notice unless it was totally un-used, and then they should've raised an eyebrow at the massive numbers of signals being sent to their domains.