Windows Recall doesn’t use OpenAI or any online API. The indexing and OCR is done by a local model, in a Secure Enclave powered by VBS and encrypted with the system TPM. AKA: a virtualization-separated process with storage inaccessible to the OS (all lookup etc. is done over RPC).
Do you hold Apple Intelligence's local LLM to the same standard?
Apple Intelligence will index all of your messages, app data, etc. into a queryable index. That will also obviously reside on disk somewhere, encrypted. And it could be just as exfiltratable as your hypothetical. (Because both cases require compromising the host computer)