It's a very non-non-issue: the client is closed source, for all we know it could do anything. Even if you listen on the data output to verify it's indeed encrypted, you still aren't able to tell whether your private key isn't transmitted alongside.
This isn't security, it's security by obscurity - in the best case, mind you.
This isn't security, it's security by obscurity - in the best case, mind you.