Does Apple explicitly say that?
Or only that they don’t know which landmark it matched?
Or only that they don’t know which landmark it matched?
The bigger privacy risk would be that the device routes the request to a specific database shard based on whichever has a center-point closest to the image embedding on the device. They take steps to protect this information such as third-party proxying to hide user IP addresses, as well as having devices send fake requests so that the server cannot tell which are real user data and which are fake data.