This what they told me

This what they told me

That answer makes me think they're importing your private key into their server.
On the other hand one of their developers talked to me about my Dart bip340 library, which indicates they are either signing or verifying signatures on the client.
We do both, all client side 😊
Private key is stored on iOS to keychain and on android it is encrypted cia key that is stored in keystore 😊