Correct. Every single time these people are incorrect and we keep having to explain this
We know it can copy parts of the context and the system prompt while a special part of the context isn't immune to being copied.
You can test it yourself by adding random strings to the system prompt, you can consistently have the model copy them over. Is that not enough to have a reasonable belief that the model can copy system prompt instructions in the web interface?
Those that experiment with local models like myself can demonstrate to you that leaking the system prompt is not difficult at all.
It's some strange kind of neurosis to harbor such incorrect and strong beliefs on matters you have zero expertise in.