Edit: I should have used a different word than upload. It's just old habit. According to TFA, there is no uploading. All processing is done in the browser, so the app needs local file system access to get at your image
This, but it can also have the browser store it to disk by requesting the persistent mode from the storage API.
https://developer.mozilla.org/en-US/docs/Web/API/Storage_API
You appear to be misunderstanding on how browsers handle file uploads. You cannot get the local file path for a file. There is no C:\ or /Volumes or whatever your OS uses. Browsers deliberately mask that from the upload.
(and I do think it's kind of irritating that Mozilla is fighting against such useful features on somewhat patronising 'the users won't understand what permission they're granting' grounds)
The File System Access API has security precautions built-in. For example, it requires users to explicitly grant permission to access a specific directory (once) per session. Also, the API never allows access to root or to system-related directories.